A new checkout service deployment relying on third-party APIs wasn’t checking validating authorization controls for certain types of API calls, where attackers used a masked application user role to enter into this company’s application internals and initiate a lateral attack. The attacker could now recon and identify multiple open internal endpoints to exploit as they moved laterally to eventually reach sensitive end-user data. The breach in the checkout service instance allowed the attacker to hop through the recommendation service and payment service instances, eventually stealing PII and payments data stored in their AWS S3 bucket, causing a major data breach through multiple attack paths.
Get a TrialOnly Operant is able to stop this kind of unauthorized access and lateral movement because Operant understands all the runtime activities across every layer of the application and can enforce multiple security policies within your environment: