Digital Transformation, Security & Protection
Security Assessment of an International Event's Android Application
At a glance
INDUSTRY
Digital Transformation, Security & Protection
CLIENT PROFILE
A digital transformation organization building the official app for a major international event
SERVICES
Mobile (Android) Security Assessment, Black-Box Penetration Testing
ENGAGEMENT
Pre-launch Android app security assessment

Key Takeaways
Client – A digital transformation organization building the Android app for a six-month international event held on a truly global stage.
Problem – The app needed to be tested for vulnerabilities that could lead to a major data leak, loss of goodwill, or reputational damage before it reached a global audience.
What Payatu did – Payatu Bandits ran black-box static and dynamic testing of the Android app, mapping findings to the OWASP Mobile Top 10, including login bypass attempts with tools like Drozer.
Outcome – Payatu delivered findings and remediation steps covering database hardening, server and authentication configuration, and third- party module updates ahead of the event.
the challenge
Why the client called us in
The client, a digital transformation organization based in the UAE, was building the Android app for a distinguished international event running six months and drawing 192 participating nations. Any anomaly in the app risked a major data leak, loss of goodwill, and reputational damage at a global scale, so the client needed the app tested and hardened before it reached that audience. It brought in Payatu to simulate real-world attackers against the app and its guest functionality.
- Identify and exploit vulnerabilities in the Android app before launch
- Test the app's guest functionality under real-world attack conditions
- Get clear, actionable remediation steps ahead of the event
scope of engagement
What was in scope
- Comprehensive analysis of the Android mobile application
- Android mobile application testing
- Black-box testing
- Testing the guest functionality
- Reporting in the client's required format
Our Approach
How Payatu ran the engagement
01
02
03
Key findings
What we found
the outcome
Results and Impact
Working against the scale of an app meant to serve visitors from 192 nations, Payatu identified the vulnerabilities that mattered most, from database exposure to authentication weaknesses to server misconfiguration, and handed the client clear steps to close them before the event went live.
Tested the app's guest functionality against real-world attack scenarios
Mapped every finding to the OWASP Mobile Top 10
Flagged database exposure, server misconfiguration, and authentication issues
Delivered hardening recommendations for the database, server, and authentication flow
Get the full case study
Download the complete PDF - full methodology, findings and remediation detail.

.png)







