Financial InstitutionAPI
Insider bulk export (BFLA)
An admin export endpoint with no function-level authorization dumps every customer with cleartext passwords.
- Attack
- GET /api/admin/users.
- Nemesis defense
- Bulk credential / PII export is off-baseline and blocked.
- Modelled on
- Sterling Bank insider / middleware bypass PII exfil.
- Endpoint
- GET /api/admin/users