Open Banking APIs: what the scanner missed

Open Banking lets outside apps connect to a bank through APIs, the interfaces that let software systems exchange data. If one of those APIs checks the wrong thing, a customer may be able to reach someone else’s account. This bank’s scanner had reported no critical issues, yet manual testing found a flaw that could move money between accounts.

The situation

A digital bank was three weeks away from launching 42 Open Banking APIs. Its automated scanner reported zero critical findings. The bank’s QSA, the independent assessor who confirms PCI DSS compliance, still needed penetration testing evidence under PCI DSS 4.0 requirement 11.3.

The QSA also wanted coverage of two weaknesses from the OWASP API Security Top 10. These are broken object-level authorization (BOLA), where a user can reach another user’s records, and broken function-level authorization (BFLA), where a user can perform actions reserved for someone else. A typical six-week test would not fit the timeline.

How we approached it

We began with a 90-minute scoping workshop with the bank’s mobile and API teams. The goal was to understand how users log in and how permissions pass between systems, because that is where authorization flaws tend to hide.

Our testers then worked through the APIs by hand. They looked for BOLA and BFLA, insecure direct object references (IDOR) and mass assignment, where an API accepts fields it should ignore. Two issues that looked minor on their own could be chained into a full account takeover, and we showed this with a working proof of concept.

The report arrived within our usual 10 days. It contained a one-page risk summary for the board and 18 findings ranked by how easily they could be exploited. Each finding was mapped to PCI DSS, SOC 2 and ISO/IEC 27001, and a retest was part of the engagement.

What happened next

The bank fixed the critical chain, and our retest confirmed it was closed. The QSA accepted the testing evidence and the launch went ahead as planned. The bank now runs continuous testing on every API release through FOCTOS, a Snipeyes company.

What other banks can take from this

Scanners are good at spotting known technical flaws. They rarely understand who should be allowed to see which account. That is a business logic question, and it takes a person to test it properly. For any API that can move money, ask for manual authorization testing before launch.