CASE STUDY · CRYPTO-FRIENDLY NEOBANK

42 findings across a full AWS environment

A full-infrastructure AWS cloud security audit for a crypto-friendly neobank, covering compute, storage, database, networking, and IAM from the root account down.

Get Scoped See CredShields One
/ Engagement

The scope, in short

ENGAGEMENT TYPE
AWS cloud security audit, full infrastructure review
SCOPE
Complete AWS cloud environment including compute, storage, database, networking, and IAM
INDUSTRY
Fintech, crypto-friendly neobank
/ Findings overview

Forty-two findings, one critical

42
TOTAL FINDINGS
1
CRITICAL
7 + 7
HIGH + MEDIUM
24 + 2
LOW + INFORMATIONAL
/ Key risk areas identified

What the audit found

01

Cloud storage buckets publicly readable, exposing user and operational data to the open internet.

02

Unencrypted EBS volumes and database snapshots storing sensitive user financial data.

03

Root AWS account accessed and used without MFA, putting the highest-privilege credentials at risk.

04

User accounts without MFA across the AWS environment.

05

Load balancer transmitting data in clear-text over HTTP, exposing user traffic to interception.

06

Database clusters publicly accessible and unencrypted, with short backup retention reducing recovery options.

07

IAM policy misconfigurations, unused credentials, weak password policies, and unused security groups.

/ Outcome

Critical public data exposure was resolved. IAM, encryption, and network security posture were significantly improved on retest.

/ Relevant for

If this looks like your environment, it probably behaves like it too

Fintech companies on AWS or any major cloud provider.

Neobanks and digital financial services with cloud-first architecture.

Companies pre-fundraising or pre-audit needing a comprehensive cloud hygiene review.

/ FAQ

Questions engagements like this raise

What does a full AWS infrastructure review actually cover?

Every layer an attacker could reach: compute instances, storage buckets, database clusters, network configuration, load balancers, and the IAM policies governing who and what can act on any of it.

How common is root account access without MFA?

More common than most teams expect, especially in accounts that grew quickly. It is also one of the highest-severity findings possible, since the root account has no ceiling on what it can do.

Why flag unused credentials and security groups?

Anything unused is untested and unmonitored by definition. It sits in the environment as standing risk with no operational benefit, which makes it a common target and an easy one to remove.

What happens after the findings are delivered?

A retest cycle against the same findings once fixes land, so remediation is confirmed rather than assumed.

/ More case studies

Other engagements

Web + API

AgriTech marketplace

19 findings, including a shared API key exposing all platform data.

Read →
Web + API

Capx AI token launch platform

7 findings led by a critical SSRF in the API proxy.

Read →
Exchange

Indian crypto exchange

High-volume transaction systems under test.

Read →
/ Get started

Start with a scoped assessment

Tell us what you are securing. We reply with scope and next steps within one business day.

Scoping within a day, findings within the first week A senior pentester on every engagement Scope and pricing before you commit

Prefer to see it first? Book a demo ↗

Already a CredShields One customer? Log in ↗

Request received We respond within one business day. For urgent requests, email [email protected].
We respond within one business day.
OR
Book a demo ↗