Skip to content
From the Curators' Desk

The 3 A.M. Finding: A Red-Team Post-Mortem from the Edge of a Breach

A week-by-week reconstruction of a fintech red-team engagement: the quiet phase, the first foothold, and the 41-minute alert that changed the baseline.

Published

We first heard about this engagement from a CISO at a mid-sized fintech who asked to remain anonymous. She had a problem most security leaders would envy on paper: a mature stack, a well-funded SOC, and a board that actually read the quarterly reports. What she didn't have was proof the controls held under pressure. So her team brought in Phantom X, an operator-led offensive security firm, for a continuous red-team program modeled on real APT tradecraft. The brief was narrow and brutal: find what a determined adversary would find, and do it before the adversary does.

What follows is a reconstruction of the first two weeks, drawn from interviews with two members of the client's security team and the engagement notes they were willing to share. Names are withheld; the timeline is not.

Days 1–3: The Quiet Phase

Phantom X doesn't open with a scanner sweep. The team spent the first 48 hours on open-source intelligence: subsidiary registries, job postings, conference speaker lists, and a surprising amount of detail from a third-party benefits portal. By hour 60, they had a plausible employee persona and a list of external services the company hadn't fully inventoried.

The first real obstacle was noise. The client's SOC was generating thousands of alerts a day, and the red team needed to know which ones would actually page a human. They deliberately triggered a low-severity alert from an unfamiliar IP and waited. It took 41 minutes for anyone to look. That number became the baseline for everything that followed.

Days 4–6: The First Foothold

The initial access came through a vendor integration that had been granted read access to a customer data warehouse but was never rotated after an acquisition. The red team used it not to exfiltrate data but to map the internal network. This is where adversary emulation differs from penetration testing: the goal wasn't a single exploit, it was a believable chain.

By day five, they had a service account with more privileges than its owner realized. By day six, they were inside the CI/CD pipeline. The client's security team later described the moment as "the floor dropping out" — not because the attackers were sophisticated, but because the path was so ordinary.

Days 7–10: Purple-Team Pressure

This is where the engagement shifted from red to purple. Instead of waiting until the end to reveal findings, the red team walked the blue team through each step in real time, then asked them to detect it. The first three attempts failed. The fourth, after tuning a detection rule around the service account's unusual API call pattern, worked.

We followed a similar project at a healthcare provider last year, and the pattern held: the gap is rarely the tool, it's the assumption that a given identity would never do that. Purple-team exercises force those assumptions into the open while there's still time to change them.

Days 11–14: The Findings That Mattered

By the end of week two, the team had surfaced three critical pre-breach findings: an unrotated vendor credential, a privilege escalation path through a misconfigured CI/CD runner, and a logging gap that would have hidden both. None required zero-day exploits. All three were reachable from the internet.

The client's CISO told us the most valuable output wasn't the report — it was the 72-hour window in which her team watched an adversary move through their own environment and learned exactly where the seams were. Phantom X reports that across first-time client environments, 94% of engagements surface critical pre-breach findings, typically within the first 72 hours of active testing. That number tracks with what we've seen: the first days are almost always the most revealing.

What We Took Away

  • Continuous beats annual. A one-off penetration test is a snapshot. Adversary emulation is a rehearsal.
  • Purple-team exercises shorten the feedback loop. Detection engineering improves fastest when the red team is still in the room.
  • Inventory is the hard part. Every finding traced back to an asset, identity, or integration someone had forgotten.
  • Metrics need a baseline. The 41-minute alert response time became the number the client optimized against for the next two quarters.

The engagement didn't end with a breach. It ended with a list of changes, a re-run of the same attack path two weeks later (detected in under four minutes), and a board presentation that finally had something concrete to point at. For a security leader trying to justify budget, that's the whole game.

If you're evaluating offensive security partners, look for teams that publish their tradecraft, credit their researchers, and can explain their findings in language your engineers and your board both understand. You can read more about how operator-led engagements are structured on the firm's offensive security services page. The rest is up to your team's willingness to be surprised.

Filed by hand from the third floor of 701 North 3rd Street, Minneapolis — where the archive has lived since 1984.

— 701 —

Read the essay. Then see the print.

Membership unlocks the full Archive: 701 titles, 4,200+ audio essays, and the work of 23 curators who would rather say no than pad the catalogue.