Research Library / Case Studies /

Financial Services (Digital Lending, Insurance, Mutual Funds)

The Money Heist: A Red Team Assessment of a Financial Services Organization

One phishing email. One vished phone call. One cloned ID lifted from a social media photo. That's all it took for Payatu's Bandits to walk straight into a $100 million financial company's office, past a guard who let them in on a single word: 'yes.'
Red Team Assessment

At a glance

INDUSTRY

Financial Services (Digital Lending, Insurance, Mutual Funds)

CLIENT PROFILE

$100 million revenue financial services company offering digital loans, home loans, microloans, mutual funds and health insurance

SERVICES

Red Team Assessment

ENGAGEMENT

Full-scope red team assessment covering web, network, cloud, social engineering and physical pentesting

Key Takeaways

  • Client – A $100 million revenue-generating financial services company offering digital loans, home loans, microloans, mutual funds and health insurance.

  • Problem – The client needed to know whether an attacker could realistically breach its systems and physical premises, given the highly confidential financial data it holds on customers.

  • What Payatu did – Our Bandits ran a full red team assessment spanning web, network and cloud reconnaissance, phishing and vishing campaigns, credential-based lateral movement, and physical pentesting that included cloning an employee ID badge sourced from a social media post to walk into the client's office.

  • Outcome – We identified 2 high-severity and 2 low-severity findings, including successful credential theft via phishing and vishing and physical entry to the premises, each paired with concrete recommendations on FIDO keys, access control and security awareness training.

the challenge

Why the client called us in

Every piece of information this client held, digital and physical, was highly confidential, and there was only one real way to test that: put it in front of an actual attacker. As a financial services provider handling digital loans, mutual funds and health insurance, a breach here meant more than lost data, it meant direct financial and reputational fallout. The client brought in Payatu Bandits to hit its people and its infrastructure at once, web, network, cloud and physical premises, all fair game.

  • Identify ways an attacker could gain access to sensitive data and internal networks
  • Test employee resilience against phishing, vishing and other social engineering
  • Assess whether the client's physical premises and wireless networks could be breached

scope of engagement

What was in scope

  1. Web servers, applications and mobile assets reachable from the internet
  2. Network infrastructure and cloud assets
  3. Social engineering attacks, including phishing and vishing campaigns
  4. Physical pentesting of the client's premises, including gaining physical access
  5. Compromise of on-site wireless networks

Our Approach

How Payatu ran the engagement

01

Reconnaissance
The Bandits ran both active reconnaissance, engaging directly with the client's infrastructure, and passive reconnaissance to build a picture of the target without touching it.

02

Initial Compromise
We ran phishing email and vishing call campaigns in parallel to steal employee credentials.

03

Establish Persistence
We used the stolen credentials to log into enterprise applications and maintain access.

04

Post-Exploitation and Lateral Movement
We escalated access using the captured credentials and worked toward the client's crown jewels.

05

Data Exfiltration
We identified sensitive customer data and attempted to exfiltrate it through different channels to test the client's detection capability.

06

Physical Pentesting
Separately, the Bandits mined social media for an employee's ID card, morphed it onto their own photos, and used the cloned badge to walk into the client's office, gathering credentials left on sticky notes before testing the exit controls.

Key findings

What we found

HIGH
Employee Credentials Compromised via Phishing and Vishing
We phished and vished client employees together and used the stolen credentials to log into their Google Workspace accounts.
HIGH
Physical Impersonation of Employees
We used a cloned employee ID card, sourced from a social media post, to enter and leave the client's premises undetected.

the outcome

Results and Impact

The assessment proved that both the client's technical controls and its physical security could be bypassed by a motivated attacker, from stolen Google Workspace credentials to a walk-in physical breach using a cloned ID badge. Each finding was paired with specific, prioritized recommendations spanning security awareness training, FIDO-based authentication and physical access control.

‍

  • 2 high-severity and 2 low-severity findings identified across digital and physical attack surfaces

  • Successful credential theft demonstrated via combined phishing and vishing campaigns

  • Physical entry to the client's office achieved using a cloned employee ID badge

  • Recommendations delivered on FIDO keys, access control policies and anti-tailgating measures for physical zones

  • Employee awareness training priorities identified for social engineering resilience

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment