ShadowSec Lab

Fintech · Northline Payments

Broken object-level authorization in a live payments API

A ten-day web and API assessment against Northline’s merchant dashboard. We demonstrated that a low-privilege operator could retrieve settlement records for other merchants through a predictable identifier — then worked with their team on a regression test.

  • Critical access-control issue closed in 72 hours
  • Authorization test suite added to CI
  • Follow-on cloud review commissioned the same quarter
Start a similar engagement
Daniel Cho, CTO
They found an authorization gap our own scanners had marked as informational. We shipped the fix before the next card-scheme review.

Daniel Cho, CTO

Next step

Tell us what you need answered.

A 30-minute scoping call is enough to know whether a pentest, a cloud review, or a retainer is the right buy. We will say if it is not.