The Challenge
The fintech runs a fast-growing digital payments platform: customer-facing apps, a web portal and a dense layer of APIs that move money and expose account data in real time. Rapid product growth had outpaced security review, and every new integration widened both the attack surface and the fraud surface.
As a business that touches customer funds and personal information, it is a high-value target for financially motivated attackers and organised fraud. It also operates under APRA CPS 234, which sets clear expectations for information security capability and for testing controls regularly. The security team needed an adversary-grade assessment that reflected how criminals actually attack payment platforms, covering the APIs, the web layer and the cloud that hosts them, so it could fortify its infrastructure and evidence its regulatory position.
Our Approach
StrikeCyber scoped a combined penetration test and adversary simulation, with a dedicated cloud security assessment, focused on the systems that process transactions and hold customer PII.
- Reconnaissance and external attack surface mapping using StrikeCyber's autonomous reconnaissance, part of our AI-augmented offensive security platform, to enumerate API endpoints, exposed services and OSINT-derived intelligence, including leaked secrets.
- API and web application penetration testing against authentication, authorisation and business logic, probing the payment flows a fraudster would target.
- Adversary simulation and a cloud security assessment, emulating techniques from MITRE ATT&CK across the cloud environment to test IAM, segmentation and detection.
Every automated finding was validated and exploited by hand by expert operators, so business-logic and authorisation flaws that scanners miss were confirmed with proof. Results streamed into a live client portal with AI-accelerated reporting, giving developers actionable detail while the test was still running.
What We Found
- Broken access control in the payment API. IDOR-style flaws let an authenticated user enumerate and access other customers' account and transaction data by manipulating object identifiers, a direct breach and fraud risk.
- Server-side request forgery (SSRF). An input in the web layer could be abused to reach internal services and the cloud metadata endpoint, a common stepping stone to credential theft in cloud environments.
- Secrets in code and cloud misconfiguration. Reconnaissance surfaced access keys committed to a repository, and over-permissive IAM roles plus a misconfigured storage bucket exposed sensitive data and widened the blast radius.
- Exploitable business logic and weak fraud controls. Gaps in transaction validation and rate limiting allowed request tampering and repetition that a fraud actor could turn into financial loss.
The Outcome
The fintech received a prioritised remediation plan mapped to CPS 234 control expectations and written for its engineering teams. The IDOR flaws were fixed with proper server-side authorisation checks, the SSRF path was closed and the metadata endpoint locked down, leaked secrets were rotated with repository scanning added, and the cloud IAM and storage misconfigurations were corrected to least privilege. Transaction validation and rate limiting were strengthened to blunt automated fraud.
A follow-up retest confirmed the critical and high findings were remediated and verified, that customer data could no longer be enumerated across accounts, and that the cloud attack paths were closed. The company reduced its external attack surface, hardened its payment infrastructure against real-world fraud techniques, and gained documented assurance to support its CPS 234 obligations and reinforce customer trust.
Why It Matters
For fintechs, the API layer is the product and the target at once, and the flaws that matter most are logic and authorisation errors no automated scan will confirm. Adversary-grade testing across APIs, web and cloud, validated by human operators, shows exactly how fraud and data theft would happen, turning a regulatory requirement into a genuine defence of customer funds and confidence. To harden your payment platform, get in touch.
