The Previous Test Found Nothing. We Found Account Takeover.

We ran a security assessment for one of our clients after they had worked with another vendor, and we found a sea of extraordinary security holes that could have done the organisation enormous damage.

The strangest part is that the previous test had turned up nothing at all. How could they have missed what we found?

  • Data theft
  • Identity tampering
  • Denial of service
  • Takeover of the admin account

All of them disasters that could have followed from those security holes – and if you ask me, it was only a matter of time.

Their report presented everything as being in order apart from minor findings. In other words: “all fine”. So where, in their report, was any mention of the horrors we found and reported in ours – the ones the previous company should have found?

The client mentioned almost in passing that he did not expect us to find anything, because everything had come back clean in the previous test.

“Everything is fine” is an axiom worth testing twice

If there is one thing that guides me and the people who work with me at AppSec Labs, it is that. In our field – application security – it is entirely normal to work with more than one vendor in order to get a second opinion on the same thing.

Suddenly I found myself thinking: how can this be? So many findings. So many holes. Data tied to users, to permissions, to financial aspects, everything. And this after they had already had a test done. The whole soft underbelly of the business, exposed.

As we worked and began to understand the scale of it, we immediately set up a call with the client and explained that the previous company’s “everything is fine” did not hold, and that there were findings that needed fixing as soon as possible.

He was in shock. “How can this be?” he asked me, in astonishment mixed with anger.

I explained that sometimes, when security assessments are run, findings do get missed – but that this time the miss was of a different order. Not minor findings, but significant ones. And in quantity.

I do not want to think about what would have happened if somebody had exploited it.

Why this matters more than it looks

The company had the security assessment done because it wanted to discover its weak points and fix them – not in order to leave the goal empty in front of the striker running in to score. So if we had not dealt with the security failings we found, an attack like that would have been even more of a surprise.

So officially, yes: you had a penetration test. But it may create serious problems in the long run. If there is a breach and attackers get in, it will be because of a careless test that never surfaced the findings – and as a professional, that is not acceptable to me.

So, to founders of software companies, CISOs and CTOs: I would encourage you to change the professional doing the work on any given system from time to time, so that you get the full picture of the security holes in your systems. If something feels wrong, trust your gut, and consider getting a second opinion.


I first shared a version of this as a LinkedIn post on 2024-07-16. It is republished here, lightly edited, so it is easier to find and reference. — Erez Metula