9 Aug 2026
Signal Headquarters
Vol. I
No. 185
Signal
· · 3 min read

The OpenAI incident report buried its own lead: stolen credentials came first, not zero-days

Zero-days attract attention. Stolen credentials do the actual damage. Zane Lackey argues the incident response documentation from a notable OpenAI breach made exactly that ordering plain, even as the public conversation fixated on the more exotic attack vector.

Security incidents rarely fail because defenders lacked imagination. They fail because the unglamorous attack vectors, the ones that have worked for decades, keep working. Stolen credentials sit at the top of that list. They are cheap to acquire, hard to detect in use, and effective against organizations that have spent heavily on everything else. The gap between how much attention stolen credentials receive and how much damage they cause has never closed, and a pointed observation from Zane Lackey suggests that gap shaped the framing of at least one high-profile incident involving OpenAI.

Lackey’s argument is direct. The incident in question did use zero-days. That much is accurate, and that detail is what landed in headlines and drove the post-incident discussion toward questions about vulnerability research, patch cycles, and exploit brokers. Those are legitimate questions. But Lackey notes that when the incident response documentation itself was examined, the ordering told a different story. Stolen credentials appeared first on the list of attack vectors, not zero-days.

That sequencing is not a minor editorial decision. In incident response documentation, the order in which attack vectors are listed generally reflects the order in which they were used, the order in which they mattered, or both. A zero-day that opens a door is consequential. But stolen credentials that preceded it, or that extended access beyond the initial compromise, carry their own weight. When the document’s authors put stolen credentials at the top and the broader conversation put zero-days at the center, the two framings pointed in different directions.

Although it's true it did utilize zero days, um, but the first thing listed out was stolen credentials Zane Lackey

The implications extend beyond any single incident. Organizations make resourcing and prioritization decisions based on what they believe the actual threat landscape looks like. If a well-documented breach is remembered primarily as a zero-day story when the underlying documentation foregrounded credential theft, the lesson that gets absorbed is the wrong one. Defenders end up investing in detection and response capabilities calibrated to the version of events that circulated publicly rather than the version the incident responders actually documented. That is a consequential mismatch.

Lackey’s point is also a reminder that incident response reports are primary sources, and primary sources deserve closer reading than they typically receive. The summary that makes it into press coverage, analyst commentary, and conference talks is often a compressed version of a compressed version. Details that did not fit the dominant narrative get dropped. In this case, the dominant narrative was zero-days, a term that carries technical credibility and signals sophistication on the attacker’s part. Stolen credentials, by contrast, carry a faint implication that someone did not have multi-factor authentication configured correctly, or that a phishing campaign succeeded, or that credentials appeared in a leak and were never rotated. None of those are exciting storylines. All of them are more common than zero-day exploitation.

The security community talks regularly about the gap between perceived and actual risk. Lackey’s observation is a concrete example of that gap operating in real time, attached to a real incident, visible in the structure of the documentation itself. Zero-days will always attract disproportionate attention because they are technically demanding and they signal something about the adversary’s capabilities and resources. But when the incident report lists stolen credentials first, the incident report is telling the reader something. Whether the broader conversation chooses to hear it is a different matter, and based on how coverage of this particular OpenAI incident unfolded, the answer appears to be that it largely did not.

That selective hearing has costs. Organizations that conclude the primary lesson is to track zero-day exposure more carefully leave their credential hygiene, their phishing resistance, and their detection of anomalous authentication events in roughly the same state they were in before the incident. The attacker toolkit does not care about that hierarchy. It reaches for whatever works first, and what works first, even in sophisticated operations against high-profile targets, is often still stolen credentials.

The Editor, for the readers of Signal Headquarters

From the Archive