The Most Expensive Code You Ship Is the Admin Panel Nobody Reviews
Every product has a second application hiding behind it. It has no designer, no load tests and no on-call rotation, and its security model often amounts to a boolean called is_admin . Support agents use it to look up customers, reset passwords and issue refunds, a few service accounts talk to it overnight, and nobody has read its pull requests with real curiosity since the sprint it was built in.…
Every product possesses an internally focused application that goes unnoticed. This hidden code typically lacks design, testing, and monitoring, and relies on a simple "is_admin" boolean for security. Support agents frequently utilize this code to access customer information, reset passwords, and process refunds. Service accounts also connect to it, often without proper review or scrutiny.
This type of software has been linked to numerous costly incidents over the past few years, with the breaches' impact extending beyond IT to affect the company's financial health.
The most notable example comes from Coinbase in May 2025, where criminals bribed support staff and employees outside the United States to obtain customer data through legitimate access. The company later incurred a $307 million expense in a single quarter due to the incident. Coinbase's monitoring system had flagged unsupported data access months before the extortion email, highlighting the potential for abuse when no reason is required to open a record.
Another case is the MGM Resorts breach in 2023, where attackers impersonated IT service desk personnel to gain access to customer information, leading to an estimated $100 million loss for MGM. Clorox experienced a similar incident, where help desk agents unknowingly facilitated an attacker's entry by resetting passwords and MFA without verifying the caller's identity.
In 2023, Okta suffered from an attacker who gained access to their support system using a service account that had stored credentials on an employee's personal device, resulting in the hijacking of customer sessions and a 11.5% drop in the company's stock value.
Lastly, Salesloft's integration with Drift in 2025 saw attackers exploiting OAuth tokens, accessing customer data from support tickets. This threat is particularly concerning as many organizations rely on these integrations for customer support, inadvertently exposing sensitive information through support communications. The attackers targeted support workflows, which usually involve privileged operations, and are often managed by outsourced teams, making them prime targets for exploitation.
To mitigate these risks, organizations should treat their back-office tools as production systems, implementing access controls, logging, and monitoring to reduce abuse and potential breaches.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.