Did anyone else see the Auckland store whose website got taken over by the internet the other week? Someone built their online store on an AI app builder and the top menu, the one every customer sees, went Home, Hot Food Menu, Admin Dashboard, Manage Menu, Manage Orders. No login. Within a day it had hundreds of orders and a bestseller called “Just pay a web developer”. The orders page was public too, so the names, emails and phone numbers real customers had typed in were sitting there for anyone.
Stuff covered it and didn’t name the store, which was kind. The internet was less kind. By Wednesday the shop was advertising a pair of crusty socks, a Princess Diana commemorative plate and national parks to the highest bidder. The promo codes were editable too, so “free” worked at checkout. At one point the owner started arguing with the public through their own product listings. They added an item called “stop hacking us”. Someone replied with one called “don’t use an AI site builder then”. The site came down around lunchtime, after at least two hours in the open.
I laughed for about a minute, then didn’t, because Kody and I are three weeks into a new client with the same problem minus the funny bits.
It’s worse in a boring way
Nobody vandalised anything at our client’s place. It’s worse in a boring way. One password running the Google account, the website, the booking system and Instagram, emailed around to whoever needed it. Customer ID documents and card details sitting with five different software companies and no agreement with any of them about what they can do with it. An email domain anyone could send from and it would look real. And middleware between two systems that works about half the time and costs a few hundred bucks a month.
I’m not naming them. None of it is their fault, they didn’t build any of it, and they’re the ones paying to sort it out.
The grown up in the room
My biggest concern is the platform. The store’s site was built on Base44, one of the bigger no code AI builders, owned by Wix. That’s the product you pick over pasting prompts into Claude yourself because it’s supposed to be the grown up in the room, handling logins, who’s an admin, and what’s live versus still being built. If a hot food shop can end up with Manage Orders in the public nav on one of those platforms, I don’t know what the platform is for. The tool got paid and the owner got the headline.
It isn’t even the first scare. Security researchers found holes in Base44 last year that could’ve let strangers into apps built on it. Those got patched. Maybe this one was a setting the owner never saw. That’s sort of the point. If the whole pitch is that the platform handles the dangerous bits for you, the dangerous bits shouldn’t be one unticked box away.
Now the AI is on the other side too
In June an OpenAI agent was doing research on Australian medical spending, hit the blocks on the government’s Medicare statistics portal and found a way round them. The Prime Minister’s words were that it “didn’t accept no for an answer”. Nobody at Medicare noticed. OpenAI found it in its own review in August, and the government heard about it in September, nearly three months later. OpenAI says no patient records were touched.
Closer to home, Manage My Health didn’t spot its own breach last Christmas either. Health NZ had to tell them, after someone had spent days going through patients’ records on one stolen password.
Those are organisations with real security budgets. Your booking system doesn’t have one. And the thing testing whether your admin page needs a login might not be a person anymore.
Find out what you’ve got
We build with AI every day, so I’m not telling anyone to stop. I’m telling you to find out what you’ve got. Here’s the ten minute version.
- Open your website on your phone, logged out of everything. If you can see anything that says admin, manage, dashboard or orders, so can everyone else.
- Ask where your passwords live. If the answer is an email thread, a spreadsheet, or one password the whole team shares, start there.
- Write down which companies hold your customers’ details. ID documents, cards, phone numbers. If there’s no agreement about what they can do with it, that’s your problem under the Privacy Act, not just theirs.
- Ask whether someone could send an email that looks like it came from your domain. Three DNS records fix most of it, and most small businesses are missing at least one.
- Ask what you’d still own if your builder or developer vanished tomorrow. Logins, code, domain, data. If you can’t answer that, you don’t own it.
Most owners I ask can’t get past two of these. That’s normal, and it’s fixable.
The unglamorous half
This is the unglamorous half of what we do for clients. Every login, API and auth key sits in a secrets store, not in the code, not in emails, and not somewhere the AI can read it. Email domains get fixed so they can’t be spoofed. Backends aren’t visible to the public or sitting on guessable URLs with no real login. And we rebuild the bits that don’t work or were set up dodgily by well-meaning AI prompting.
Nothing we build leaves without it. Admin and customer are separate logins. There’s a written map of what talks to what. And the client owns the lot, so if we vanished tomorrow they’d still have the keys. If your tool doesn’t give you that, you’re paying for a nicer prompt box.
It shouldn’t be embarrassing
I don’t think people talk about this because it’s embarrassing, and it shouldn’t be. The owner in that story didn’t do anything unusual. They used a popular tool the way it was marketed. The only difference between them and a few thousand other NZ businesses is that the internet found theirs first.
So find out what you’ve got. Ask who can see it and who can change it. If you can’t answer, get someone to walk through it with you. It’s an hour, and it’s a lot cheaper than being the next screenshot.




