CipherTest
boot sequence
loading offensive platform0%
CipherTest
Back to case studies
FinTech 3 weeks

API Security Testing

API Security Assessment

A FinTech provider needed assurance over open-banking APIs handling payments and account aggregation. We mapped every endpoint and identified broken object-level authorization on several transaction routes.

Engagement scope: 42 REST endpoints, 1 GraphQL gateway
42Endpoints tested
3BOLA findings
0.81Avg EPSS

Engagement Objectives

  • Validate OAuth 2.0 and token handling
  • Test object-level authorization on payment routes
  • Assess rate limiting and abuse resistance

Approach

We began with a scoping workshop to align on in-scope assets, rules of engagement, and success criteria. Over the following weeks, our consultants applied a manual-first methodology aligned to API Security Testing, validating every finding before reporting and coordinating closely with the client's engineering team.

Outcome

We demonstrated unauthorized access to transaction history via a BOLA flaw and recommended schema enforcement and per-object checks. All findings were remediated within the sprint cycle.

What We Delivered

Executive summary for leadership
Technical report with reproducible PoCs
CVSSv3.1 scored findings
Remediation walkthrough with engineers
Attack-path visualization
Free retest to confirm closure