OCBC to continue with physical tokens as it weighs fraud risks to customers
OCBC has told The Business Times it is halting its move to phase out physical hardware tokens - previously slated for end-March 2022 - amid the sharp rise in online fraud involving the bank last month.
"We are not phasing out hardware tokens and will continue to enable customers to use hardware tokens for two-factor authentication of digital banking," said OCBC head of global consumer financial services Sunny Quek on Thursday (Jan 6) evening.
The lender had previously announced that it would completely phase out the use of hardware tokens on its online banking platform by March 31, 2022.
All customers would have to switch to OCBC's digital security token, integrated within its mobile app, to authenticate transactions.
DBS had stopped issuing physical tokens since February 2021 and fully phased out the use of these tokens in April 2021.
UOB had stopped issuing physical tokens in 2018, though customers can still request for one should they want to.
BT has reached out to both banks for comment.
OCBC's move to keep its hardware tokens comes after nearly 470 people have lost at least S$8.5 million in SMS phishing scams impersonating the bank since the start of December.
Francisco Celio, OCBC head of group corporate security, said that unlike other SMS phishing scams, the recent attack is "particularly aggressive and highly sophisticated in duping consumers" into disclosing their personal banking details, despite repeated bank warnings to be alert and not to do so.
Victims had received unsolicited SMSes purporting to be from OCBC, claiming there were issues with their banking accounts and they had to click on a link given in the message to resolve the issue.
The link led to fraudulent bank websites and victims were asked to key in their Internet banking account login details. They discovered that they had been scammed when they received notifications that there were unauthorised transactions in their bank accounts.
BT understands that the scams are still ongoing.
"The recent SMS phishing attack is not the first and will certainly not be the last. We will continue to put in additional measures as new tricks are continuously deployed by scammers. The success of these scammers hinges on them obtaining personal banking details from bank customers. Therefore, we want to again remind our customers to be vigilant and not to disclose their personal banking details to unverified sites," said Celio.
Mobile access to bank accounts should always be done via the official banking or payment app, or by keying in the bank's URL directly into the phone browser.
OCBC said it will never ask customers to access their bank accounts through SMS links.
The bank is currently working with the police on this incident.
TRENDING NOW
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
Grab CEO’s wife Chloe Tong on life with Anthony Tan and finding her purpose
What role can Japan play in Asean’s future?
From folding clothes to factory work: Why China is sending humanoid robots to school