Banks move away from SMS OTPs in favour of app-based authentication methods

Yong Jun Yuan
Published Wed, Jul 5, 2023 · 08:50 PM
    • SMS messages, which are not encrypted, can be intercepted and read by fraudsters in a number of ways.
    • SMS messages, which are not encrypted, can be intercepted and read by fraudsters in a number of ways. PHOTO: BT FILE

    BANKS are pushing customers away from the less secure authentication method of SMS One-Time Passwords (OTPs), and promoting app-based methods instead.

    They stopped short of phasing out SMS OTPs completely, though.

    This comes as the Monetary Authority of Singapore (MAS) has required banks to phase out SMS OTPs as a sole factor to authenticate high-risk transactions, such as adding payees and changing fund transfer limits.

    A deadline will also be set for all retail banks to provide such authentication methods for other high-risk card transactions, such as online payments, said Senior Minister Tharman Shanmugaratnam, who is also minister in charge of MAS, in a written reply on Wednesday (Jul 5) to a parliamentary question.

    On Jun 19, Citi customers were notified that they will be able to authenticate Internet banking transactions by scanning a QR code with their Citi Mobile App and using either biometric or password authentication instead of receiving an SMS OTP.

    Citibank Singapore digital banking head Prachi Vijlani said the proposed method is more secure as “authentication using the push notifications and the QR code can only be done through the customer’s registered Citi Mobile App, whereas SMS OTP is susceptible to man-in-the-middle attacks”.

    Because SMS messages are not encrypted, they can be intercepted and read by fraudsters through malware installed on victims’ phones.

    The Cyber Security Agency of Singapore in May published an advisory about such malware targeting Android devices, which are able to access and delete SMS OTPs and transaction notifications.

    Fraudsters overseas have also stolen mobile numbers by requesting that such numbers be ported to other telcos, or that a new SIM card be issued.

    Vijlani added that Citi is progressively rolling out the push notification as an authentication solution for merchants using 3D Secure, an additional security layer for online credit and debit card transactions. The bank aims to complete its implementation “within this year”, she said.

    With this solution, users receive a push notification on their mobile apps to authenticate card transactions – instead of an SMS OTP.

    Vijlani said the bank will continue to offer SMS OTPs to customers as a back-up option while it transitions them to these new methods.

    The Business Times understands that digital lender Trust Bank does not use SMS as an authentication method. Authentication for transactions is done through push notifications sent through the bank’s mobile app.

    The trio of local banks also have alternative authentication methods for customers.

    A DBS spokesperson said a majority of its customers have already activated and used digital tokens to authenticate online banking transactions. There are plans to transition customers from SMS to digital token authentication for online card payments in the coming months.

    OCBC head of group digital business and digital transformation Serene Koh said 94 per cent of its customers have registered for the bank’s app-based authentication method, which allows customers to authenticate transactions via the OCBC website with push notifications.

    Since end-March 2023, customers have also had the ability to tap on the push notifications on their banking app to authorise online purchases.

    Choo Wan Sim, head of UOB’s digital bank TMRW Digital in Singapore, said UOB customers have also been able to register and set up digital tokens on their banking apps.

    They will then be prompted with push notifications to authenticate Internet banking logins, as well as other higher-risk transactions such as adding new payees and updating transaction limits.

    SMSes have been recognised as a weak link in the delivery of digital banking services, and have also become a sticking point for a proposed framework to share financial losses related to digital banking scams.

    MAS and the Association of Banks in Singapore introduced additional measures regarding the use of SMS in January last year. Banks are no longer allowed to send clickable links in emails and SMSes to retail customers.

    MAS announced in February last year that a framework is being developed for how losses from scams should be shared among consumers and financial institutions.

    This framework was expected to be released for public consultation three months after it was announced.

    Responding to a question in Parliament in May, Tharman acknowledged that the development of the framework has “taken some time”.

    He said the government has been in discussions with telcos as it intends to include them in the framework.

    “Our aim is to strengthen the roles and accountabilities of the key parties who can mitigate the risk of phishing scams and to preserve confidence in digital payments in Singapore.

    “This includes making clear the duties of FIs and telcos in particular, and the responsibility of customers themselves to be vigilant against scams,” he said.

    The public consultation paper is now expected in the third quarter of this year.

    In his statement on Wednesday, Tharman said MAS does not see the need to require banks to opt out of SMS OTPs as this is an authentication method that can be accessed by all customers on any type of mobile device.

    “Removing SMS OTPs entirely will exclude a significant number of online banking customers who do not own mobile devices that can install digital tokens,” he said.

    The Infocomm Media Development Authority also introduced mandatory SMS sender ID registration in October last year, in a bid to curb scam SMSes.

    This is supposed to prevent fraudsters from impersonating banks and sending SMSes to customers, which led hundreds of OCBC customers to be scammed during the year-end festive period in 2021.

    The full registration requirement took effect on Jan 31, 2023. Any messages sent with unregistered sender IDs were labelled as “Likely-SCAM” for around six months after that, and will eventually not reach their intended recipients in the end.