Customise Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorised as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyse the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customised advertisements based on the pages you visited previously and to analyse the effectiveness of the ad campaigns.

No cookies to display.

Banks in Singapore phasing out OTP login for digital token users to combat scams

0

Major banks in Singapore will begin phasing out the use of one-time passwords (OTP) for bank account logins by customers who are digital token users.

These banks include DBS, OCBC, and UOB.

The move, which will be implemented within the next three months, will protect bank users against phishing scams, the Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) said in a press release on Tuesday (July 9).

Bank customers who are using physical tokens will not be affected.

Customers who have activated their digital token on their mobile device will have to use them for bank account logins via the browser or the mobile banking app, MAS and ABS said.

The digital token will authenticate customers’ logins without the need for an OTP, which scammers can steal or trick them into disclosing, they added.

“Customers who have not activated their digital tokens are strongly encouraged to do so to lower the risk of having their credentials phished,” MAS and ABS said.

$14.2 million was lost to phishing scams last year.

Introduced in the 2000s, OTPs were seen as a multi-factor authentication option to strengthen online security.

But technological developments and more sophisticated social engineering tactics have since enabled scammers to phish for customers’ OTP, MAS, and ABS.

Phishing scams were among the top five ruses in Singapore last year, with at least $14.2 million lost, according to data released by the Singapore Police Force earlier this year.

“This latest measure will strengthen the authentication process, making it harder for scammers to fraudulently access a customer’s account and funds without the customer’s explicit authorization using his mobile device,” they added.

The director of ABS, Ong-Ang Ai Boon, said that while this measure may give rise to some inconvenience, it is necessary to help prevent scams and protect customers.

“MAS continues to work closely with banks to protect consumers by leaning hard against digital banking scams,” Loo Siew Yee, MAS’s assistant managing director (policy, payments, and financial crime), added.

“This latest measure will complement good cyber hygiene practices that customers must continue to practice, such as safeguarding their banking credentials.”

Leave A Reply

Your email address will not be published.