Basilisk
BASILISK
[setor_e_commerce]E-COMMERCE & MARKETPLACE

Offensive security for e-commerce and marketplaces.

In online retail, the flaw rarely appears as an error on screen. It appears as margin that evaporates, chargebacks that climb and customer accounts taken over. We test the whole path, from catalogue to payment.

Where online retail loses money quietly

Most losses in online retail do not come from a spectacular breach. They come from quiet logic abuse: coupons stacking where they should not, prices manipulated mid-checkout, accounts taken over with reused credentials. Automated tooling does not detect it, because technically nothing broke.

  • Business rule abuse consumes margin without raising a security alert.
  • Credentials reused from other breaches fuel account takeover at scale.
  • Seasonal peaks expose architectural limits and open a window for malicious automation.
  • Gateway, anti-fraud and logistics integrations widen the surface beyond your own code.

What we test in an online retail operation

We follow the order flow and the money flow, looking for where the rule can be bent in the attacker's favour.

// checkout and payment

Manipulation of price, shipping and quantity, race conditions between authorisation and capture, and what happens when flow steps run out of order.

// coupons and promotions

Improper stacking, reuse beyond limits, eligibility checks and discount calculation — logic abuse that bleeds margin continuously.

// customer accounts

Registration, login, password recovery and resistance to credential stuffing, plus object-level authorisation on order history and saved data.

// marketplace and sellers

Isolation between sellers, file upload, listing edits and panel access — if one seller reaches another's data, it surfaces.

// APIs and automation

Catalogue, stock and pricing endpoints: rate limiting, data enumeration and information exposure that enables scraping at scale.

// external integrations

Payment gateway, anti-fraud, ERP and logistics — including webhooks, which accept unauthenticated calls more often than anyone expects.

Compliance without interrupting trade

We work around the retail calendar: scope closed outside peak periods and evidence ready for whoever asks for it.

PCI DSS
Where cardholder data is stored, processed or transmitted, we align scope and evidence format with what a QSA will request during assessment.
GDPR
Customer base, purchase history and addresses are personal data. We document data subject exposure and the technical route to disclosure.
Consumer protection
A flaw that allows price or sales conditions to be altered has contractual consequences, not only technical ones. The executive report addresses that angle explicitly.
Partner requirements
Marketplaces, acquirers and large customers routinely ask for evidence of periodic testing. The attestation letter answers that without exposing technical detail.

How we run in online retail

01

Off-peak window

No meaningful testing happens during peak season or a major campaign. We agree the window with your operations team and respect the volume limits set.

02

Business logic focus

Beyond technical testing, we attack the rules: discounts, shipping, stock, returns. That is where losses hide unnoticed for months.

03

Account takeover scenarios

We simulate the full fraudster path, from leaked credentials to use of saved payment data, to measure where the fraud pipeline actually holds.

04

Remediation and retest

We prioritise by what drains margin first, follow the remediation and retest before issuing the final version.

What you receive

  • Executive report with margin impact
  • Reproducible technical report
  • Business rule abuse map
  • Justified CVSS scoring
  • Account takeover scenarios tested
  • Priority by financial loss
  • Retest of remediated findings
  • Attestation letter for partners

Sector FAQ

Do you test during peak season or major campaigns?

+

No. The highest revenue period is exactly when it makes least sense to introduce a variable. We close scope beforehand, execute in an off-peak window and, if you want, retest critical points shortly before the campaign with restricted, non-intrusive activity.

Are coupon abuse and price manipulation in scope?

+

They are, and they usually produce the most expensive finding. This class of flaw does not break anything technically, so automated scanning stays silent. It depends on understanding the business rule and testing it by hand, which is exactly what we do.

How do you test account takeover without affecting real customers?

+

With test accounts we create in the environment, reproducing fraudster behaviour: reused credentials, changes to registered details, use of saved payment methods. Real customer accounts are never targets. What we measure is whether the pipeline detects and blocks the pattern.

Does the report satisfy my acquirer or marketplace?

+

It does. We issue an attestation letter confirming scope, period and conclusion of the engagement without exposing exploitable detail. It is the document normally accepted in partner due diligence, and it neither replaces nor conflicts with a formal PCI DSS assessment.

Services applied to this sector

// contact

Ready to uncover your flaws?

First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.