Skip to main content
All case studies
E-commerce

Red Team Engagement Exposes Full Kill Chain at a High-Growth Quick-Commerce Operator

Physical + digital attack simulation reveals path from lobby to production database in under 48 hours

Client: Leading Quick-Commerce Platform

48 hrs
Time from initial physical entry to production database access
23
Critical findings including 3 zero-day-equivalent misconfigurations
100%
Critical and high findings remediated before IPO filing
12M+
Customer records reachable through the attack chain

The Challenge

Board-Mandated Red Team Assessment Before IPO Roadshow

A $5B+ quick-commerce unicorn preparing for IPO needed an independent red team assessment to validate their security posture. Previous penetration tests had returned clean reports, but the CISO suspected their defences had never been tested against a motivated adversary.

  • Previous VAPT reports showed low-severity findings only, leaving the board sceptical of the results
  • 500+ microservices across 3 cloud regions with no unified access control
  • Physical security at 4 dark stores and 2 office locations never assessed
  • IPO due diligence required evidence of adversarial testing

The Solution

Full-Spectrum Red Team: Physical Intrusion + Social Engineering + Network Exploitation

Security Brigade deployed a 6-person red team over 3 weeks, combining physical intrusion attempts, targeted social engineering and network exploitation. The engagement followed the MITRE ATT&CK framework mapped to the client's threat model, with the B-52 engine coordinating attack paths and tracking coverage.

Services used

Red Team AssessmentSocial EngineeringNetwork Penetration TestingVAPT

Our approach

  1. 01Week 1: OSINT reconnaissance mapped 847 employee LinkedIn profiles, identified 23 high-value targets and discovered 3 leaked credentials on the dark web
  2. 02Week 2: Physical intrusion at HQ via tailgating + USB drop attack; spear phishing campaign targeting DevOps team with fake CI/CD alert
  3. 03Week 3: Pivoted from a compromised developer workstation to VPN credential extraction, then into the staging environment and on to the production database via a misconfigured service mesh
  4. 04Documented full kill chain with video evidence, remediation roadmap prioritised by exploitability

The Results

Full Production Database Access Achieved, 23 Critical Findings Remediated Before IPO

A chained attack that began with a physical USB drop ended in access to the production database and its 12M+ customer records. All 23 critical findings were remediated and verified within 6 weeks through the Lemon platform.

48 hrs
Time from initial physical entry to production database access
23
Critical findings including 3 zero-day-equivalent misconfigurations
100%
Critical and high findings remediated before IPO filing
12M+
Customer records reachable through the attack chain

Ready to discuss your security needs?

Talk to our team about a similar engagement for your organisation.

Request a Scoping Call