Secrets in logs
Logs quietly become a second copy of your most sensitive data, with wider access and longer retention than the original.
It happens by accident: a debug line printing a whole request object, an error capturing the headers, a stack trace containing the query. Those logs are then shipped to a central system readable by far more people than the database ever was, and kept for years. Nobody decided to store card numbers or session tokens in a searchable archive, which is precisely why nobody is protecting them there.
Checked against the primary source.
