UNPROTECTED ENVIRONMENT · no Nemesis · deliberately vulnerable demo
OmniTrust
Sign in
USE-CASE EXPLORER · UNPROTECTED DEPLOYMENT
Financial Institution
Banks, fintechs and payment platforms. Deep, end-to-end tests across every money-movement surface.
◆ Start the guided walkthrough

Choose your industry

Pick a sector to load its use cases. Each one is an end-to-end test you can run on this deployment and compare against the other.

View detection rules
Financial Institution Web3 / Crypto Startup Telecommunications E-commerce / Retail Insurance

15 use cases for Financial Institution

APIWeb
API recon (BOLA) → cash-outAn attacker enumerates another customer's records over the API, then moves money from the same session. Nemesis links the blocked reconnaissance to the cash-out and declines it.
APIWeb
Credential-stuffing takeover → cash-outAn injection / credential-stuffing login against this account is blocked; the account is flagged as taken-over, so the attacker's immediate cash-out is declined.
WebAPI
Peel-chain layering (A→B→C)A transfer whose destination sits on a multi-hop chain where each account forwarded most of what it received within the window — layering that breaks the audit trail.
WebAPI
Circular money-mule ringFunds routed to an account that cycles value back to the origin (A→B→C→A) — round-tripping to disguise the source of funds.
WebAPIUSSD
Counterparty on your fraud blocklistA transfer to an account you have already blocklisted as a confirmed mule cash-out node — caught however the party is named.
WebAPI
Sanctions / PEP beneficiary screeningA payout to a beneficiary whose name matches the consolidated OFAC / EU / UN / UK sanctions and PEP watchlist.
WebMobileUSSD
Instant transfer to a mule accountA push payment on the irreversible NIP rail to a flagged mule account whose BVN was registered by an insider.
WebAPI
Card-testing on wallet fundingRapid low-value auths on a stolen-card BIN, with device velocity and impossible-travel across cities.
WebAPI
Account takeover via SQL injectionA login-bypass payload authenticates as the first user with no valid password.
API
Customer KYC / BVN harvest (BOLA)Increment an id and read any customer's full KYC, including BVN, address and balance.
API
Insider bulk export (BFLA)An admin export endpoint with no function-level authorization dumps every customer with cleartext passwords.
API
Exposed database backup / secretsA world-readable backup leaks env, DB creds, HSM key reference and weakly-hashed passwords.
WebAPI
Statement download path traversalA statement filename with ../ escapes the directory and reads arbitrary server files.
Web
Inflated payout / claim fraudA large, anomalous payout request clears with no fraud scoring.
WebMobile
Support assistant prompt injectionA prompt-injection message makes the AI assistant leak its internal system context.