Back to case studies
FinTech 3 weeks
API Security Testing
API Security Assessment
A FinTech provider needed assurance over open-banking APIs handling payments and account aggregation. We mapped every endpoint and identified broken object-level authorization on several transaction routes.
Engagement scope: 42 REST endpoints, 1 GraphQL gateway
42Endpoints tested
3BOLA findings
0.81Avg EPSS
Engagement Objectives
- Validate OAuth 2.0 and token handling
- Test object-level authorization on payment routes
- Assess rate limiting and abuse resistance
Approach
We began with a scoping workshop to align on in-scope assets, rules of engagement, and success criteria. Over the following weeks, our consultants applied a manual-first methodology aligned to API Security Testing, validating every finding before reporting and coordinating closely with the client's engineering team.
Outcome
We demonstrated unauthorized access to transaction history via a BOLA flaw and recommended schema enforcement and per-object checks. All findings were remediated within the sprint cycle.
What We Delivered
Executive summary for leadership
Technical report with reproducible PoCs
CVSSv3.1 scored findings
Remediation walkthrough with engineers
Attack-path visualization
Free retest to confirm closure