Trusted Servers Can Still Send Fraudulent Payments
Network origin, credentials and transaction authority need separate checks.
India’s CERT-In and CSIRT-Fin report campaigns targeting financial businesses: attackers compromise applications or APIs, steal payment credentials and transfer funds from the victim’s whitelisted infrastructure.
Direct calls bypass loan, KYC, beneficiary, balance and transaction-limit checks. An allowed server is therefore not sufficient protection.
Network location is not authority
NIST’s zero trust architecture guidance, published in August 2020, rejects implicit trust based solely on network location or ownership. It treats authentication and authorisation as distinct functions and focuses protection on resources rather than network segments.
The practical distinction is between where a connection originates and what its identity is allowed to do. Passing one check does not remove the need for the other. An organisation should be able to explain the access decision for the particular resource, not simply point to an approved subnet.
Ask what the API makes possible
OWASP’s API6:2023 guidance adds the business perspective. Excessive access to a sensitive workflow can cause harm even without a conventional technical impact. Its examples include buying scarce stock, blocking reservations and abusing referral credits.
Prevention is a shared responsibility: business teams identify harmful flows; engineering chooses protections. OWASP also warns that machine-to-machine APIs may lack required protections. An endpoint inventory alone cannot answer whether the exposed workflow is appropriately constrained.
For a review meeting, separate three questions: which resource is reached, which identity is authorised, and which business outcome the workflow permits? Name the owner who can answer each one. NIST and OWASP provide architectural context, not evidence about the reported incidents.
Contain the reported payment path
CERT-In recommends suspending compromised APIs/accounts, preserving evidence and rotating credentials. Reconcile transfers with approved records; bind transaction stages, require second approval, validate beneficiaries and enforce limits.
The advisory is dated 9 October 2026. Its 11 October footer supplies no revision history. AI assistance is only possible; victims, losses and a CVE are not identified.
For another trust-boundary investigation, see BlackTree’s GhostAction reporting. That separate incident concerns credential harvesting in repositories, not these payment campaigns.


