The Scope That Was Never Narrowed
The alert fired at 3:47 a.m. on a Thursday. The on-call engineer read it twice before she understood what she was looking at, and by then the attacker had been inside the service account for six weeks. She called the CISO first. She called him second. By the second call she knew what she was going to have to say.
The alert fired at three-forty-seven a.m. on a Thursday. Lena was on call, which meant the phone on her bedside table made the specific chirp that she had been trained to recognize even through deep sleep. She picked it up. She read the alert.
She read it again.
The alert was from the correlation rule that her team had written four months ago, during the log-aggregation project that the CISO had championed and that the AI platform team had resisted for reasons that had seemed to her, at the time, like standard inter-organizational friction. The correlation rule watched for specific patterns across the four log sources that her team had integrated into the security data lake: client-side MCP telemetry, server-side MCP telemetry, backend access logs, and identity provider logs.
The rule that had fired was the simplest of the rules her team had shipped. It watched for cases where the user identity on the client side did not match the user identity that eventually reached the backend system for the same transaction. In a correctly-operating MCP deployment, the identities should always match. In the six months the rule had been live, it had fired exactly twice, both times because of legitimate service operations that had since been excluded. It had never fired because of an attack.
This time it had fired three hundred and twelve times in the last forty-eight hours.
She sat up in bed. She pulled her laptop from the nightstand. She opened the correlation dashboard. She scrolled.
The pattern was clear, in the way that retrospective patterns always are. All three hundred and twelve instances involved the same MCP server — the internal customer-records MCP server that the company had deployed sixteen months ago to let the customer support team query account information through the agent layer. All three hundred and twelve instances involved the same anomaly: the client-side identity was a legitimate support engineer; the backend-side identity was the MCP server's service account, which had broader scope than any individual support engineer.
The service account was accessing customer records for a customer the requesting support engineer had no legitimate business accessing.
The service account had been doing this for at least forty-eight hours, at a rate of roughly six records per hour.
Lena opened a second window and ran a lookback query. She pulled the correlation history going back ninety days.
The pattern had been running for six weeks.
She stared at her laptop. She breathed carefully. She counted to five. Then she opened her contacts and called the CISO.
The CISO picked up on the second ring. He sounded exactly as awake as a person is when they have been asleep for forty-five minutes and have been woken by the specific ringtone he had assigned to on-call-to-CISO escalations.
"Lena."
"Active incident. MCP-related. Customer records. Six weeks."
"I'm going to be in the office in thirty-five minutes. Can you get the AI platform team on a bridge by then?"
"Yes."
"Has the attacker been contained?"
"No. They're active right now, sir. The rule fired three hundred and twelve times in forty-eight hours and the last one was six minutes ago."
"Kill the MCP server."
"Sir, I don't have the authority to —"
"I'm giving you the authority. Kill the server. Right now. Cut the service account credentials. Everything. Then get the bridge up."
"Yes, sir."
She hung up. She opened the MCP platform admin interface. She navigated to the customer-records server. She clicked "deactivate." A confirmation dialog appeared. She clicked "confirm."
The customer-records MCP server, which had been serving the support team for sixteen months, went offline. Every agent interaction that was mid-flight failed. Several support tickets on the active queue would error out when their agent reached the customer-records tool.
She then rotated the service account credentials. The old credentials, whatever the attacker was doing with them, would stop working in the next few minutes.
She opened a bridge. She paged the AI platform team on-call, the compliance team on-call, the legal team on-call, and two of the senior engineers who had built the original MCP deployment.
She started typing the incident notes while she waited for people to join.
The first person on the bridge was Raj, from the AI platform team. He sounded tired but not surprised.
"Lena, what do we have?"
"Active MCP-related incident. Customer-records server. Service account was being used to access customer records outside the originating support engineer's scope. Started approximately six weeks ago."
"How did they get the service account?"
"I don't know yet. The server's offline. The credentials are rotated. We need to do forensics on the server's process memory and the endpoint it was deployed to."
"OK. Who's driving?"
"I am, until the CISO arrives."
"OK."
Raj pulled up the customer-records server deployment manifest on his own screen. He looked at the scope grants. He was quiet for a long moment.
"Lena."
"Yeah."
"The scope grant on this service account is 'full customer records read.' There's no scope limit for specific customer subsets. The service account can read any customer record in the system."
"I know."
"Who approved this scope?"
"I don't know. Sixteen months ago. Before I was on the security team."
"This is bad."
"Yeah."
"If the attacker has been running for six weeks at six records per hour, that's roughly six thousand records. With full-read scope. That's disclosable under California, New York, the new federal framework, and probably GDPR depending on what's in the records."
"I know."
"OK. I'm going to start pulling the server logs. You drive the bridge."
The CISO arrived at the office at four-twenty-one a.m. He looked tired and clear-headed at the same time, which was a specific look that Lena had seen on him exactly once before, during the last major incident the company had handled, which had been nothing like this one.
"Walk me through what we know."
She walked him through what they knew. The scope grant. The service account abuse pattern. The six-week duration. The estimated records accessed. The containment actions taken. The bridge participants.
The CISO listened without interrupting. When she finished, he nodded.
"OK. Two things. First, we're going to activate the IR protocol for regulated-data incidents. That means the clock starts now on the disclosure window. We have seventy-two hours under California, and the federal framework is thirty days but starts on discovery. Discovery was —" he checked his watch "— thirty-four minutes ago."
"Understood."
"Second thing. I need you to understand that the correlation rule you shipped six months ago just saved this company somewhere between two hundred million and eight hundred million dollars in direct and indirect costs. Those are the numbers we use for incidents at this scale. I want you to remember that, later, when the rest of this gets hard. You did the job. The work you did before this happened is what gave us the chance to contain it. I want to be on the record about that before the rest of the day starts."
"Yes, sir."
"OK. Get me the AI platform lead on the bridge. I need to know what else we're running that has this scope configuration. If we have a systemic issue with scope grants across our MCP deployment, I need to know before I walk into the board meeting that is about to be on my calendar."
"Yes, sir."
The AI platform lead joined the bridge at four-forty-three. The conversation that followed was the one that Lena would replay, later, as the most important conversation of the incident. The AI platform lead confirmed what Raj had already suspected: the customer-records server was not the only MCP server with broad-scope service account grants. There were seventeen. Most of them had been configured during the initial MCP deployment push sixteen months ago, under operational time pressure, with scope narrowing deferred as a second-phase improvement that had never been prioritized.
By five a.m. the team had inventoried all seventeen servers and classified them by the sensitivity of the backend data they accessed. Six were in the same risk class as the customer-records server. Eleven were somewhat less sensitive but still concerning.
By six-fifteen the scope grants on all seventeen had been tightened to operational minimums, with emergency change management approval and a full audit trail.
By eight a.m. the CISO was on the bridge with external counsel and the breach response firm the company retained for incidents at this scale.
By nine the General Counsel was on the bridge.
By eleven Lena had written the incident note that would go into the permanent record of the incident. She had written it twice. The first time she had written it in the third person, which had felt wrong — it was her rule that had fired, her action that had contained the server, her hours of forensic work that had bounded the blast radius — but she had written it that way because it felt presumptuous to write it in the first person. The CISO had read her third-person draft and had walked over to her desk and told her, quietly, to rewrite it in the first person because the record should be accurate.
She had rewritten it.
The disclosure would come out on Friday afternoon, the way company disclosures typically did. The board conversations would happen over the weekend. The regulatory filings would be filed on Monday. The post-mortem would run for six months, with external oversight and extensive documentation of what had gone wrong and what had gone right.
What had gone wrong was clear: the scope grants had been too broad, the service accounts had been too privileged, the audit trail had been under-correlated for fourteen months before the correlation work had been completed, and an attacker had found the gap.
What had gone right was that the correlation rule had caught the attack at six weeks rather than six months. At six weeks, the incident was a contained, disclosable, recoverable event. At six months, it would have been a company-ending catastrophe.
Lena went home at two p.m. She slept until seven, woke up, ate dinner, went back to bed, and slept until the following morning.
When she came back to the office on Saturday, there was a printed card on her desk, in the kind of envelope that nobody at the company used for anything other than handwritten notes.
It was from the CISO.
It said: "The correlation rule you shipped six months ago was the difference between a disclosure and a disaster. Thank you. — Tom"
She kept the card.