Retest included. If a fix does not hold on retest, we test it again at no cost until it does. How it works

We break inon purpose.

THJ Security attacks your applications, networks and cloud the way a real adversary would, proves it with a working exploit, and hands you the exact path to shut it down.

Fixed quote in 2 business days · Retest included · See our research

Engagements across
FintechBankingTelecomPublic sectorSaaSE-commerce
The gap

Scanners find noise. Attackers find paths.

A scanner reports what looks wrong. An attacker chains what actually works: a weak token here, a race there, a forgotten admin route, and suddenly it is someone else's money.

Annual checkbox pentests do not close that gap. They arrive late, test wide and shallow, and leave your engineers with a PDF full of unranked guesses.

We test the way the people who will attack you do, and we only report what we can prove.

Built by people who came up through CTFs and bug bounty on Google, AWS and open source, we run on one rule: proof, not theory.

Approach

A clear engagement, start to fixed.

Set the scope once. We test, prove, report and retest, and keep you in the loop every day. Anything critical is escalated the moment we find it.

Retest is included in every engagement. The job is done when the fix is verified, not when the invoice is sent.

Request an assessment
ScopeDays 1-2

Rules of engagement

Targets, objectives and constraints agreed in writing. Fixed price, fixed window.

TestWeeks 1-3

Hands-on exploitation

Daily comms. Criticals escalated the moment we confirm them.

ReportFinal week

Impact, repro, fix

Every finding with a working exploit and a concrete remediation, readable by engineers and execs.

RetestAfter your fix

Verified closed

We re-run every finding and confirm nothing new broke. Included, not billed.

Proof

Real exploits. Real fixes.

Ask for a redacted sample report before you commit to anything. Same structure, same level of detail, real findings.

See a sample report

How we work

  • Proof, not theory. Every finding ships with a working exploit path.
  • Fixable reports. Prioritised, reproducible, written for whoever remediates.
  • Discretion by default. NDAs, responsible disclosure, your data handled like ours.
  • Retest included. The job isn't done until the fix is verified.
Findings summaryTHJ-2026-0xx · redacted
  • CriticalCross-tenant fund transfer via payout race
  • HighIDOR on merchant payout endpoint
  • HighSSRF in webhook validator reaches metadata
  • MediumSession fixation on SSO callback
  • LowVerbose stack traces on 500s
14 findings · 2 critical · every one with a fixRetest: 14/14 verified
Advisories

Real vulnerabilities. Real impact.

We hunt in the software the region runs on and work responsibly with vendors to get it fixed before it is used against anyone.

No public advisories yet. Disclosures appear here once the vendor fix has shipped.
Company

Attacker mindset. Engineer's discipline.

THJ Security is a boutique offensive-security practice in Ulaanbaatar, Mongolia, working with fintech, banking, telecom and public-sector teams across the region.

We come from the CTF and bug-bounty world, so we test like the people who actually attack you, and write like the engineers who have to fix it. Every engagement is led by a senior operator from first recon to final retest. No outsourced juniors. No scanner-and-invoice.

Contact

Tell us what you are building.

We scope an assessment and send a fixed quote, usually within two business days. Nothing you type here is stored on this site; submitting opens a pre-filled email.

Location
Ulaanbaatar, Mongolia · UTC+8
Response within two business days