They may have exfiltrated personal data by different means, but this week’s successful compromise of Westpac’s PayID service highlights the continuing threat faced by organisations whose business relies on collecting large volumes of sensitive information. PayID – a new service that allows customers to transfer money to other customers using only mobile phones as an identifier – was compromised after an enumeration attack saw a large number of user lookups lodged from several compromised Westpac accounts.
Read full article on CSO