Mid-2025: Major Commercial Bank API Exploit
Published on 2025-08-05T14:15:00Z
## The Incident
In mid-2025, a major commercial bank in Nepal experienced a severe cybersecurity incident involving its mobile banking application's API. Driven by rapid digitalization, the bank had deployed new API endpoints to support mobile features, but these endpoints lacked adequate security validation.
Attackers discovered and exploited an Insecure Direct Object Reference (IDOR) / Broken Object Level Authorization (BOLA) vulnerability. By manipulating parameters in the API requests, they...
Back to Blog