Dev.to Security 🔐 Cybersecurity 👁 0 📖 7 min read

The Most Expensive Code You Ship Is the Admin Panel Nobody Reviews

Every product has a second application hiding behind it. It has no designer, no load tests and no on-call rotation, and its security model often amounts to a boolean called is_admin. Support agents use it to look up cust

Every product has a second application hiding behind it. It has no designer, no load tests and no on-call rotation, and its security model often amounts to a boolean called is_admin. Support agents use it to look up customers, reset passwords and issue refunds, a few service accounts talk to it overnight, and nobody has read its pull requests with real curiosity since the sprint it was built in. Trace the costliest incidents of the past few years back to their first step and a surprising number start in exactly this kind of software, while the damage rarely stays inside IT: a recent analysis of the financial impact of a cyberattack shows how quickly an intrusion becomes a cash flow and credit problem for the entire company. This post looks at the other end of that chain, the unglamorous internal tooling where the money starts leaking, and at what developers can change in it before the next quarter closes.

Follow the Receipts

Start with the cleanest example. In May 2025 Coinbase disclosed that criminals had bribed support contractors and employees outside the United States to pull customer records out of the company's own support tools. There was no exploit and no malware. The insiders used access they legitimately had to collect names, home addresses, government ID images, masked bank details and account balances for 69,461 customers, and the buyers used that data to phone victims while posing as Coinbase. The company refused a $20 million extortion demand, then booked $307 million in expenses tied to the incident in a single quarter. The detail worth sitting with is that Coinbase's own monitoring had flagged support staff accessing data without a business need months before the extortion email arrived. The signal existed. A console that never asks why a record is being opened can only report abuse after it has happened.

The help desk is the same story told over the phone. According to Bloomberg's reporting on the MGM Resorts breach, the 2023 attack that disrupted MGM's resorts and casinos across the US began when attackers talked their way past the company's IT service desk. MGM later estimated a hit of roughly $100 million to its adjusted property EBITDAR, plus under $10 million in one-time costs. Clorox describes a similar opening move in the $380 million lawsuit it filed against Cognizant in July 2025, alleging that outsourced help desk agents reset passwords and MFA for an attacker without checking who was calling. Cognizant rejects the claims and says it was hired for a narrow scope of work. CISA and the FBI have described the same playbook in their joint advisory on Scattered Spider: impersonate an employee, call the help desk, walk away with a fresh password and a new MFA device. Whoever wins the lawsuit, the attack path was a reset workflow, and somebody designed that workflow.

Then there are the accounts that aren't people. In 2023 an attacker entered Okta's customer support system with a service account that could view and update support cases. Okta's own root cause analysis found that the account's username and password had been saved to an employee's personal Google profile, signed in on a company laptop. Inside the support system sat HAR files that customers had uploaded for troubleshooting, session tokens included. The attacker reached files belonging to 134 customers and used them to hijack sessions at several of them. Okta's stock closed down about 11.5% on the day of disclosure, and more than $2 billion of market value was gone within two trading sessions.

Finally, the integrations. In 2025 attackers spent months inside a Salesloft GitHub account, moved into the AWS environment behind its Drift chat product and left with the OAuth tokens that Drift customers had granted to connect it with Salesforce. Google's threat intelligence team said it was aware of at least 700 affected organizations. Because many of them used the integration for customer support, much of what leaked came from support tickets, and support tickets are where people paste things they shouldn't. Salesloft said the attackers pulled secrets such as AWS access keys, passwords and Snowflake tokens out of that data.

Why Attackers Shop in the Back Office

None of this is bad luck. Internal tools concentrate privilege by design: they exist to do what the product deliberately won't let a user do, such as view anyone's data, change anyone's email, reset anyone's MFA or move anyone's money. They are run by big, frequently outsourced teams, which means more people who can be tricked, exhausted or bought. In the help desk's case, they are authenticated by a human listening to a voice on a phone line. And they rarely get the threat modeling that customer-facing code receives, because "only staff can reach it" feels like a security control when it is really a fact about the network.

The economics are moving in the wrong direction. IBM's analysis of its 2026 Cost of a Data Breach findings puts the global average breach at a record $4.99 million and notes that fewer than half of organizations are actively securing non-human identities, the service accounts and tokens at the heart of the Okta and Drift stories. IBM's release on the same report adds that one in four malicious breaches is now AI-enabled, mostly through deepfake impersonation and AI-enabled malware, at an average cost of about $6 million. Put plainly, the caller asking your help desk for an MFA reset may not be a person at all, and "the agent recognized the voice" no longer counts as verification.

Treat the Back Office Like Production

The fixes are not exotic. Most of them are ordinary engineering work that never reached a roadmap because the tool was "internal":

  • Make every lookup carry a reason. Tie record access to an open ticket or case ID, mask sensitive fields by default and log every reveal. Bulk harvesting becomes slow, noisy and attributable.
  • Put budgets on human queries. Rate limits shouldn't stop at the public API. Alert when an agent opens far more accounts than their queue explains, or starts browsing customers nobody assigned to them.
  • Never let a voice authorize a reset. MFA resets, email and phone changes and payout address updates should require a push to an already enrolled device, a callback to a number on file or a second approver, and the UI should make skipping that step impossible rather than merely discouraged.
  • Give machine credentials an expiry date. Service accounts and OAuth grants need narrow scopes, short lifetimes, a named owner and a place in an inventory. A token that has worked for two years without anyone touching it is a finding, not a convenience.
  • Scrub secrets at the door. Strip cookies and authorization headers from HAR files on upload, scan ticket bodies for keys and expire attachments when a case closes.
  • Log for the worst day. Keep audit trails the support organization cannot edit, store them where a stolen session cannot reach, and make "who viewed this customer last month" a query that returns in seconds.

None of these items requires a new vendor. They require someone to open the admin panel's repository with the same suspicion they bring to the login page.

Pricing the Fix

The hard part is rarely the code. It is convincing a roadmap that internal tooling deserves engineering time when no customer will ever notice the change. Money is the argument that lands, and the incidents above make it unusually easy to price. Ticket-scoped access, per-agent query budgets and a hardened reset flow are measured in sprints, not years. Set that against $307 million in one quarter at Coinbase or the $380 million claim Clorox took to court. IBM's data supplies a second lever: detection and escalation together with lost business make up 63% of breach costs, so an audit trail that answers questions in seconds is not paperwork. It is a direct cut to the most expensive line items.

Phrase the risk the way finance already thinks. "The support console has broad read access" gets a polite nod and is forgotten by Friday. "One bribed contractor could export our customer list, and the last company this happened to spent $307 million cleaning up" gets a ticket scheduled. One sentence like that usually does more than a twelve-page threat model.

The attackers in these stories did not need a zero-day. They needed a search box that asked no questions, a reset button that trusted a voice, a token nobody remembered issuing and a ticket queue full of pasted secrets. Every one of those was built on purpose by someone shipping under a deadline, which means the people best placed to take them apart are the developers reading this, ideally before an extortion email does the code review for them.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.