Kestrel Payments

Containing an overnight IRSF loop in four minutes

A compromised test credential began dialling premium-rate ranges at 02:00. Baseline monitoring caught it before it became a five-figure invoice.

Results

4min
Time to containment
£400
Actual exposure
99%
Loss avoided

The challenge

Kestrel's verification service used a shared credential across staging and production. When the credential leaked, an automated loop began placing calls to international premium-rate ranges overnight, when nobody was watching.

Under their previous provider this would have surfaced on the monthly invoice.

What we did

Per-destination baselines had been running for three weeks, so the platform already knew what normal looked like for the account. Traffic to a destination Kestrel had never called before, at a volume they had never sent, tripped the anomaly threshold immediately.

A hard per-destination hourly spend cap stopped the traffic at the session border controller rather than waiting for a nightly reconciliation job.

The outcome

The loop was blocked four minutes after it started. Total exposure was under £400 against a modelled worst case of roughly £46,000 by morning. The incident timeline gave Kestrel's risk team everything they needed for their own post-mortem.

“We found out at four minutes past, not at month end.”
Anna Lindqvist — CTO, Kestrel Payments

Ready to move some traffic?

Sandbox credentials are issued immediately. Talk to an engineer before you commit to anything.