Slide 14 of 28
Part 3 · Attack ScenariosSlide 14
PART 3
Attack Scenarios
Slides 14–17 · Where this shows up in the real world
Slide 14 · Scenarios 1–3
It's everywhere you shop, see a doctor, or bank.
Three industries. Same vulnerability. Different consequences.
SCENARIO 01 · E-Commerce
You see a stranger's entire order history.

You buy something online. Your order confirmation links to /api/orders/58291. You change it to 58290. You see the previous customer's name, shipping address, items purchased, and partial payment method.

Multiply this by an automated script that loops through 100,000 order IDs. Now you have a list of real names, real addresses, and what people bought.

Why it matters: Home addresses plus purchase history is enough to enable targeted theft, fraud, or stalking.
SCENARIO 02 · Healthcare
A patient reads another patient's medical records.

A patient portal exposes records at /api/patients/3310/records. A user changes their patient ID. They can now read another patient's diagnoses, medications, lab results, and doctor's notes.

Why it matters: Medical data is among the most sensitive personal information that exists. It can affect insurance, employment, and relationships. HIPAA violations alone can cost millions in fines.
SCENARIO 03 · Banking
A customer views another customer's transactions.

A banking app fetches statements at /api/accounts/AC-10042/transactions. Changing the account number returns another customer's full transaction history — where they shop, how much they earn, what they spend.

Why it matters: Transaction data reveals life patterns. Combined with a name and address, it enables identity theft and targeted financial fraud.
← Back More scenarios →