The First Spark: Two Undelivered Cards and Two Amazon Alerts

In standard banking operations, the process of renewing credit cards is subject to a strict security protocol known as the Chain of Custody. When a bank creates a shipping waybill for a new card, the old card should expire and enter a mandatory destruction phase under the responsibility of an authorized employee, making it unusable for any electronic or physical transaction.
But what happened at Riyad Bank represents a clear breach of this linear protocol. This is where the story begins — the collapse of the bank's security system, and the attempt to cover it up.
1. Renewal Notice and Shipping Waybill
The case began with an official notification from Riyad Bank informing the customer that the credit card was about to expire and that a replacement would be delivered via the authorized courier.

2. The Moment of Shipment and the First Leak (*1174)
On May 14, 2025, at 01:46 PM, Aramex’s system officially showed the shipment had been received at the main offices in Riyadh.

Here emerges the fatal operational gap: the old card ending in 1174 — which should have been destroyed and fully deactivated — was not. Its complete data was leaked in conjunction with the shipment handover.
At 01:56 AM on the same date (May 14, 2025), the record shows an unauthorized purchase attempt associated with AMAZON.COM. Because the alert precedes the displayed afternoon courier timestamp, the two timestamps should be treated as separate events on the same date—not proof that one immediately followed the other.

3. Analytical Conclusion of the First Incident
The same-date records do not identify the source of exposure by themselves. They do establish an urgent question: how did an unauthorized Amazon attempt become associated with card 1174 while the replacement and delivery process remained unresolved?
4. Recurrence with the Replacement Card (*1233)
The story did not end there. The bank issued a replacement card ending in 1233. On May 22, 2025, at 02:26 PM, Aramex received the replacement card.

On the same day (May 22, 2025) at 10:58 PM, the crime repeated itself identically: a new unauthorized attempt on AMAZON.COM using the replacement card that had not yet been delivered to the customer.

Conclusion the Bank Tries to Evade
The recurrence on two dates (May 14 and May 22, 2025) raises the possibility of a persistent vulnerability. Identifying the precise leak path requires issuer, card-production, tokenization, merchant, and courier audit records.
These two dates are exactly what the bank later tried to hide from the Saudi Central Bank (SAMA) through software tampering with data files — as we will reveal with digital evidence in the next article.
HD.39 / Digital Forensics Record