Cybersecurity Case Study

Protecting Financial Services From Supply Chain Attacks

How Mudals Managed Security Services helped a financial institution respond to a compromised third party script while protecting customer journeys, banking applications and critical APIs.

Industry
Financial Services
Attack Type
Supply Chain Attack
Primary Focus
Application Security
Response Model
Continuous Protection
The Customer Scenario

The attack started outside the bank

A financial institution used several trusted third party services across its digital banking experience. These included identity verification, credit services, payment processing, customer support and analytics.


One analytics provider was compromised. A malicious JavaScript update was then delivered through the trusted integration and loaded by the bank’s loan application portal.

1
compromised third party integration became the starting point for a much broader attack.
6+
critical customer journeys and API areas required protection.
What Happened

One compromised integration created multiple risks

The incident moved from a trusted third party component into customer facing applications and backend services.

01

Third Party Compromise

A trusted analytics provider distributed a malicious JavaScript update.

02

Customer Data Targeted

The script attempted to capture information entered during loan and card applications.

03

Sessions Targeted

Stolen session information was used to support automated login and API activity.

04

Attack Surface Expanded

Attackers moved toward banking applications, APIs and customer facing services.

05

Malicious Traffic Increased

Automated activity and high volume traffic added another layer of pressure.

Business Risk

The impact could reach far beyond the application

Customer Data Exposure

Sensitive information entered during financial applications could be exposed.

Account Takeover

Stolen session information could support unauthorized access attempts.

Fraud Risk

Attackers could target loan, card and payment workflows.

Service Disruption

High volume malicious requests could affect application availability.

Compliance Pressure

A customer data incident could create additional regulatory obligations.

Trust Impact

A security incident involving financial services can directly affect customer confidence.

Mudals Response

Protection was built around the attack

Instead of relying on one security control, Mudals coordinated several layers of protection and continuously tuned them as the attack changed.

01

Web Application Firewall

Mudals investigated attack events across applications and APIs, then strengthened protection around high value banking endpoints.

Outcome

Stronger protection against application attacks while keeping legitimate customer traffic flowing.

02

DoS Protection and Rate Control

Traffic patterns were analyzed and controls were tuned around login, OTP, loan, card and payment services.

Outcome

Malicious request surges were reduced without depending only on static IP blocking.

03

Client Reputation

Suspicious traffic from scanners, scrapers, anonymizers and other high risk sources was investigated and correlated with attack behavior.

Outcome

High risk traffic could be challenged or denied while legitimate customers remained accessible.

04

IP and Network Lists

Confirmed attacker infrastructure was identified and rapidly added to centralized security lists.

Outcome

Threat infrastructure could be contained quickly across relevant security controls.

05

Bot Manager

Automated login attempts, scraping, account enumeration and form abuse were investigated and classified.

Outcome

Malicious automation was reduced while trusted bots and approved business automation continued.

06

Bot Manager Premier

More advanced automation was analyzed using behavioral signals, browser integrity and bot risk indicators.

Outcome

High risk automation could be blocked while medium risk activity received additional checks.

How The Controls Worked Together

Security decisions were based on real traffic

Mudals continuously reviewed traffic behavior, security events and application patterns before changing policies.

WAF Policy Tuning

Security policies were strengthened around critical customer journeys while legitimate traffic was protected through granular exceptions.

Login and authentication
Auto loan applications
Credit card applications
Payment APIs
Customer profile APIs

Traffic Analysis

Request behavior was examined across applications and APIs to separate normal customer activity from malicious patterns.

Request frequency
Request paths
HTTP methods
Headers and cookies
Payload characteristics

Granular Exceptions

When legitimate traffic was affected, protection was not simply switched off. Exceptions were created around specific application behavior.

Hostname
URL path
Request headers
Cookies
Client IP and network

Adaptive Bot Protection

Bot policies were continuously adjusted as attacker behavior changed, while trusted automation remained available.

Behavioral analysis
Browser integrity signals
Bot risk scoring
Conditional actions
Trusted bot categories
Incident Response Framework

One incident. Multiple layers of protection.

Each stage of the attack was connected to a specific security response so the team could move from detection to containment and continuous optimization.

Third Party Script Compromise Customer information becomes a target
Security Analytics
Investigate Identify affected applications and attack indicators
Backend Exploitation Applications and APIs are targeted
WAF
Strengthen Protect critical endpoints and tune policies
Traffic Surge Malicious requests increase rapidly
DoS Protection and Rate Control
Mitigate Control request rates and reduce malicious traffic
High Risk Infrastructure Attackers use distributed sources
Client Reputation and Network Lists
Contain Block confirmed malicious infrastructure
Automated Abuse Bots target accounts and customer journeys
Bot Manager and Bot Manager Premier
Adapt Detect and respond to changing automation
Business Value

Security that protects the customer experience

The goal was not simply to block attacks. The goal was to protect important banking services while allowing genuine customers to continue using them.

01

Faster Containment

Attack indicators were investigated and mitigation policies were adjusted as the incident evolved.

02

Protected Banking Services

Login, loan, card, payment and API journeys received focused protection.

03

Reduced False Positives

Application aware tuning helped maintain protection without unnecessarily blocking customers.

04

Improved Availability

Malicious traffic and application layer attacks were managed while critical services remained accessible.

05

Adaptive Security

Policies were continuously refined as application behavior and attacker techniques changed.

06

Operational Support

Mudals provided continuous monitoring, investigation, policy updates and security optimization.

Operational Perspective

Enterprise security requires continuous attention

Ongoing security operations can require significant engineering effort across policy tuning, monitoring, incident analysis, configuration changes and application support.

100 to 120
estimated engineering hours per month for ongoing operational activities in a large environment.
Estimated Monthly Professional Services Effort
$35K to $42K
Based on the engineering effort described in the case study.
Managed Security Services

Keep security moving as fast as the threat

Mudals helps organizations continuously monitor, investigate, tune and optimize their security environment while protecting the digital experience their customers depend on.

Talk to Our Security Team