Financial Services (Digital Lending, Insurance, Mutual Funds)
The Money Heist: A Red Team Assessment of a Financial Services Organization
At a glance
INDUSTRY
Financial Services (Digital Lending, Insurance, Mutual Funds)
CLIENT PROFILE
$100 million revenue financial services company offering digital loans, home loans, microloans, mutual funds and health insurance
SERVICES
Red Team Assessment
ENGAGEMENT
Full-scope red team assessment covering web, network, cloud, social engineering and physical pentesting

Key Takeaways
Client – A $100 million revenue-generating financial services company offering digital loans, home loans, microloans, mutual funds and health insurance.
Problem – The client needed to know whether an attacker could realistically breach its systems and physical premises, given the highly confidential financial data it holds on customers.
What Payatu did – Our Bandits ran a full red team assessment spanning web, network and cloud reconnaissance, phishing and vishing campaigns, credential-based lateral movement, and physical pentesting that included cloning an employee ID badge sourced from a social media post to walk into the client's office.
Outcome – We identified 2 high-severity and 2 low-severity findings, including successful credential theft via phishing and vishing and physical entry to the premises, each paired with concrete recommendations on FIDO keys, access control and security awareness training.
the challenge
Why the client called us in
Every piece of information this client held, digital and physical, was highly confidential, and there was only one real way to test that: put it in front of an actual attacker. As a financial services provider handling digital loans, mutual funds and health insurance, a breach here meant more than lost data, it meant direct financial and reputational fallout. The client brought in Payatu Bandits to hit its people and its infrastructure at once, web, network, cloud and physical premises, all fair game.
- Identify ways an attacker could gain access to sensitive data and internal networks
- Test employee resilience against phishing, vishing and other social engineering
- Assess whether the client's physical premises and wireless networks could be breached
scope of engagement
What was in scope
- Web servers, applications and mobile assets reachable from the internet
- Network infrastructure and cloud assets
- Social engineering attacks, including phishing and vishing campaigns
- Physical pentesting of the client's premises, including gaining physical access
- Compromise of on-site wireless networks
Our Approach
How Payatu ran the engagement
01
02
03
04
05
06
Key findings
What we found
the outcome
Results and Impact
The assessment proved that both the client's technical controls and its physical security could be bypassed by a motivated attacker, from stolen Google Workspace credentials to a walk-in physical breach using a cloned ID badge. Each finding was paired with specific, prioritized recommendations spanning security awareness training, FIDO-based authentication and physical access control.
2 high-severity and 2 low-severity findings identified across digital and physical attack surfaces
Successful credential theft demonstrated via combined phishing and vishing campaigns
Physical entry to the client's office achieved using a cloned employee ID badge
Recommendations delivered on FIDO keys, access control policies and anti-tailgating measures for physical zones
Employee awareness training priorities identified for social engineering resilience
Get the full case study
Download the complete PDF - full methodology, findings and remediation detail.

.png)







