Web App Cloud Social Engineering

Northwind Retail — E-Commerce Security Program

Ahead of peak season, a national retailer put us on retainer: storefront and API testing, cloud misconfiguration hunts, and a phishing program that cut click rates by two thirds.

Clothing racks inside the retail store assessed in this program

The challenge

Holiday traffic meant no downtime, no risky payloads in production, and a checkout flow processing millions daily. The client's goals: prove the storefront couldn't be turned into a skimmer, confirm customer data wasn't leaking from cloud storage, and measure whether staff would hand over the keys.

My approach

I tested a staging mirror for dangerous payloads and production for safe logic abuse — finding a coupon-stacking flaw worth thousands per day and an order-ID enumeration leaking customer details. In parallel I hunted their cloud buckets (two public), and ran three phishing waves ending with a voice-pretext call that reached the payments desk.

  • 19 findings fixed before peak season, including 4 criticals.
  • Phishing click rate fell from 31% to 9% across three waves.
  • Zero-downtime testing with a dedicated safe-hours window.
Testing checkout and support flows over laptop and phone

The outcome

The client entered peak season with a clean retest, a hardened checkout, private-by-default cloud storage, and a staff reporting culture that now flags real phishes weekly. The program renewed for a second year with cloud attack-path reviews added.

Operation facts

  • Sector: national retail, high-traffic storefront.
  • Duration: 12-week seasonal program.
  • Services: web app testing, cloud review, phishing simulation.
  • Renewed for year two with expanded scope.

Related operation

Peak season is coming. Test first.

Storefront, cloud, and staff — one program.

Start Your Program