38,000 records. 72 hours. And you can't find the English fast enough.
It's 4:50 on a Friday when the alert fires. A logging endpoint nobody remembers writing is copying customer records out of the database. Thirty-eight thousand of them. It's been quietly running for eleven months. You see it first. You understand it first: an old token, never rotated, someone's shortcut from a year ago that was never closed. You know exactly how to say it. In your own language,…
It was 4:50 on a Friday when the alert went off. An endpoint no one had touched for months was quietly copying 38,000 customer records from the database. The cause appeared to be an old, unrotated token that had been left open for a year. The call with the CTO, legal counsel, and a data protection official from Germany began immediately.
Everyone spoke English quickly as the legal counsel declared, "under GDPR, you have seventy-two hours to report this from the moment you became aware." The clock had started at 4:50. The critical question now was: how did they get in? In the heat of the moment, the engineer struggled to find the right words in English. The CTO suggested it might have been intentional, pointing to a rogue developer.
However, the truth was a simple mistake, not a malicious act. The team needed to act quickly to stop the breach, but their language failed them in the critical first moments.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.