BI-FAST payment module penetration test: a case study
A digital bank and its payment subsidiary were three weeks away from joining BI-FAST, Bank Indonesia’s real-time payment system. Before going live, they needed to show Bank Indonesia and OJK (Indonesia’s Financial Services Authority) that the new payment module was safe. Two corporate clients were waiting to use it.
Our test found a way for a criminal to take over the phone number a customer uses to receive money. The bank fixed it before launch.
What BI-FAST changes for a bank
BI-FAST lets customers send money instantly to a “proxy”, such as a phone number, email address or ID number, instead of an account number. The bank keeps the link between each proxy and the right account. Payments settle in real time, so there is little chance to stop a bad one once it has gone.
That puts pressure on a few specific points. The bank must be sure who owns a proxy. It must process each payment exactly once. And it must be able to trust the settlement messages it receives.
What we tested
The module had 23 endpoints (the individual functions that other systems call). They covered proxy registration, credit transfers, settlement and exception handling. We tested how proxies are registered, removed and looked up, how transfers are processed, and whether limits could be bypassed. We also reviewed how the bank stores its signing keys and whether personal data leaked into logs.
The work followed the OWASP API Security Top 10 and the OWASP Web Security Testing Guide, two widely used public testing references. CREST-certified testers carried it out.
The weakness that mattered most
When a customer re-registered a phone number as a proxy, the system did not check that they owned that number. An attacker could therefore link someone else’s phone number to their own account. Payments meant for the victim would then land with the attacker.
We demonstrated this in the test environment. We re-linked a test phone number to a different account and watched a transfer follow it.
Two more ways money could go wrong
The system did not check whether a transfer request had already been processed. When we sent the same request twice, the account was credited twice.
The module also accepted settlement confirmations without checking their digital signature. A forged message could tell the bank that a payment had settled when it had not.
We reported 19 findings in total: one critical chain of linked issues, 3 high, 6 medium and 9 low. The report explained each in terms of fraud exposure and possible Bank Indonesia sanctions, so the board could see what was at stake.
How the bank closed the gaps
Changing a proxy now requires a one-time code sent to that number, followed by a waiting period before the change takes effect. The database rejects duplicate transfer requests. Settlement messages are checked against their signature before the bank acts on them.
The critical issues were fixed within three days, and our retest confirmed they were closed. The bank then completed BI-FAST certification and launched on its planned date. It also added a fraud alert, connected to Snipeyes Fraud Detection, that fires when a proxy changes hands too often.
For the technical team
- Endpoints: proxy registration, deregistration, alias resolution, credit transfer,
idempotencyKeyhandling andsettlementCallback - Critical:
phoneNoownership not verified at re-registration; PoC re-bound+62xxxin UAT and diverted funds - High: no uniqueness check on
idempotencyKey, so a replayed credit transfer was credited twice - High:
settlementCallbacksignature not validated, allowing a forged settlement status - Also tested: per-account and per-alias rate limits, amount limits, duplicate submission, race conditions, HSM and vault key management, message signing, mTLS, PII in logs
- Mapping: OWASP API Top 10, BI-FAST Spec v1.3, OJK POJK 11/2022, PCI DSS 4.0 and ISO/IEC 27001
- Fixes: OTP verification and cool-down on proxy change, database unique constraint on the idempotency key, HMAC verification on callbacks
- Report within 10 days of testing, retest included
Any bank joining BI-FAST, directly or through a sponsor bank, faces the same questions about proxies, duplicate payments and settlement. We can help you answer them before your Bank Indonesia review.