How could a stolen session token even be useful. I have to log into tools every day, if I change IPs at all I have to re-authenticate, and all prod access needs to be approved and has a finite lifespan.
How could a CI company be that negligent. They should be leading this stuff from a best practice point of view.