Skip to the content

A security audit before card acquiring went live

The bank asked for a test report. We found access to other customers’ orders via a direct link, and a promo code that applied twice.

Client
E-commerce, 40 staff
Industry
Retail
Year
2026
Duration
7 working days
The problem

The shop was moving to direct card acquiring, and the bank required an independent test report. There was no in-house security team.

Solution

What we did
and why we did it that way.

01

Reconnaissance

We found a forgotten test environment holding a copy of the production database, open to the internet.

02

Logic flaws

The scanner produced 2 findings, manual testing another 12. The most expensive one was access to someone else’s order via the number in the URL.

03

The economics of a vulnerability

A promo code applied twice under concurrent requests. We worked out what that would have cost over a quarter.

04

Retest

After the team’s fixes we re-ran the scenarios at no charge—two of the findings had not been fully closed.

Result

What changed
and what we measured it with.

14
findings, 3 critical
7
working days for the whole audit
100%
of critical findings closed before acquiring went live
1forgotten environment holding production data
Stack
OWASP Top-10Burp SuiteSemgrepTrivyCVSS
Timeline

How it went
day by day and week by week.

  1. Day 1

    Scope and NDA

    We fixed the perimeter and ruled out destructive testing.

  2. Days 2–3

    Reconnaissance

    Subdomains, environments, entry points.

  3. Days 4–6

    Exploitation

    Critical findings were sent over immediately, without waiting for the report.

  4. Day 7

    Report

    Priorities, proof of concept, a summary for management.

Screens

How it looks
in schematics.

These are screen schematics. We do not publish client interfaces without permission

Next

A similar problem
on your side?

Describe it in the brief. In working hours we come back with an estimate of time and cost within two hours.