1. The Plaintext Database Vulnerability
Most traditional desktop billing applications store customer records in unencrypted database files located in generic folders like C:\Billing or C:\JewelApp. Anyone with physical access to the shop PC—or a technician providing remote support via AnyDesk—can copy the entire customer phonebook and transaction history in under 30 seconds without triggering a single alert.