Skip to content
Kodesec × Integrated-Systems.ai
KODESEC

Broken Access Control: The #1 OWASP Vulnerability That Can Sink a Business

Broken Access Control is the digital version of a hotel key card that accidentally opens every room in the building instead of just one.

Kodesec Research 8 min read

Broken Access Control: The #1 OWASP Security Vulnerability

If you run a business, you've probably heard the phrase "data breach" in the news more times this year than you'd like. What you may not know is that a huge share of those breaches trace back to one single, avoidable problem: Broken Access Control.

It sounds technical. It isn't, once you strip away the jargon. Broken Access Control simply means the wrong person was allowed to see or do something they should never have had access to — a customer viewing someone else's invoice, an ex-employee still able to log into company files, or a stranger on the internet pulling up thousands of private records just by changing a number in a web address.

This single category of weakness is officially ranked as the #1 risk on the OWASP Top 10 — the industry's most trusted list of the most dangerous web application security risks. And it doesn't just cost engineering teams a headache. It costs businesses money, customers, and reputation.

This article breaks down what Broken Access Control is, why it sits at the top of the OWASP list, how it hits your business and your customers differently, and three real breaches that show exactly what happens when it goes wrong.


What Exactly Is "Access Control," and How Does It Break?

Think of access control as the security guard, the ID badge, and the locked door of your digital business. It decides:

  • Who is allowed to log in
  • What they're allowed to see once they're in
  • What actions they're allowed to take

Broken Access Control happens when that "digital security guard" has a gap — a door that should be locked but isn't, or an ID badge that lets someone into rooms they were never approved for.

In plain business terms, it's the digital version of a hotel key card that accidentally opens every room in the building instead of just one.

Proper Access Control vs Broken Access Control

Why OWASP Ranks It #1 — In Plain English

OWASP (the Open Web Application Security Project) is the closest thing the security world has to a global rulebook. Every few years, they publish the "OWASP Top 10" — a ranked list of the most critical risks facing web applications.

In the most recent major update, Broken Access Control jumped from the 5th spot all the way to 1st place. Their research found that roughly 94% of applications tested had some form of broken access control somewhere in them.

Why does this matter to a non-technical business leader? Because it means this isn't a rare, exotic hacking technique reserved for movie-villain hackers. It's a common, everyday mistake that shows up in almost every piece of software built — including, quite possibly, yours.


The Business Side: What Broken Access Control Actually Costs You

For a business owner, this isn't an "IT problem." It's a business-continuity problem. Here's what's really at stake:

  • Regulatory fines — Data protection laws (GDPR, CCPA, and local equivalents) treat unauthorized data exposure as a serious violation, often with penalties tied to global revenue, not just the data involved.
  • Legal exposure — Affected customers, partners, and regulators can and do sue.
  • Loss of customer trust — Trust, once broken, is expensive to rebuild — and some customers simply never come back.
  • Operational disruption — Investigating a breach, notifying customers, and patching systems pulls your best people away from actual business work for weeks or months.
  • Competitive disadvantage — In B2B relationships, a breach can disqualify you from contracts that require security certifications.

The Client Side: What It Feels Like for the Customer

Business owners often think of a breach in terms of dollars and headlines. But for the person on the other end — your customer — it's personal:

  • Their private information is now out of their control — bank details, medical records, home addresses, ID numbers.
  • They face real risk of identity theft, fraud, or targeted scams built from the leaked data.
  • They lose confidence in every company they share data with, not just yours.
  • They have to spend their own time and money monitoring accounts, freezing credit, or resetting passwords.

This is the part that's easy to forget in a boardroom conversation about "risk" — a breach isn't an abstract statistic. It's a real person finding out a stranger could see their financial records simply because your application forgot to check who was asking.


Real-World Case Studies: When Broken Access Control Went Public

Case Study 1 — First American Financial Corp. (2019)

First American Financial, one of the largest title insurance companies in the United States, exposed approximately 885 million mortgage-related documents dating back to 2003. The flaw was an insecure direct object reference — anyone who knew the web address of one document could view any other document simply by changing a number in that link, no login required.

The exposed files included bank account numbers and statements, mortgage and tax records, Social Security numbers, wire transaction receipts, and driver's license images — all sitting in the open for anyone with a browser. The company was later fined and investigated by state regulators over the incident.

Business lesson: A single overlooked permission check on one internal application put over a decade's worth of highly sensitive customer financial data at risk — with zero hacking skill required to exploit it.

Case Study 2 — Optus, Australia (2022)

Optus, Australia's second-largest telecom provider, suffered a breach affecting close to 10 million current and former customers — over a third of Australia's population. The information exposed included names, dates of birth, home addresses, phone numbers, email addresses, and passport and driver's license numbers.

Investigators later traced the breach to a coding error in the access control protecting an API that connected the customer portal to Optus's backend database — an internet-facing endpoint that had gone unsecured for years. Regulators described the method as unsophisticated, carried out simply by trial and error rather than advanced hacking skill.

Business lesson: The regulator is now pursuing the company for penalties partly because the same coding flaw had already been caught and fixed on the main website years earlier — but never fixed on the connected API. One overlooked corner of the system was enough.

Case Study 3 — The 2024 Snowflake-Linked Breaches (AT&T, Ticketmaster, and Others)

In 2024, attackers breached over 160 customer environments hosted on the Snowflake data platform — including major names like AT&T and Ticketmaster — largely because of missing access validations, exposing billions of records.

Business lesson: Even when you trust a major cloud platform, access control is still a shared responsibility. If your own account-level protections (like requiring multi-factor authentication) aren't enforced, attackers don't need to break into the platform at all — they just need to be let in the front door.


How This Actually Happens (No Jargon Version)

You don't need to understand code to understand the root causes. Almost every real-world case comes down to one of these:

  1. Missing checks — The system never asks "does this specific user actually own this specific piece of data?" before showing it.
  2. Guessable links or IDs — Data is reachable by simply changing a number or code in a web address (like the First American case).
  3. Forgotten corners of the system — Old, unused, or "internal only" tools are left connected to the internet without protection (like the Optus case).
  4. Trusting the front door too much — Assuming that if someone got past login, they must be allowed to see everything (like the Snowflake-linked breaches).

Common Causes of Broken Access Control: Missing Checks, Guessable IDs, Forgotten Corners, and Over-trusting Login

What Business Leaders Should Ask Their Teams

You don't need to become a security expert. You just need to ask the right questions and expect real answers:

  • ✅ Does every feature check who is asking, not just whether they're logged in?
  • ✅ Are old tools, admin panels, and APIs regularly reviewed and shut down if unused?
  • ✅ Do we test our own application the way an attacker would — by trying to access things we shouldn't?
  • ✅ Is access reviewed whenever an employee changes roles or leaves the company?
  • ✅ Do we have a written plan for what happens in the first 24 hours if something like this is discovered?

If your team can't answer these confidently, that's the real warning sign — long before any breach happens.


The Bottom Line

Broken Access Control isn't a rare, sophisticated attack technique. It's the digital equivalent of forgetting to lock an office door — and the OWASP Top 10 ranks it #1 precisely because it's so common and so damaging when it's missed.

For a business, the cost isn't measured only in fines. It's measured in trust, in customer relationships, and sometimes in the company's ability to keep operating normally. For the customer, it's measured in real personal risk they never signed up for.

The good news: this is one of the most preventable categories of security failure. It doesn't require exotic defenses — it requires discipline, regular review, and a culture where "who is allowed to see this?" is asked before every feature ships, not after a breach forces the question.


References

  1. Rakuten India, Broken Access Control: The #1 Security Risk in OWASP Top 10 — https://sixthsense.rakuten.com/api-security/blog/broken-access-control-owasp-top-10
  2. Krebs on Security, First American Financial Corp. Leaked Hundreds of Millions of Title Insurance Records (May 2019) — https://krebsonsecurity.com/2019/05/first-american-financial-corp-leaked-hundreds-of-millions-of-title-insurance-records/
  3. SecurityWeek, First American Financial Exposed Millions of Sensitive Documents — https://www.securityweek.com/first-american-financial-exposed-millions-sensitive-documents
  4. Wikipedia, 2022 Optus data breach — https://en.wikipedia.org/wiki/2022_Optus_data_breach
  5. BankInfoSecurity, Australia Optus 2022 Data Breach 'Not Highly Sophisticated' — https://www.bankinfosecurity.com/australia-optus-2022-data-breach-not-highly-sophisticated-a-25594
  6. CPO Magazine, Australian Authorities Trace Optus Data Breach to Access Control Coding Error — https://www.cpomagazine.com/cyber-security/australian-authorities-trace-optus-data-breach-to-access-control-coding-error-may-seek-hundreds-of-millions-in-penalties/
  7. OWASP Foundation, A01:2021 – Broken Access Control — https://owasp.org/Top10/A01_2021-Broken_Access_Control/

Written for business owners and decision-makers who want to understand cybersecurity risk without needing a technical background.

  • #owasp
  • #access control
  • #web security

Written by

Kodesec ResearchResearch team

All articles

Keep reading