Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    ;
    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Banking > Banks must ditch SMS one-time passcodes – and fast
    Banking

    Banks must ditch SMS one-time passcodes – and fast

    Banks must ditch SMS one-time passcodes – and fast

    Published by Gbaf News

    Posted on October 24, 2019

    Featured image for article about Banking

    By Frans Labuschagne, United Kingdom and Ireland country manager, Entersekt 

    The rise of SIM swap fraud and the number of headline-making vulnerabilities exposed in recent weeks, putting over one billion mobile users at risk, provide overwhelming evidence that the technology is outdated

    Frans Labuschagne

    Frans Labuschagne

    When the news broke in mid-September that over one billion mobile phone users are potentially at risk from a SIM card vulnerability that is currently being exploited by cybercriminals, it came as no surprise to me. Rather, I found myself despairing that so many financial institutions are still, despite numerous warnings, persisting with one-time passcodes (OTPs) sent – and therefore easily intercepted by bad actors – via SMS messages.

    The so-called SimJacker flaw, identified by researchers at AdaptiveMobile Security, is yet another alarming example that lays bare how at-risk SIM cards and SMS messages are to hackers. This latest glitch has been exploited for two years by “a specific private company that works with governments to monitor individuals”, according to AdaptiveMobile Security.

    “SimJacker has been further exploited to perform many other types of attacks against individuals and mobile operators,” continues the researcher’s report, “such as fraud, scam calls, information leakage, denial of service and espionage.”

    Since Entersekt’s inception, in 2010, our position has been that SMS OTP is not secure, and the revelation about SimJacker further emboldens that position. There was more evidence to strengthen our case only two weeks before the SimJacker flaw was discovered, when a server containing an unprotected database of over 419 million phone numbers linked to Facebook accounts was exposed.

    The leak of phone numbers could potentially open a huge number of users to SIM swap-type fraud. Organised crime groups trade digital files packed with personal data and account details sourced in mass data breaches and malware attacks. The fraudster will buy this data and use it to open a parallel account in their chosen victim’s name.

    Other details in the file or gained separately through social engineering and searches online provide them with enough information to answer security questions at the relevant mobile network operator and register a new SIM. The victim’s SIM is deregistered in turn, and the answers to security questions changed in order to frustrate the victim’s attempts at rectifying the situation.

    If more proof was needed to ditch SMS OTPs, earlier in the year Metro Bank became the first major financial institution to be named as a victim of hackers who were able to steal OTPs by hijacking customers’ text messages. It is understood that other banks have also been damaged by cybercriminals exploiting flaws in a set of protocols established over 40 years ago, called Signalling System No7 (SS7). Developed in 1975, SS7 is used by telecoms companies to coordinate how they route calls and SMS messages around the world. The age and open nature of SS7 makes it vulnerable to cybercriminals pretending to be network providers. It was clear when Metro Bank was called out in February that SIM swap fraud was on the rise, meaning OTP texts were no longer enough protection. That was almost eight months ago.

    At the time, back in February, a National Cyber Security Centre (NCSC) spokesman said: “We are aware of a known telecommunications vulnerability being exploited to target bank accounts by intercepting SMS text messages used as 2-Factor Authentication.” The NCSC’s understated verdict was: “Text messages are not the most secure type of two-factor authentication.”

    The truth is security experts have known about SMS technology flaws for some time and have regularly warned organisations about them. Indeed, as long ago as 2015, in the Strong Authentication Requirements for internet payments, as issued by the European Banking Authority (EBA), SMS-based authentication was listed as a method “to be avoided”.

    Regulatory bodies in the financial industry are slowly beginning to heed these black-and-white warnings, as SMS OTPs’ risks to consumer security overtake the cost benefits. In spite of all this, digital banking security has a long way to go. It is business critical for organisations using SMS OTPs to move on – and fast – if they want to avoid falling prey to the inevitable risk inherent in relying on such out-of-date methods.

    Financial institutions should be providing customers with the services they want and what’s good for them, and not sacrificing one over the other. Moreover, risk-based “Band-Aid” approaches to security, such as risk-based algorithms, are problematic because they fail to provide a complete security solution.And, if breached or the wrong decision is made, it can often end up costing orders of magnitude more than an up-to-date cyber defence.

    There is good news, though: while SMS may not be secure enough to deliver OTPs, the mobile device itself can be used to authenticate financial transactions. Leveraging the ubiquity, computing power and connectivity of the mobile device not only provides the potential to bank anywhere, anytime, but allows banks to authenticate and secure interactions of all kinds at speed.

    In order to protect against SIM swap attacks, it is advisable that service providers make strong user authentication available and users elect to use it. This will combine knowledge factors like a password or PIN with either a strong possession factor like a mobile phone, FIDO keys, or an inherence factor such as facial or fingerprint recognition biometrics. These can all be facilitated through any mobile phone less than a decade old.

    It’s important for financial institutions to be aware that there are a range of alternatives to SMS OTPs, including digital signing and biometric enablement. A secure mobile app, for instance, creates a secure channel between the user and the bank, rather relying on the telecom’s provider.

    Essentially, the customer makes a connection to the bank and then uses their mobile device as authentication which opens a completely separate, secure connection to the bank. The user will receive a pop-up notification asking: “Is this you making the transaction?” The customer will then answer “yes” or “no” with one click on their smartphone. Because it is a secure and separate channel, it means it can’t be intercepted and is not vulnerable to SIM-swap fraud.

    Most experts in the cybersecurity industry can’t understand why in late 2019 banks are still using SMS OTPs to fight financial fraud. They have been rendered ineffective, inconvenient for users, and are susceptible to SIM swap or number-porting attacks, fake caller IDs, and call forwarding scams operated by dishonest customer service representatives at mobile carriers. Worse, OTPs do not guarantee protection from phishing attacks and malware-enabled account takeover fraud. Banks need to move with the times, ditch the SMS OTPs and invest in alternative cyber security solutions – before it’s too late.

    Related Posts
    DeFi and banking are converging. Here’s what banks can do.
    DeFi and banking are converging. Here’s what banks can do.
    Are Neo Banks Offering Better Metal Debit Cards Than Traditional Banks?
    Are Neo Banks Offering Better Metal Debit Cards Than Traditional Banks?
    Banking at the Intersection: From Nashville to Cannes, A Strategic Call to Action
    Banking at the Intersection: From Nashville to Cannes, A Strategic Call to Action
    Driving Efficiency and Profit Through Customer-Centric Banking
    Driving Efficiency and Profit Through Customer-Centric Banking
    How Ecosystem Partnerships Are Redefining Deposit Products
    How Ecosystem Partnerships Are Redefining Deposit Products
    CIBC Private Banking wins four 2025 Global Banking & Finance Awards
    CIBC Private Banking wins four 2025 Global Banking & Finance Awards
    How Banks Can Put AI to Work Now and Prove ROI in 90 Days
    How Banks Can Put AI to Work Now and Prove ROI in 90 Days
    Top 5 AI quality assurance framework providers for Banks and Financial Services firms.
    Top 5 AI quality assurance framework providers for Banks and Financial Services firms.
    The Unbanked Paradox: How Banking Access Creates Economic Resilience
    The Unbanked Paradox: How Banking Access Creates Economic Resilience
    Hyper-Personalised Banking - Shaping the Future of Finance
    Hyper-Personalised Banking - Shaping the Future of Finance
    The End of Voice Trust: How AI Deepfakes Are Forcing Banks to Rethink Authentication
    The End of Voice Trust: How AI Deepfakes Are Forcing Banks to Rethink Authentication
    Predicting and Preventing Customer Churn in Retail Banking
    Predicting and Preventing Customer Churn in Retail Banking

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Banking PostAre banks missing out on the benefits of real-time cash liquidity reporting, asks new Deutsche Bank paper
    Next Banking PostAhli United Bank is the 2019 Global Banking & Finance Awards® winner for Most Innovative Digital Banking Initiative (Smart Branch) Kuwait 2019

    More from Banking

    Explore more articles in the Banking category

    Growth and Impact: Banreservas Leads Dominican Republic Economic Expansion

    Growth and Impact: Banreservas Leads Dominican Republic Economic Expansion

    Turning Insight into Impact: Making AI and Analytics Work in Retail Banking

    Turning Insight into Impact: Making AI and Analytics Work in Retail Banking

    KeyBank Embraces Next-Generation AI Platform to Transform Fraud and Financial Crime Prevention

    KeyBank Embraces Next-Generation AI Platform to Transform Fraud and Financial Crime Prevention

    Understanding Association Banking: Financial Solutions for Community Success

    Understanding Association Banking: Financial Solutions for Community Success

    Applying Symbiosis for advantage in APAC banking

    Applying Symbiosis for advantage in APAC banking

    AmBank Islamic Berhad Earns Triple Recognition for Excellence in Islamic Banking

    AmBank Islamic Berhad Earns Triple Recognition for Excellence in Islamic Banking

    FinTok Strategy: How Banks Are Reaching Gen Z Through Social Media

    FinTok Strategy: How Banks Are Reaching Gen Z Through Social Media

    Rethinking Retail Banking Sustainability: Why the ATM is an Asset in the Sustainable Transition

    Rethinking Retail Banking Sustainability: Why the ATM is an Asset in the Sustainable Transition

    How private banks can survive the neo-broker revolution

    How private banks can survive the neo-broker revolution

    Next-Gen Bank Branches: The Evolution from Transaction Hubs to Experience Centers

    Next-Gen Bank Branches: The Evolution from Transaction Hubs to Experience Centers

    The Banking Talent Crunch: How Financial Institutions Are Competing for Digital-Native Skills

    The Banking Talent Crunch: How Financial Institutions Are Competing for Digital-Native Skills

    Beyond Interest: How Banks Are Reimagining Revenue in the Digital Age

    Beyond Interest: How Banks Are Reimagining Revenue in the Digital Age

    View All Banking Posts