The incident report landed in my inbox at 2 AM: unexpected API usage from Eastern Europe. Not a brute-force attack, not a plugin vulnerability, just a translation API key, quietly exfiltrating product descriptions for a week before finance flagged the $1,200 invoice. The key had been pasted into a shared Slack thread for debugging six months earlier. That was the moment I realized translation cred