Incident response
Active engagement · INC-4471.
Token theft via OAuth misconfiguration on the Salesforce surface. Cross-region containment in progress.
Critical · active
Token theft via OAuth misconfig — Salesforce surface
Detect
01Triage
02Contain
03Eradicate
04Recover
05Token theft via OAuth misconfig — Salesforce surface
Started 12m ago
Suspicious model inference at fraud-scoring endpoint
Started 1h 02m ago
Credential stuffing campaign · 4 ASN clusters
Started 2h 47m ago
Engagement timeline
- 00:00Auto-detect
Anomalous OAuth scope grant detected on Salesforce surface
- 00:42Lens-Q
Correlated with prior credential reuse from same IP block
- 01:38P. Devereux
Declared INC-4471 · severity raised to Critical
- 02:04Auto-action
Revoked 14 active tokens, forced re-auth for 312 sessions
- 04:11L. Okonkwo
Forensic snapshot captured · 4.2 GB
- 07:55Comms
Stakeholder brief distributed · exec, legal, GRC
- 11:42P. Devereux
Containment verified across all impacted regions
Stakeholders
- Online
P. Devereux
IR Lead · Commander
- Online
A. Volkov
SOC Director
- Paged
M. Carrasco
Legal · Privacy
- Online
E. Whitfield
CISO · Sponsor
- Notified
J. Saito
Customer Success
Comms log
- Exec brief08:12
Initial impact summary sent
- Status page08:24
Investigating · degraded auth flows
- GRC09:05
Reg notification window started · 72h
- Customers (T1)10:18
Direct notice · 47 enterprise accounts