Viw Magazine

Men's Weekly

.

  • Written by Paul Haskell-Dowland, Associate Dean (Computing and Security), Edith Cowan University
Linking your mobile number to your bank account could have unintended consequences. SewCream/Shutterstock.com

When we think of a bank robbery, we might imagine a safe with the door blown open. But nowadays it might be more accurate to picture criminals accessing our bank account online from another country. Bank robbers don’t need balaclavas and shotguns anymore.

Australian banks have long provided convenient ways for customers to transfer funds. But the process of remembering and entering BSB and account numbers is prone to human error. Enter PayID.

PayID allows customers to attach their mobile phone number or email address to their bank account. They can then simply provide these details to other people, providing a convenient way to receive payments.

It can only be used for incoming payments, rather than outgoing ones. So you might think that makes it less of a tempting target for hackers. But that’s not necessarily the case.

Launched in February 2018 by New Payments Platform Australia, an alliance of 13 banks, PayID is reportedly available to more than 52 million account holders across almost all major financial institutions. By February 2019, some 2.5 million PayID identifiers had been created, and 90 million transactions totalling more than A$75 billion had been processed.


Read more: The New Payments Platform may mean faster transactions, but it won't be safer


When entering a PayID mobile phone number to make a payment, the full name of the account holder is displayed, so the person making the payment can ensure they are sending it to the right PayID account.

Shortly after the service launched, Twitter users began pointing out that this means you can enter random phone numbers and, if that number has been linked to a PayID account, the account holder’s name will show up – rather like a phone book in reverse.

Twitter posting of PayID details. @anthonycr0

The following day, on February 17, 2018, NPP Australia acknowledged this issue in a media release, but effectively dismissed users’ concerns:

While unfortunate for the individuals involved, the discussion highlights the choice and benefits to be considered by users when they opt in to create a PayID.

This is not exactly reassuring for bank customers whose details were publicly posted. And developments this year suggest that the underlying problems persist.

Better luck next time?

In June 2019, around 98,000 PayID details were obtained after hackers used several online bank accounts to carry out more than 600,000 PayID lookups over the course of six weeks, reportedly by simply entering phone numbers in sequential order.

It is not clear who was to blame, although there are allegations of a leaked memo pointing the finger at US-based fraudsters.

The exact motive is unclear, but any personal data has value in the underground economy. In this case, the data could potentially be used as part of a more complex phishing scam designed to steal further information from account holders.

Although this is clearly a very simple attack involving nothing more sophisticated than simple trial and error, it appears the PayID system did not detect the large number of lookups – an average of 14,000 per account – or the speed with which they were undertaken.

To give a real-world example, it would be like going into your bank 14,000 times and handing over a different piece of identification each time.

This high volume of lookups should have raised significant security concerns. While legitimate users could be forgiven for needing a couple of tries to punch in the right number, no one should need thousands of attempts.

It should have been a simple security step to add lookup limits and to identify this as highly abnormal behaviour. Yet neither the bank concerned nor NPP Australia had implemented mechanisms to detect or prevent this form of misuse.

After a security breach this size, the banks might reasonably be expected to take urgent steps to prevent it happening again. But it did happen again, two months later.

In August 2019, a further 92,000 PayIDs were exposed. In this case, it was reported that the breach happened within the systems of a financial institution connected to the NPP Australia systems. Worryingly, this breach reportedly revealed users’ full name, BSB and account number.

Banks were quick to reassure customers that this does not allow transactions to be undertaken. However, it did deliver yet more valuable information into the hands of cyber criminals – further enabling phishing opportunities.

While affected customers have been contacted, the only option to remove this risk is to stop using PayID. This is easily done but removes the convenience factor for most bank customers.

What’s the real risk?

Because the system enables payments into accounts, rather than authorising withdrawals from them, the risk may seem minor. Indeed, many in the banking sector have dismissed it as so. But there is a deeper risk.

Phishing is a form of cyber crime in which victims are tricked into revealing confidential information through convincing-looking emails or SMS messages. Unfortunately, there are already examples of this in relation to PayID.

Real examples of PayID-related SMS phishing messages. canstar.com

The approach depicted above is not particularly sophisticated. But imagine a more tailored email message quoting examples of identifiable information (PayID, full name) or, as with the most recent breach, BSB and account number.

Coupled with the correct branding and reassuring words of your bank, it would be easy to convince an unsuspecting user of the need to “login to change your PayID for security reasons”. Just a few minutes of creativity on a computer can produce convincing results.

The image shown below was created to show how easy this process is. It uses genuine branding, but the “login” button could easily be set to direct users to a website designed to steal login credentials.

Mock-up of a potential PayID-related phishing email.

With the ME Household Financial Comfort Report indicating that almost 50% of households have at least A$10,000 in savings, there is a clear incentive for cyber criminals to target our bank accounts. As with any phishing attack, it only takes a few people to succumb to make the enterprise worthwhile.


Read more: Banks can't fight online credit card fraud alone, and neither can you


Although bank customers can do little more than think twice before responding to messages, the real power is with the banks. Simply being alert to unusual patterns of behaviour would have prevented these security breaches.

This is not new territory for financial institutions, who routinely look for unusual patterns in credit card transactions. Perhaps it is time to apply these same concepts in other scenarios and better protect Australia’s banking customers.

Paul Haskell-Dowland does not work for, consult, own shares in or receive funding from any company or organisation that would benefit from this article, and has disclosed no relevant affiliations beyond their academic appointment.

Authors: Paul Haskell-Dowland, Associate Dean (Computing and Security), Edith Cowan University

Read more http://theconversation.com/payid-data-breaches-show-australias-banks-need-to-be-more-vigilant-to-hacking-123529

No Credit Check Loans in Australia: What They Signal About Access to Credit

No credit check loans sit at the intersection of financial inclusion and risk management in Australia’s lending market. Often discussed ...

Domestic vs Commercial Builders in NSW: Licensing Differences Explained

When planning a construction project in New South Wales, choosing the right builder is crucial to ensure quality, compliance, and a smooth p...

Hybrid vs. Standard Caravans: Which is Better for a Family of Four?

Families exploring caravans for sale often compare hybrid and standard models to find the best balance of comfort, practicality and off ro...

First Time Shopping at a Caravan Clearance Sale? Here’s What to Know

If you’re in the market for a caravan, you should have a good idea of what you’re looking for by now. If a caravan clearance sale is loo...

Why the Alps Should Be on Every Traveler’s Bucket List

The Alps: one of the most remarkable mountain ranges in the world. A place where nature, culture, activity, and tranquility meet like a ha...

Exploring Local Markets and Artisan Shops in the Alps

Your ultimate guide to exploring the markets and artisan shops in the Alps of all of the regions' excursions is one of the most authentic ...

The Importance Of Professional Fiberglass Boat Repair For Strength, Safety And Long-Term Performance

Boats made from fiberglass are known for their durability, lightweight structure and smooth performance. However, even the strongest vesse...

Why Choosing the Right Cosmetic Clinic Bundoora Matters for Confidence and Care

Personal appearance can influence confidence, comfort, and overall wellbeing. Many people seek treatments to enhance features, refresh the...

Best Home Care Package Meal Providers: A Comprehensive Guide for Australian Seniors

As we age, maintaining proper nutrition becomes increasingly important, yet preparing healthy meals can become challenging for many older Au...

The Benefits Of Residential Solar Power Systems For Long-Term Energy Savings And Sustainability

Many homeowners are turning to residential solar power systems as a practical way to reduce rising electricity costs, improve energy inde...

Paint Protection Film Brisbane: The Ultimate Guide to Protecting Your Vehicle

Brisbane's harsh subtropical climate, with its intense UV rays, summer storms, and coastal conditions, can wreak havoc on your vehicle's pai...

The Complete Guide to Name Tags: Types, Benefits, and Best Practices

Whether you're organising a corporate conference, managing a retail team, or hosting a networking event, name tags play a crucial role in fa...

How Family Court Lawyers Can Guide You Through High-Conflict Parenting Disputes

High-conflict parenting disputes can be draining, unpredictable and emotionally overwhelming, especially when communication has broken dow...

Why Professional Evaporative Cooling Repair Is Important for Reliable Performance and Summer Comfort

Evaporative cooling is widely used in many homes. However, like any cooling system, it can experience wear, blockages, or mechanical fault...

How 3pl Companies Support Business Growth Through Efficient Warehousing And Fulfilment Solutions

As customer expectations continue to rise, businesses rely heavily on streamlined logistics to deliver products quickly and accurately. Ma...

Restoring Rental Spaces To Perfection Before Moving Out

A stressful part when leaving a rented home is ensuring the space is spotless and ready for inspection. A professional's help becomes invalu...

Why More Aussies Are Choosing Pontoon Boats To Launch a Waterside Lifestyle

Soaking up the long, sunny days of summer is a classic Australian pastime, and there’s no better way to do it than aboard a boat. But wh...

Building Bespoke Spaces: Why a Custom-Driven Approach Truly Matters

When it comes to creating a home that’s a perfect fit for your lifestyle, a Fiteni Homes-style approach offers unmatched flexibility and...

Refining Facial Contours with Modern Surgical Techniques on the Gold Coast

When we think of rejuvenation and restoring youthful contours, a targeted solution such as a face lift can be transformational. For those ...

Term Deposits Australia: A Complete Guide to Fixed-Rate Savings

For Australians seeking a safe, predictable way to grow their savings, term deposits australia options provide an attractive solution. Off...

hacklink hack forum hacklink film izle hacklink สล็อตเว็บตรงbets10คลิปโป๊deneme bonusucrown155 casinohb88aussuper96 loginbetsmoveyakabetyakabethttps://www.chicnic.org/casibom한국야동jojobet girişสล็อตpadişahbetcasibomgiftcardmall/mygift주소모음 주소모아spin2u loginneoaus96 casino loginJojobetStreameastartemisbetmarsbahisjojobetgooglebets10ff29 casinoStreameastholiganbetstakemate77best e-wallet pokies 2025破解工具топ 10 казинорейтинг лучших казиноjojobet 1115holiganbetzbahis girişjojobetmostbetpusulabetjojobet 1115mostbetbahis siteleri 2025matbet girişjojobetwww.giftcardmall.com/mygiftjojobetcasibomcasibom girişgiftcardmall/mygiftsadfasdfsdfasdasdasdasdmeritkingmatbetjojobetroyalbet girişлучшие казино на деньгиpin up azcasino med Klarnajojobet 1115Casibomwww.mcgift.giftcardmall.com balancegiftcardmall/mygiftwww.giftcardmall.com/mygift activatetm menards loginartemisbetparibahisbetasussekabetpusulabetcasibomcasibomlunabetzbahisfixbetfixbet girişbets10casibomcasibom girişbetsmovecasibomsitus slot gacorGalabetcasibom9046google hit botudizipalmarsbahisjojobetjojobetmarsbahiskonya escortpusulabetpusulabeteSIM Evropajojobetmatbetjojobet girişartemisbetbetasusjojobetmeritkingjojobetmarsbahisMarsbahispusulabetcasibommarsbahiskingroyalJojobetgiftcardmall/mygiftbetlikedeneme bonusu veren sitelerbahiscasinojojobet girişStreameastтоп рейтинг казиноcasibomcratosroyalbetcasibom girişmatbetGanobetJojobetcasinolevantsekabet girişmarsbahisjojobet girişmeritking girişextrabetholiganbetprimebahistaraftarium24jojobetjojobetgrandpashabetjojobetonwin girişmilanobetbets10vaycasinobetnanocasibomvevobahisbets10bets10meritkinggrandpashabetJojobet girişjojobetonwin girişbetebetbetpassekabetMeritkingMarsbahisbuy shrooms canadacasibomcasinofastmatbet hacklink hack forum hacklink film izle hacklink สล็อตเว็บตรงbets10คลิปโป๊deneme bonusucrown155 casinohb88aussuper96 loginbetsmovecasibom한국야동jojobet girişสล็อตpadişahbetcasibomgiftcardmall/mygift주소모음 주소모아spin2u loginneoaus96 casino loginJojobetStreameastartemisbetmarsbahisjojobetgooglebets10ff29 casinoStreameastholiganbetstakemate77best e-wallet pokies 2025топ 10 казинорейтинг лучших казиноjojobet 1115holiganbetzbahis girişjojobetmostbetpusulabetjojobet 1115mostbetbahis siteleri 2025matbet girişjojobetwww.giftcardmall.com/mygiftjojobetcasibomcasibom girişgiftcardmall/mygiftsadfasdfsdfasdasdasdasdmeritkingmatbetjojobetroyalbet girişлучшие казино на деньгиpin up azcasino med Klarnajojobet 1115Casibomwww.mcgift.giftcardmall.com balancegiftcardmall/mygiftwww.giftcardmall.com/mygift activatetm menards loginartemisbetparibahisbetasussekabetpusulabetcasibomcasibomlunabetzbahisfixbetfixbet girişbets10casibomcasibom girişbetsmovecasibomsitus slot gacorGalabetgoogle hit botudizipalmarsbahisjojobetjojobetmarsbahiskonya escortpusulabetpusulabeteSIM Evropajojobetmatbetjojobet girişartemisbetbetasusjojobetmeritkingjojobetmarsbahisMarsbahispusulabetcasibommarsbahisJojobetgiftcardmall/mygiftbetlikebahiscasinojojobet girişStreameastтоп рейтинг казиноcasibomcratosroyalbetcasibom girişmatbetGanobetJojobetcasinolevantsekabet girişmarsbahisjojobet girişmeritking girişextrabetholiganbetprimebahistaraftarium24jojobetjojobetjojobetonwin girişmilanobetbets10vaycasinobetnanocasibomvevobahisbets10bets10grandpashabetJojobet girişjojobetonwin girişbetebetbetpassekabetMeritkingMarsbahisbuy shrooms canadacasibomcasinofastmatbet