Case studies: what we found and how it was fixed

These are real projects by Snipeyes, a CREST-accredited, ISO/IEC 27001:2022 certified cybersecurity firm in Jakarta. Client names have been removed. Each one shows what we tested, what kind of weakness we found and how the client closed it. Five cases come from systems that regulators watch closely, such as plant control systems, core banking and national payment services. Eighteen more show our automated testing, grouped into four categories.

In every case, findings were linked to the rules that applied: OJK and Bank Indonesia regulations, ISO/IEC 27001, SOC 2, PCI DSS 4.0, IEC 62443 or the relevant OWASP standard.

Systems regulators watch closely

SCADA/OT Penetration Testing

Testers moved from the office network into plant controllers using a historian password, a jump server and a vendor VPN. All testing ran on a lab copy. The retest confirmed every high-risk finding was closed.

BI SNAP API

We tested 27 endpoints of a bank's open-banking API. One flaw let a user divert funds from another account, and signed requests could be replayed. The critical chain was fixed in 4 days, and the auditor accepted the evidence.

Mobile Banking QRIS Module

Printed merchant QR codes could be swapped, and the app's SDK key could be intercepted. The bank moved to signed dynamic QR codes and certificate pinning. A retest confirmed all critical findings were closed before the QRIS audit.

AS/400 Core Banking (IBM i)

An over-privileged service account (*ALLOBJ) allowed direct database changes, and terminal sessions could be hijacked. The bank locked away its credentials and added encryption and access rules. All critical findings were closed within 48 hours.

BI-FAST Payment Module

A customer's proxy alias could be hijacked, and a missing duplicate check let one payment be credited twice. The fixes added OTP checks on alias changes and signed callbacks, and the module then went through BI-FAST certification.

Automated security testing by category

The eighteen cases are grouped by purpose: finding what you own, testing it, proving what is exploitable, and turning results into decisions. Each card opens the full case study.

CATEGORY 01 · DISCOVERY

Map everything exposed to the internet before you test it.

Attack Surface Discovery

The client's inventory listed 180 systems. We found 612 reachable from the internet, including forgotten cloud storage and debug APIs. The exposed items were closed within 9 days.

Digital Footprint Discovery

We found 214 official and 89 unofficial hosts, plus 12 look-alike domains. One of them was a live phishing site, which was taken down.

CATEGORY 02 · SECURITY TESTING

Automated testing per target: web, API, AI, identity, configuration and threat-based scenarios.

Automated Vulnerability Scanning

8,400 raw scanner results were narrowed down to 132 real findings. A cluster of remote code execution flaws was closed in 72 hours, and the PCI DSS assessor accepted the evidence.

Web Application Security Testing

Shoppers could check out for Rp0 by stacking vouchers and forging payment callbacks. Both flaws were fixed before the 11.11 sales campaign.

API Security Testing

The client documented 84 API endpoints; we found 121. Flaws let users see other people's balances and trigger reversals they should not reach. A retest confirmed the critical issues were closed.

AI Security Testing

Hidden instructions planted in content could trick an AI customer-service assistant into leaking internal procedures and offering double refunds. The fixes were retested against the same attacks.

Automated Penetration Testing

Testing proved that one customer of a SaaS platform could read another customer's invoices. The SOC 2 auditor accepted the evidence, and each weekly release is now tested.

Continuous Security Testing

A flaw that let users bypass the admin login was caught 35 minutes after the code was committed, before it reached production.

Credential & Identity Testing

A leaked GitHub token led all the way to single sign-on admin access. We also found OTP guessing and tampered login tokens. The takeover path was closed within 48 hours.

Configuration Security Testing

We found more than 300 cloud misconfigurations, including open storage, Kubernetes settings and firewall rules. Three weeks later, 12 remained. Alerts now flag new ones within 24 hours.

Threat-Based Testing

Copying a ransomware group's methods, we reached full control of the network (domain admin) in 26 hours. After the fixes, a rerun was stopped at the second step and the SOC raised an alert.

CATEGORY 03 · VALIDATION

Prove what is exploitable, map attack paths and verify that fixes actually close the issue.

Exploit Validation

A scanner flagged 540 issues as critical. Only 58 could really be exploited, so the team fixed those first instead of chasing all 540.

Attack Path Analysis

Six medium-rated findings, chained together, led from the guest Wi-Fi to the core database. Two fixes broke 11 of the 14 attack paths.

Automated Retesting

The first retest showed that many reported fixes had not worked. After a second round, every item was closed, with before-and-after evidence for each.

CATEGORY 04 · SECURITY INTELLIGENCE

Turn technical results into decisions for the board, the SOC and long-term operations.

Risk Intelligence

400 findings were turned into a 12-item plan that management agreed to fund.

Executive Intelligence

A 120-page technical report was condensed into one page for the board, which then approved the security budget.

Tactical Intelligence

Each finding came with a test payload, a monitoring query and a firewall rule, so the security team could detect and block it straight away.

Operational Intelligence

Fixes built into shared code templates, plus team scorecards, stopped the same vulnerabilities from coming back release after release.

Running a similar system?

Tell us about it. We start with a free 90-minute scoping session, and every project ends with a free retest of your fixes. Pricing is set per module.

Request Case Study Proposal
All case studies are redacted and protected by NDA. Proofs of concept run in UAT, staging or lab environments with rollback plans.

Chat on WhatsApp