Northwind Retail — E-Commerce Security Program
Ahead of peak season, a national retailer put us on retainer: storefront and API testing, cloud misconfiguration hunts, and a phishing program that cut click rates by two thirds.
The challenge
Holiday traffic meant no downtime, no risky payloads in production, and a checkout flow processing millions daily. The client's goals: prove the storefront couldn't be turned into a skimmer, confirm customer data wasn't leaking from cloud storage, and measure whether staff would hand over the keys.
My approach
I tested a staging mirror for dangerous payloads and production for safe logic abuse — finding a coupon-stacking flaw worth thousands per day and an order-ID enumeration leaking customer details. In parallel I hunted their cloud buckets (two public), and ran three phishing waves ending with a voice-pretext call that reached the payments desk.
- 19 findings fixed before peak season, including 4 criticals.
- Phishing click rate fell from 31% to 9% across three waves.
- Zero-downtime testing with a dedicated safe-hours window.
The outcome
The client entered peak season with a clean retest, a hardened checkout, private-by-default cloud storage, and a staff reporting culture that now flags real phishes weekly. The program renewed for a second year with cloud attack-path reviews added.
Operation facts
- Sector: national retail, high-traffic storefront.
- Duration: 12-week seasonal program.
- Services: web app testing, cloud review, phishing simulation.
- Renewed for year two with expanded scope.
Related operation
Peak season is coming. Test first.
Storefront, cloud, and staff — one program.