Penetration testing for gateways and acquirers that process cards and Pix — and need to pass PCI DSS 4.0.
Offensive security assessments built for payment companies, including those operating in or entering Brazil. Coverage of PCI DSS 4.0 (Requirement 11.4), BACEN Resolution 4,893 (CMN 4,893), transaction fraud, refund race conditions, webhook tampering, BIN attacks and anti-fraud bypass. Reports formatted for your PCI QSA.
- Mutual NDA within 24h
- Retest included
- Direct contact with the researcher
Why payments
A bug in a gateway is money leaving the company in real time
In a payment gateway, a bug doesn't create “risk” — it causes an instant financial loss. A refund race condition doubles the refund. An anti-fraud bypass lets a fraudulent transaction through. A BIN attack runs card testing at scale. A replayed webhook re-approves a cancelled order.
These bugs aren't theoretical. They're what organized attackers go after today in Brazilian payment gateways. Automated card testing accounts for a meaningful share of attempted transactions at acquirers — and every attempt that gets through costs interchange, chargebacks and your standing with the card brands.
A pentest here isn't a regulatory checkbox — it's proof that the product isn't quietly bleeding money.
Scope
What our payments penetration testing covers
Regulatory coverage
- PCI DSS 4.0 — Requirement 11.4 (internal and external penetration testing, CDE segmentation, application layer)
- BACEN Resolution 4,893 — the Central Bank of Brazil's cybersecurity policy rule, for authorized payment institutions
- BCB Resolution 85 — cybersecurity policy (Central Bank of Brazil)
- LGPD Art. 46 (Brazil's data protection law) — cardholder data, CPF (Brazilian taxpayer ID), transaction data
Card transaction flows
- Tokenization — token usage validation (replay, leakage, expiration)
- 3DS 2.x — bypass via frictionless fallback, risk score manipulation
- BIN attacks — card testing at scale, rate limiting by BIN/IP/device
- Refunds — race conditions, double refunds, amount manipulation
- Delayed capture — amount manipulation between pre-authorization and capture
- Chargeback flow — dispute abuse, evidence tampering
- Recurring billing — cancellation bypass, reuse of expired tokens
Pix (gateway side)
- Dynamic QR codes — payload manipulation, amount validation bypass
- Pix refunds — race conditions, double refunds, receiver manipulation
- Pix billing (Pix Cobrança) — phishing using forged keys
- Payment initiation — initiator authentication, JWT validation
- Reconciliation — status manipulation, payment receipt replay
Notification webhooks
- HMAC signature bypass — timing, length extension, algorithm downgrade
- Replay attacks — webhooks that change order status (paid, refunded)
- Webhook forgery — forging a callback to release an order without payment
- SSRF via a webhook URL configurable by the merchant
- Duplicate callback race conditions — double processing of notifications
Anti-fraud and risk scoring
- Rule bypass through payload modification (headers, fingerprint, geolocation)
- Score manipulation through test volume
- BOLA on rule endpoints (rule dump)
- Velocity checks — rate limit bypass via IP rotation, header injection
- Device fingerprint forgery
Merchant application (dashboard)
- Cross-merchant BOLA on transactions, receivables and settings
- Balance / early settlement manipulation
- Limit bypass through payload modification
- Card data leakage in logs / exports
- Unauthorized access to the chargeback tool
PCI infrastructure
- CDE segmentation — pivoting from the DMZ into the PCI zone
- HSM — validation of signed operations
- Logs and WORM storage — audit log tampering
- Key management — rotation, derivation, derivative leakage
Compliance
Reports formatted for QSAs, BACEN and the card brands
A PCI QSA expects a report in a specific format:
- An executive summary formatted for the C-suite and the QSA
- Findings mapped to PCI DSS 4.0 requirements (especially 11.4.x and 6.x)
- A formal compliance statement after the retest
- Evidence of CDE segmentation testing
- An attack surface inventory classified by CDE exposure
For BACEN, we use the same structure, adapted to BACEN Resolution 4,893 and BCB Resolution 85. For the card brands (Mastercard SDP, Visa CPP), an additional format is available on request.
Pricing
Payments penetration testing pricing
| Scenario | Price range | Coverage |
|---|---|---|
| Early-stage sub-acquirer / payment facilitator | Deep Dive (50h): US$ 7,500 to US$ 12,500 | PCI DSS application layer + auth + webhooks |
| Acquirer in production | Full Scope (100h+): from US$ 15,000 | + Pix + anti-fraud + CDE segmentation |
| BACEN-regulated acquirer + PCI Level 1 | Full Scope (150h+): from US$ 22,500 | Full white box + HSM + cloud + reconciliation |
| Recurring, quarterly | PTaaS: on request | Continuous pentesting + attack surface monitoring |
Every engagement gets a custom quote once the scope is defined. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.
FAQ
Frequently asked questions
Does PCI DSS require penetration testing?
Yes. PCI DSS 4.0 Requirement 11.4 requires internal and external penetration testing at least once every 12 months and after any significant infrastructure change. It includes segmentation testing of the CDE (Cardholder Data Environment) and application-layer testing. Without formal pentest evidence, you won't pass your PCI assessment.
How much does payment gateway penetration testing cost?
Early-stage sub-acquirer / payment facilitator: Deep Dive (50h), US$ 7,500 to US$ 12,500. Acquirer in production: Full Scope (100h+), from US$ 15,000. BACEN-regulated acquirer + PCI DSS Level 1 (6M+ transactions/year): Full Scope (150h+), from US$ 22,500. PTaaS (recurring): on request. The hourly rate ranges from US$ 150 to US$ 250 per hour.
Do you cover transaction fraud beyond PCI?
Yes. Coverage includes refund race conditions, BIN attacks, replay of signed transactions, double spending on Pix, currency manipulation in multi-currency accounts, anti-fraud bypass through payload modification and chargeback flow abuse.
What is a refund race condition?
It happens when two refund requests reach the gateway at the same time. Without proper locking, both complete — and the customer gets back twice the original amount. We've found this pattern repeatedly in pentests of Brazilian sub-acquirers, and the impact is a direct financial loss.
Next step
Request a proposal for your payments platform.
Mutual NDA within 24h. Once it's signed, a 60-minute technical call to map your CDE scope, and a formal proposal within 3 business days.
Talk to a researcher