Loading...
A four-year-old pilot credential became the entry point to a category-wide breach of strategy data. The bill for the access economy just came due for buyers.
A four-year-old credential for a limited pilot that nobody decommissioned was the entry point. Hackers walked through it, harvested OAuth tokens, and queried the Salesforce instances of more than a dozen named security vendors in a single afternoon. Salesforce disabled the integration itself. The platform had to be disconnected by the system it was leaking into. That is what "tools sell access" actually costs a buyer, and the bill came due the same week the advertising industry's largest buyer stood on the Palais stage and said the holdco model is broken.
Last Tuesday, TechCrunch reported that a major competitive intelligence vendor confirmed the credential at fault dated to 2022 — issued for a limited pilot, never decommissioned, sitting on a live OAuth chain for four years. CSO Online's reconstruction shows the same chain reached HubSpot, SharePoint, Zoom, Gong, Clari, Google Drive, and Slack, not just Salesforce. The artifact that leaked in every case was the buyer's own strategy data: battlecards, quotes, support cases, sales conversations. Not passwords. Not credit cards. The competitive intelligence corpus the buyer trusted the tool to hold.
Tools are excellent at the access part. They give you a login, a dashboard, a connector, an API, and a key to a database you do not operate. The contract is implicit: you put your data in, the tool holds it, and the operational discipline of every integration the tool has ever shipped is the perimeter protecting your strategy. That contract just visibly failed at category scale. The buyer did not get breached. The tool that was given the keys got breached. There is no version of this story where the buyer's data stayed in the buyer's control, because that is not the tool's business model. The tool's business model is to hold the data for you, at scale, across every integration it can ship, as fast as it can ship them. Operational discipline is a tax on that business model. The breach is what happens when the tax goes unpaid.
The same week, the world's most credible advertising buyer said the model that puts your strategy in someone else's stack is no longer fit for purpose. Marc Pritchard, P&G's chief brand officer, told the Cannes Lions audience that brand building is now a "constant sprint" and that the agency model that routes every workstream through a single holdco is the wrong shape for the work. His language was deliberate. AI is the propellant. Human accountability is the craft. The buyer wants both, and wants the human accountability named on the recommendation rather than buried in a holding company's operating model.
The breach is the negative case the buyer was making. P&G's modular, named-human frame asks for one thing that "tools sell access" structurally cannot provide: a single named owner whose signature is on the recommendation, whose phone rings when the recommendation turns out to be wrong, and whose operational discipline is the perimeter the buyer is actually paying for. A credential-management mistake at a third-party vendor is not a procurement event. It is a strategic event, and the buyer has no seat at the table where it is decided.
The festival closed on Friday on a "Creativity Has to Strike Back" theme. Fernando Machado, the chief brand officer of Chipotle, told the Palais that the industry had become "too obsessed with optimization, dashboards, and AI hacks." The same night, the Film Grand Prix went to Claude — an AI platform — for a Super Bowl campaign that mocked AI advertising. The Film Lions jury president called it "an AI making fun of AI." The category's top creative prize went to the work that named the category's failure most directly.
The same frame, applied to strategy: when a tool's "access" is a license to query your competitive intelligence from inside the buyer's perimeter, the question is not whether the tool is useful. The tool is useful. The question is who owns the perimeter. When the perimeter leaks, who calls the customer. When the recommendation turns out to be wrong, who signs the revision. Tools do not have an answer to that question. They have a security blog post and a customer alert. The buyer has a procurement decision to make.
Autostrat is an AI-native strategy agency. We deliver audience insights, competitive intelligence, and strategic clarity as a finished service, not as access to a database. The difference is structural. Our work is delivered as a named decision, with a named human accountable for the recommendation and a defined revision path. We do not hold your strategy data in a third-party database subject to four-year-old pilot credentials. We do not ship integrations faster than we can decommission them. We do not have an OAuth chain to your Salesforce. The work lives in your environment, on your terms, with a human signature on the recommendation.
That is what "we sell accountability" means in operating terms. It means the perimeter protecting your strategy is your perimeter, not a vendor's. It means the recommendation has an author, the author has a phone number, and the phone number has a real human on the other end of it. It means the buyer can answer the question P&G put on the Cannes stage — who is accountable for this work — with a name, not a logo.
The access economy is not going away. Tools will keep selling dashboards, connectors, agents, and integrations, and the integrations will keep being the perimeter. The question for the buyer is no longer whether the tool is useful. The question is whether the buyer's strategy should live inside the perimeter the tool sells. The breach is the answer.
Book a 30-minute demo. Bring a live question and watch the answer get built.