Menu
iconCase Studies

Mamo

Penetration tests for fintech company
Location

Dubai, UAE

Industry

Fintech

csHero image

About the Project

Mamo, a leading payments solutions provider in the UAE, transforms businesses by helping them consolidate payment collection, corporate cards, and expense management in one beautiful, intuitive platform. Over 1,000 companies have used Mamo to improve revenue collection, control spending, reduce costs and automate financial operations. Mamo's mission is to empower people to effortlessly access their money through a platform that demonstrates simplicity, empathy, and utility.

mockup

Challenge

Mamo required a thorough security assessment of its cloud infrastructure, mobile applications, and web platform. Operating in a fintech environment where data security, user trust, and regulatory standards are crucial, Mamo had to ensure that every aspect of its payment solution could withstand sophisticated cyber threats. With thousands of businesses relying on their platform for payment collection and expense management, even a minor vulnerability could pose significant financial and reputational risks.

Furthermore, maintaining robust security measures became challenging as Mamo’s product offerings and customer base grew. Ensuring that every system remained operationally sound and met compliance requirements was critical. Achieving this balance was essential for upholding Mamo’s commitment to reliability, trust and transparency in financial services.

Solution Delivered

Solution Delivered

We conducted a comprehensive penetration test, following the Penetration Testing Execution Standard (PTES) and OWASP Testing Guides, to identify and address potential vulnerabilities across Mamo’s cloud, mobile, and web applications. The project began with an in-depth reconnaissance phase that mirrored the perspective of an actual attacker, gathering publicly available information and identifying possible points of entry.

Solution Delivered

We then used automated scanning tools to spot common security issues quickly while gathering an initial environment overview. Building on these findings, our team conducted thorough manual testing to investigate complex authentication flows, API endpoints, and custom-built features that automated tools often overlook. This hands-on approach helped us detect weaknesses that could pose significant threats.

Solution Delivered

We chained controlled cyberattacks using industry-standard tactics, techniques, and procedures to emulate real-world attack scenarios. All tests were performed in isolated environments to avoid disrupting live operations, and we maintained strict confidentiality.

Solution Delivered

Finally, we compiled our findings into a clear, actionable report highlighting critical vulnerabilities, recommended remediation measures, and strategic best practices for ongoing security enhancements.

Protect your project with us

Get a detailed estimate of your project with all risks included.

rossross

Provided Services For Mamo

Provided Services
For Mamo

We offered specialized services that addressed every layer of security in cloud, mobile, and web environments. First, we thoroughly evaluated the cloud infrastructure, reviewing configurations, access controls, and underlying layers to uncover hidden vulnerabilities. This focus on the cloud reinforced defences and ensured compliance with stringent fintech standards.

Common Tools We Use

Our security testing arsenal is stacked with cutting-edge tools implementing in different areas like AI in cybersecurity that enable us to identify vulnerabilities in third-party dependies with static analysis tool such as Semgrep, enforce code standards, and fortify your defenses.

OWASP ZAP
OWASP ZAP
Burp Suite
Burp Suite
Arachni
Arachni
SonarQube
SonarQube
Semgrep
Semgrep
Snyk.io
Snyk.io
Maltego
Maltego
SpiderFoot
SpiderFoot
Nmap
Nmap
Wappalyzer
Wappalyzer
Kali Linux
Kali Linux
Parrot Security
Parrot Security
OWASP ZAP
OWASP ZAP
Burp Suite
Burp Suite
Arachni
Arachni
SonarQube
SonarQube
Semgrep
Semgrep
Snyk.io
Snyk.io
Maltego
Maltego
SpiderFoot
SpiderFoot
Nmap
Nmap
Wappalyzer
Wappalyzer
Kali Linux
Kali Linux
Parrot Security
Parrot Security
OWASP ZAP
OWASP ZAP
Burp Suite
Burp Suite
Arachni
Arachni
SonarQube
SonarQube
Semgrep
Semgrep
Snyk.io
Snyk.io
Maltego
Maltego
SpiderFoot
SpiderFoot
Nmap
Nmap
Wappalyzer
Wappalyzer
Kali Linux
Kali Linux
Parrot Security
Parrot Security

Our Team

Ihor Sasovets

Ihor Sasovets

Lead Security Engineer

Ihor is a certified security specialist with experience in penetration testing, security testing automation, cloud and mobile security. OWASP API Security Top 10 (2019) contributor. OWASP member since 2018.

sc-9.png
sc-11.png
sc-12.png
sc-6.png
sc-8.png
sc-3.png
sc-4.png
sc-7.png
sc-1.png
sc-5.png
Victoria Shutenko

Victoria Shutenko

Security Engineer

Victoria is a certified security specialist with a background in penetration testing, security testing automation, AWS cloud. Eager for enhancing software security posture and AWS solutions

sc-6.png
sc-3.png
sc-11.png
sc-7.png
sc-8.png
Denys Spys

Denys Spys

Associate Security Engineer

Denys is a certified security specialist with web and network penetration testing expertise. He demonstrates adeptness in Open Source Intelligence (OSINT) and executing social engineering campaigns. His wide-ranging skills position him as a well-rounded expert in the cybersecurity industry.

sc-6.png
sc-11.png
Certification.png
sc-7.png
Roman Kolodiy

Roman Kolodiy

Director of Cloud & Cybersecurity

Roman is an AWS Expert at TechMagic. Helps teams to improve system reliability, optimise testing efforts, speed up release cycles & build confidence in product quality.

sc-12.png
sc-10.png
sc-2.png
|

Project Outcomes

Following our comprehensive penetration testing and security assessment, Mamo achieved a significantly improved security posture across its cloud, mobile, and web environments. Our team’s in-depth findings and tailored remediation strategies enabled Mamo to address critical vulnerabilities before malicious actors could exploit them. In addition, our clear documentation and guidance helped streamline ongoing security efforts, enhancing regulatory compliance and stakeholder confidence.

By adopting a proactive stance on cybersecurity, Mamo reinforced user trust, minimized potential disruptions, and established a foundation for continual improvement in a rapidly evolving fintech landscape.

As a result, Mamo recognized our comprehensive approach and scheduled regular penetration testing and vulnerability scanning with us, ensuring an ongoing commitment to robust security.

Project Outcomes

Why Choose TechMagic For Penetration Testing

Certified security specialists
Certified security specialists

With certifications PenTest+, CEH, eJPT and eWPT, our team possesses deep expertise and technical skills to identify vulnerabilities and simulate real-world attack. We provide cloud penetration testing, wireless penetration testing, social engineering testing, mobile and web application penetration testing, API penetration testing, external and internal network pen testing.

001
/003
Security and compliance
Security and compliance
002
/003
Proven track record
Proven track record
003
/003

Cases That May Be Of Interest To You

Let’s safeguard your project
award_1_8435af61c8.svg
award_2_9cf2bb25cc.svg
award-3.svg
Ross Kurhanskyi
linkedin icon
Ross Kurhanskyi
VP of business development
cookie

We use cookies to personalize content and ads, to provide social media features and to analyze our traffic. Check our privacy policy to learn more about how we process your personal data.