I too think it is disinformation.
The document says that the system is already running live, connecting with banking systems and accepting funds wired in. From my IT background, I know that in a live system of even moderate scale, it would be impossible for a bunch of testers to roam around in the system and make random changes at will. Any change, especially significant changes such as upgrading a user status, will leave an audit trail that points to who did it.
Testers (stress test, penetration test) are just normal users in the system. They are not administrators. Even administrators would probably have compartmentalised access rights so they wouldn't be able to such a thing.
The whole document is wishful thinking: Follow, trust some saviours and they will save you. You don't have to do any hard work. Unfortunately, real life usually doesn't work that way.
The document says that the system is already running live, connecting with banking systems and accepting funds wired in. From my IT background, I know that in a live system of even moderate scale, it would be impossible for a bunch of testers to roam around in the system and make random changes at will. Any change, especially significant changes such as upgrading a user status, will leave an audit trail that points to who did it.
Testers (stress test, penetration test) are just normal users in the system. They are not administrators. Even administrators would probably have compartmentalised access rights so they wouldn't be able to such a thing.
The whole document is wishful thinking: Follow, trust some saviours and they will save you. You don't have to do any hard work. Unfortunately, real life usually doesn't work that way.