The PayID search function on Australia's New Payments Platform ( NPP ) has been hit with another glitch. This time, a series of files and data have been leaked. 
NPP, which oversees all transactions that occur on the system, confirmed on Tuesday that some data was exposed due to a vulnerability in one of the financial institutions funded by Cuscal Limited.
NPP Australia was notified of the incident on Friday evening. Cuscal told NPP Australia that the technical issues that caused the datawere resolved immediately.
The data exposed included PayID and account numbers.
“None of this information can on its own allow funds to be withdrawn from a customer’s account without further involvement from the customer,” NPP Australia said.
PayID allows payments to be made via NPP without any other banking information – BSB and account number. PayID is a unique number for each user, linked to a bank account and can be a phone number, email address or Australian Business Number (ABN).
It can only be used to deposit money into an account and not to withdraw money.
As the PayID is a unique number for each user, when a payment is made, the name registered in the PayID is displayed as part of the confirmation process.

However, this means that a person can be found by entering their phone number.
PayID does not include any other personal information, so no other data is exposed.
In June, Westpac's PayID search function was also hacked.
Westpac discovered that hackers had gained access to a very large amount of data. However, customers.
Australia's New Payments Platform (NPP) went live last February. Its infrastructure was built by the Reserve Bank of Australia (RBA), Commonwealth Bank of Australia (CBA), National Australia Bank (NAB), Australia and New Zealand Banking Group (ANZ) and Westpac.
NPP Australia said it has regulations in place to prohibit the disclosure of bank account details. In addition, the regulations require financial institutions participating in the platform to conduct ongoing checks to detect and prevent any attempts to abuse the PayID service.
These regulations include the suspension of access to the PayID service by organizations that do not meet these requirements, while they have recently been strengthened by the introduction of fees for those who do not comply.
