A new background check service that ingests sensitive customer data was pushed to prod at a FinTech company. The dev/staging environments did not enforce protocol security and endpoint validation, which meant that this API was left open to the public, just waiting to be discovered by attackers. When an attacker discovered the insecure http endpoints, they were quickly able to move laterally, causing a breach. This breach in the background check instance allowed the attacker to hop through to the internal services and access highly confidential PII data stored in their AWS S3 bucket, causing a major PR and regulatory issue for the company.
Get a TrialOnly Operant protects against this scenario with a powerful multi-step shield.