Overview
In a matter of minutes, a series of unauthorised BI-FAST transfers was processed through a payment aggregator's API integration. Every request passed authentication, and nothing in the system appeared abnormal.
DFI was appointed to find out how the investigation proved red flags and an error in code in the authentication tool. The fraud was carried out with legitimate access, and forensic analysis allowed DFI to separate the fraudulent activity from normal operations and identify where the compromise began.
Attack chain
Six steps, reconstructed from forensic evidence.
Actor
TTP: how the attack worked
Mapped to MITRE ATT&CK for Enterprise, to benchmark attack-level detection coverage.
IoC: what to look for
Behavioural indicators that can be turned into monitoring rules. Match to system behaviours, not just static signatures.
A partner's API traffic shifting away from its established profile.
Inconsistent metadata within the same request.
Authorisation tokens used in calls to non-partner official application user products.
Anomalous metadata in the request transaction.