Concealed Dates? Examining the Records Submitted to SAMA
A statement is not necessarily a complete database extract. It may be limited by product, posting status, card number, date range, report configuration, or the purpose for which it was generated. When material dates are absent, the first task is to identify the report’s scope before attributing the omission to a particular query or operator.
This report compares the dates documented elsewhere in the case—May 14, 2025 for card 1174 and May 22, 2025 for card 1233—with the material supplied during the complaint process to the Saudi Central Bank (SAMA).
1. The Time Gap
The submitted material, as published here, does not visibly include the two dates associated with the Amazon alerts. The omission is significant, but the image alone does not identify whether those events were excluded, declined without posting, held in another authorization system, or outside the report parameters.

The proper disclosure should identify the report type, its date range, filters, posting logic, and whether declined or zero-value authorizations appear in a separate system. Without that information, the regulator and customer cannot know whether the document answers the security complaint.
2. The Blatant Financial Contradiction: Fees on a Stolen Card!
The manipulation did not stop at hiding dates. It extended to committing an accounting blunder that proves confusion. In the same statement, we find on May 21, 2025 a transaction recorded under the description (LOST STOLEN REPLACEMENT FEE) worth 50 SAR for the replacement card (1233)!
How can a "lost/stolen replacement fee" be charged for a replacement card on May 21, while the same card was shipped, leaked, and attempted to be used the very next day, May 22?! The bank imposes fees on a compromised card before it reaches the customer, while simultaneously deleting the records of the actual breach date from the regulatory report!
3. What Cannot Be Inferred From a Screenshot
A screenshot of report output cannot reveal the SQL statement, report template, or operator action that produced it. Many technical mechanisms could omit an event. Claiming a specific NOT IN query without a query log would replace evidence with speculation.
The records that would resolve the issue are the report definition, extraction parameters, authorization logs, posting logs, audit history, and the exact file supplied to SAMA with its metadata.
Conclusion
The material raises a serious completeness question. It does not, without the underlying logs, establish who selected the report parameters or why the relevant dates were absent. That is precisely why the regulator should request the source-system records rather than rely on a presentation-layer extract.
HD.39 / Digital Forensics Record