From refresh token theft to global admin