Securing 200+ APIs for a Tier-1 Payments Platform
BOLA and BFLA vulnerabilities in payment flows discovered and fixed with zero false positives
Client: Major UPI Payments Platform
The Challenge
RBI Mandate and Rapid API Growth Outpaced Security Reviews
A UPI payments platform processing 800M+ transactions monthly had scaled from 40 to 200+ APIs in 18 months. Their automated API scanning tools were generating 3,000+ findings per scan, mostly false positives, which made real threats impossible to identify. An RBI circular on API security testing required evidence of manual expert assessment.
- 200+ APIs across payments, merchant onboarding, KYC, and settlement services
- Automated scanners producing 3,000+ findings with 85%+ false positive rate
- Payment flow APIs handling sensitive UPI VPA and bank account data
- RBI mandate for API-specific security testing with CERT-In empanelled auditor
The Solution
Manual API Security Assessment with Business Logic Focus
Security Brigade conducted a deep-dive manual API security assessment across all 200+ endpoints, focusing on business logic flaws that automated tools miss. Each API was tested against OWASP API Top 10 with custom test cases for payment-specific attack vectors. The B-52 engine ensured every endpoint was covered, and the Lemon platform provided real-time tracking of findings with zero false positives.
Services used
Our approach
- 01Phase 1: API inventory reconciliation. Found 34 undocumented shadow APIs not in the client registry
- 02Phase 2: Authentication and authorisation testing. BOLA and BFLA checks across all payment flows with role-based matrices
- 03Phase 3: Business logic testing. Rate limiting bypass, transaction amount manipulation, concurrent request race conditions
- 04Phase 4: Remediation verification. Each fix retested within 48 hours via Lemon and signed off with evidence
The Results
17 Critical API Vulnerabilities Fixed with Zero False Positives
Identified 17 critical and 43 high-severity vulnerabilities across payment APIs, including BOLA flaws that could have allowed unauthorized access to transaction histories of any user. All findings were verified as true positives before delivery.
Ready to discuss your security needs?
Talk to our team about a similar engagement for your organisation.
Request a Scoping Call