Security Flaw in Financial App Using AI Model Claude Exposes Sensitive Data
Editorial illustration generated by baba News — not a photograph of the event.
Security10:12 · 1h ago

Security Flaw in Financial App Using AI Model Claude Exposes Sensitive Data

SrugimReligious-right
Translated & summarized from Srugim by baba
The story · English

A critical security vulnerability was discovered in a financial application whose significant code was written using the AI model Claude. The flaw was uncovered during a penetration test conducted by the Israeli cybersecurity firm Sigania for a financial institution managing assets worth billions of dollars. The app, designed to onboard new clients and allow users to resume registration before choosing a username and password, relied on a unique GUID to identify returning users. However, the access mechanism issued tokens based solely on possession of the GUID, without verifying the requester’s identity, enabling minimal-permission users who guessed or obtained another user’s GUID to access sensitive information.

Exposed data included personal identifiers such as US Social Security numbers, contact details, credit request statuses, and information about financial partners or joint applicants. Sigania explained this was not a typical programming error but a logical flaw in the authorization design, where the system incorrectly assumed possession of an identifier equated to ownership or permission. Zack Mead, a senior penetration tester at Sigania, noted that automated code scanning tools often fail to detect such vulnerabilities because they stem from trust boundary design rather than explicit code defects.

Ironically, the researchers also used a language model to analyze parts of the code and locate the flaw, highlighting how AI tools that accelerate code writing can also aid security researchers and attackers in quickly identifying weaknesses. Sigania described this phenomenon as the "democratization of vulnerabilities," where even individuals without advanced cybersecurity knowledge can analyze leaked or exposed code using language models to find potential exploits.

While AI-assisted coding does not inherently produce insecure code, risks increase when organizations integrate AI-generated code without thorough human review, architectural assessment, and security testing focused on business logic. This case underscores ongoing cybersecurity debates about uncontrolled AI tool usage within organizations, including unauthorized employee use that may expose internal data and increase leak and attack risks.

In response to rising AI adoption, Sigania announced expanded services for AI system security, including infrastructure and data flow assessments, penetration testing of AI-based applications, and organizational policy development for AI tool usage. Ilia Rabinovich, Sigania’s Cyber Consulting VP, emphasized that organizations must now identify where AI is already in use, what data it accesses, and whether existing security measures address the new risks posed.

Read the original at Srugim
Open the live terminal