Skip to main content
MondelezTech adoption

An employee at Mondelez International discovered that the operations team built and deployed a customer-facing data intake application using Replit without IT's knowledge or oversight, a case of...

What happened

An employee at Mondelez International discovered that the operations team built and deployed a customer-facing data intake application using Replit without IT's knowledge or oversight, a case of 'shadow IT'.

Source

RedditSep 4, 2026By u/Friendly-Rooster-819

r/Information_Security

Found out someone in ops built a customer facing app on Replit and no one told IT

upvotes
227
comments
24

Post

Highlighted: the lines this signal was extracted from

I work at a mid-size manufacturing company that rhymes with Schmondelez. Stumbled into this one. Someone in ops has had an intake form running on Replit for about two months, customers fill it out, it writes straight to a database. Only noticed because a vendor called asking why a subdomain I didn't recognize was throwing a cert warning. Asked ops who owns it. Answer was "it just works, why does it matter." Asked if the admin view has auth on it. Silence, then "I dunno think so, I never set one up." Asked where the database lives. He had to go check. It's been live and indexed since October. I dunno what's in it at this point, and I'm not sure he does either. Not filing an incident yet since nothing's confirmed leaked. Just sitting here wondering how many more of these exist that I haven't stumbled into by accident.

Also quoted as evidence

  • [comment u/skynetcoder] maybe you can find more here. https://crt.sh/?q=mondelezinternational.com

reddit.com/r/Information_Security/comments/1w6wtx9/found_out_someone_...Read the full source

Comments on the post

5 of 24 comments
  • “I'd treat this as a security incident or at least an incident candidate even if there's no evidence of a breach yet. The fact that it's customer-facing, has a database, and nobody can clearly explain the auth/data ownership is enough to warrant getting security involved.”

    u/Fragrant-Cheek-427326 points · Sep 4, 2026View

  • “Yea shit is getting out of hand.”

    u/stacksmasher14 points · Sep 4, 2026View

  • “Audit your domain/subdomain registry and their inbound/outbound connections”

    u/hasnat-ullah9 points · Sep 4, 2026View

  • “The scary part to me isn't really Replit specifically. It's that the organization apparently has no inventory of these apps. Once one exists, I'd assume there are more and start with discovery: unexpected subdomains/DNS records, OAuth applications, service accounts, API keys, databases and externally reachable endpoints. Then establish the boring rule that every operational app needs an owner,”

    u/gammacoder7 points · Sep 4, 2026View

  • “maybe you can find more here. https://crt.sh/?q=mondelezinternational.com”

    u/skynetcoder3 points · Sep 4, 2026View

Extracted by Autobound

From the Signal API record
Signal
Tech adoption

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/Information_Security
Stage
Switched
Event date
Jul 2026

Companies

  • ReplitAlso named

The full record

From the Signal API record

Numbers

Mentions
1

Details

Timing
Completed
Category
Application Development Platform
Virality
High
Post kind
Text
Prominence
Core
Company's role
Buyer

Topics and mentions

Topics

  • shadow it
  • application development
  • security
  • compliance

Extraction

Sentiment
Neutral
Detected
Sep 4, 2026
signal_type
reddit-company
signal_subtype
techAdoption

Use this data

Get every Reddit signal for Mondelez and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Mondelez this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/bac83b17-618e-593d-a804-a184f3a95432 returns this record as JSON. POST /v1/companies/enrich returns every signal for mondelezinternational.com.

{
  "signal_id": "bac83b17-618e-593d-a804-a184f3a95432",
  "signal_type": "reddit-company",
  "signal_subtype": "techAdoption",
  "detected_at": "2026-09-04T06:53:02+00:00",
  "company": {
    "name": "Mondelez",
    "domain": "mondelezinternational.com"
  },
  "data": {
    "nsfw": false,
    "stage": "switched",
    "awards": 0,
    "timing": "completed",
    "topics": [
      "shadow it",
      "application development",
      "security",
      "compliance"
    ],
    "post_id": "1w6wtx9",
    "summary": "An employee at Mondelez International discovered that the operations team built and deployed a customer-facing data intake application using Replit without IT's knowledge or oversight, a case of 'shadow IT'.",
    "category": "Application Development Platform",
    "comments": [
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w6wtx9/comment/p7s0802/",
        "depth": 0,
        "score": 26,
        "author": "Fragrant-Cheek-4273",
        "excerpt": "I'd treat this as a security incident or at least an incident candidate even if there's no evidence of a breach yet. The fact that it's customer-facing, has a database, and nobody can clearly explain the auth/data ownership is enough to warrant getting security involved.",
        "posted_at": "2026-09-04T13:39:24.000Z",
        "author_url": "https://www.reddit.com/user/Fragrant-Cheek-4273/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w6wtx9/comment/p7r4wan/",
        "depth": 0,
        "score": 14,
        "author": "stacksmasher",
        "excerpt": "Yea shit is getting out of hand.",
        "posted_at": "2026-09-04T10:43:00.000Z",
        "author_url": "https://www.reddit.com/user/stacksmasher/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w6wtx9/comment/p7qe9a7/",
        "depth": 0,
        "score": 9,
        "author": "hasnat-ullah",
        "excerpt": "Audit your domain/subdomain registry and their inbound/outbound connections",
        "posted_at": "2026-09-04T07:03:04.000Z",
        "author_url": "https://www.reddit.com/user/hasnat-ullah/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w6wtx9/comment/p7v4hq9/",
        "depth": 0,
        "score": 7,
        "author": "gammacoder",
        "excerpt": "The scary part to me isn't really Replit specifically. It's that the organization apparently has no inventory of these apps.\n\n Once one exists, I'd assume there are more and start with discovery: unexpected subdomains/DNS records, OAuth applications, service accounts, API keys, databases and externally reachable endpoints.\n\n Then establish the boring rule that every operational app needs an owner,",
        "posted_at": "2026-09-04T21:58:07.000Z",
        "author_url": "https://www.reddit.com/user/gammacoder/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w6wtx9/comment/p7ra1sb/",
        "depth": 0,
        "score": 3,
        "author": "skynetcoder",
        "excerpt": "maybe you can find more here. https://crt.sh/?q=mondelezinternational.com",
        "posted_at": "2026-09-04T11:17:58.000Z",
        "author_url": "https://www.reddit.com/user/skynetcoder/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w6wtx9/comment/p7rnicu/",
        "depth": 0,
        "score": 3,
        "author": "j-joshua",
        "excerpt": "Customer: Why didn't my bread get delivered today?\n\n You: ...",
        "posted_at": "2026-09-04T12:36:20.000Z",
        "author_url": "https://www.reddit.com/user/j-joshua/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w6wtx9/comment/p7swn2b/",
        "depth": 0,
        "score": 3,
        "author": "UnfeignedShip",
        "excerpt": "Are you subject to GDPR? If so, you must treat this as a compliance issue AT MINIMUM.",
        "posted_at": "2026-09-04T16:03:34.000Z",
        "author_url": "https://www.reddit.com/user/UnfeignedShip/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w6wtx9/comment/p7wbtbh/",
        "depth": 0,
        "score": 1,
        "author": "KeeganDoomFire",
        "excerpt": "Couple weeks ago we discovered an analyst team was just shipping data out to a client. No legal, no PII review, just dumb confidence.\n\n The only reason we found out was we got asked about it by another team that was wondering why they for asked to automate it...",
        "posted_at": "2026-09-05T02:02:35.000Z",
        "author_url": "https://www.reddit.com/user/KeeganDoomFire/"
      }
    ],
    "evidence": [
      "[post] I work at a mid-size manufacturing company that rhymes with Schmondelez.",
      "[post] Stumbled into this one. Someone in ops has had an intake form running on Replit for about two months, customers fill it out, it writes straight to a database.",
      "[comment u/skynetcoder] maybe you can find more here. https://crt.sh/?q=mondelezinternational.com"
    ],
    "virality": "high",
    "post_date": "2026-09-04T06:53:02.000Z",
    "post_kind": "text",
    "post_text": "I work at a mid-size manufacturing company that rhymes with Schmondelez. Stumbled into this one. Someone in ops has had an intake form running on Replit for about two months, customers fill it out, it writes straight to a database. Only noticed because a vendor called asking why a subdomain I didn't recognize was throwing a cert warning.\n\nAsked ops who owns it. Answer was \"it just works, why does it matter.\" Asked if the admin view has auth on it. Silence, then \"I dunno think so, I never set one up.\" Asked where the database lives. He had to go check. It's been live and indexed since October. I dunno what's in it at this point, and I'm not sure he does either.\n\nNot filing an incident yet since nothing's confirmed leaked. Just sitting here wondering how many more of these exist that I haven't stumbled into by accident.",
    "sentiment": "neutral",
    "subreddit": "Information_Security",
    "event_date": "2026-07",
    "post_title": "Found out someone in ops built a customer facing app on Replit and no one told IT",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/Information_Security/comments/1w6wtx9/found_out_someone_in_ops_built_a_customer_facing/",
    "entity_role": "buyer",
    "post_author": "Friendly-Rooster-819",
    "upvote_ratio": 0.9871244635193133,
    "mention_count": 1,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/Information_Security/",
    "total_upvotes": 227,
    "comments_total": 24,
    "total_comments": 24,
    "event_date_text": "about two months",
    "other_companies": [
      {
        "name": "Replit",
        "role": "adopted",
        "domain": "replit.com"
      }
    ],
    "post_author_url": "https://www.reddit.com/user/Friendly-Rooster-819/",
    "signal_category": "adoption",
    "comments_included": 11
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.