Found a decade of financial sector procurement data sitting on a former employee’s home NAS
One of our analysts was going through public repos last week and stumbled on something a bit weird: two repositories, published by the same actor on the same day, that on their own looked unremarkable. Put together, they were a complete fraud kit targeting a telecoms loyalty program. The frontend was harvesting OTPs and managing multiple compromised sessions simultaneously through localStorage. The backend was a Flask proxy quietly hitting internal API endpoints that had no business being reachable from the outside. Someone sat down and thought this through, it wasn’t a rushed job. What got us: the malicious domain never showed up in any scan, because it was sitting inside the repo itself. Pure code-level exposure. You’d walk right past it looking at infrastructure alone. When we finally pulled it, the IP had been flagged malicious 23 times across 13 sources. The localStorage detail is what’s been nagging at me since. It’s a tidy way to keep multiple compromised sessions alive without generating the noise that kind of activity usually produces. Has anyone run into this pattern in loyalty fraud tooling before? Genuinely curious whether this is becoming more common. submitted by /u/CybelAngel_official [link] [comments]Technical Information Security Content & DiscussionRead More