Security Origin
In 2014 I took RAT malware apart and traced its command-and-control infrastructure. Two years later I noticed a PIN limit at a local bank that was too short. I worked out what that meant in practice and sent concrete remediation notes.
I reported only what I could prove, and left it at that.
EvidenceThe history is documented in local archive sources. There is no verified public link yet.