fresh no ads
Goodbye, SMS OTPs: Banks' move to safer checks and what it means for you | Philstar.com
^

The Budgetarian

Goodbye, SMS OTPs: Banks' move to safer checks and what it means for you

Ana Crescini - Philstar.com
Goodbye, SMS OTPs: Banks' move to safer checks and what it means for you
Your bank may soon stop texting OTPs. What comes after this?
Philstar.com illustration

MANILA, Philippines — Banks and e-wallets are moving away from SMS and email one-time passwords, or OTPs, especially for high-risk transactions, as regulators push financial institutions toward harder-to-steal forms of authentication.

The reason is simple: OTPs are easy for users, but also easy for scammers to target.

"OTPs were built for a less complex threat environment," Sylvain Chaperon, general manager of 8x8 CPaaS, said in a report by The STAR.

Fraudsters can exploit the system through SIM swapping, message interception and social engineering schemes that trick customers into giving away their codes.

"In a mobile-first economy like the Philippines, where the smartphone is most people's primary gateway to banking and payments, that makes the authentication step a high-value target," Chaperon said.

What's replacing OTPs?

The shift follows Bangko Sentral ng Pilipinas Circular 1213, which discourages reliance on authentication methods that can be shared with or intercepted by third parties, such as SMS and email OTPs.

Instead, banks and e-wallets are expected to use stronger methods such as biometrics, passkeys, in-app approvals, device checks and adaptive authentication based on a customer's location, device and behavior.

In plain language, your bank may soon ask: Is this your usual phone? Is the transaction coming from your usual place? Has your SIM changed recently? Does the transfer look unusual for you?

If the transaction looks normal, verification may happen quietly. If it looks risky, the bank may ask for another layer of approval.

So what should users do to adapt to the change? You can keep banking apps updated, enabling app notifications and making sure their mobile number and device registered with their bank are current.  

Customers should also avoid sharing OTPs, passwords or approval prompts with anyone if they are clients to institutions that have no made the shift. 

Users should be suspicious of calls from those who claim to be from the bank asking for OTPs. Lost phones or suspicious SIM activity should also be reported to the bank.

Some have already moved

Some financial platforms have already announced or rolled out changes.

  • GCash said it would replace SMS-based authentication with in-app OTPs sent through in-app push notifications starting June 22.
  • BDO similarly announced that app-based push authentication will replace OTPs for BDO Online website logins and transactions starting July 17.
  • BPI already uses Mobile Key, which allows users to authorize transactions or web logins through the BPI app.
  • Metrobank has also described a system where transactions require approval from an enrolled primary device instead of traditional OTPs.

Why this may be safer

Security experts have long warned that SMS-based verification is weaker because it relies on the phone network and the customer's ability to avoid scams.

Newer methods are harder to phish because they bind approval to a trusted device, app or biometric check. Some verification can also happen silently in the background, leaving no code for a scammer to intercept or persuade a customer to share.

OTPs may not vanish overnight. But for most sensitive transactions, the six-digit text code is slowly becoming an antiquated lock.

BANKING SECTOR

BANKS

PHISHING

Philstar
Are you sure you want to log out?
X
Login

Philstar.com is one of the most vibrant, opinionated, discerning communities of readers on cyberspace. With your meaningful insights, help shape the stories that can shape the country. Sign up now!

Get Updated:

Signup for the News Round now

FORGOT PASSWORD?
SIGN IN
or sign in with