
John Paul Siapel
The era of one-time password (OTP) security code is officially over for major digital banking users after the Bangko Sentral ng Pilipinas (BSP) enforced a policy for institutions to abandon one-time passwords for high-risk online transactions.
Under BSP Circular No. 1213, financial institutions processing over 75 million pesos in monthly online volume had until June 25 to transition to advanced, device-bound multi-factor authentication systems.
The mandate applies to all financial institutions, digital banks, major universal and commercial banks and e-wallets.
It serves as the operational mechanism for Section 6 of the Republic Act No. 12010 or the Anti-Financial Account Scamming Act (AFASA), aiming at aggressively reversing a national fraud epidemic that previously spiked to more than double the global average.
“BSP is equally dedicated to promoting innovation in financial services as to protecting customers from new forms of fraud, including technology-enabled fraud,” said BSP Deputy Governor Lyn I. Javier in an official statement addressing the structural overhaul.
The policy shift directly targets legacy telecommunications infrastructure vulnerabilities, specifically the decades-old Signaling System No. 7 routing protocol, which global cybersecurity experts have warned allows bad actors to intercept text messages through specialized SIM-swapping tactics.
While lower-risk actions like balance inquiries can still utilize standard text alerts, critical operations like third-party fund transfers, device registrations, and credential alterations now mandate server-side biometrics or cryptographic passkeys.
Mandated protocols are legal
The BSP confirmed that compliance with the newly enacted framework acts as a legal shield for universal and commercial banking institutions operating across the archipelago.
Under the specific liability clauses of the AFASA law, banks that successfully deploy these mandated risk management protocols are legally insulated from the financial repercussions of digital theft.
“There will be no extensions for this rollout, and any institution failing to deploy phishing-resistant, server-side biometric barriers by the deadline will be legally mandated to fully reimburse fraud victims out of their own corporate pockets,” BSP Deputy Governor Elmore Capule said.
This sharp statutory shift means financial organizations can no longer blame user error or compromised consumer hygiene to avoid covering losses resulting from network intrusions.
Due to systematic failure
The regulator targeted SMS authentication due to the systemic failure of external telecommunications infrastructure to protect encrypted data streams from modern interception tools.
Furthermore, this sweeping ban comes as a direct response to a staggering domestic crisis, given that regional data tracks the digital fraud rate in the Philippines at an alarming 13.4%, effectively tripling the current global average.
Real-time phishing scripts and localized intercept equipment have made stealing a temporary text string as simple as tricking an unsuspecting user into loading a fraudulent website.
“Each of these attacks works because the authentication factor has to leave the bank’s systems and pass through a channel anyone can potentially intercept,” according to an article published by security firm Authsignal.
Unlike the basic fingerprint or facial recognition setups used to unlock consumer smartphones, server-side frameworks do not rely on local operating system integrity.
Instead, the live biometric data captured through the camera or scanner is transmitted as a heavily encrypted representation directly to the bank’s secure cloud backend.
“The ideal secure banking experience should feel almost invisible to the user,” noted Moises Ycot, growth lead for the Philippines at identity verification firm Sumsub, when evaluating the domestic market’s systemic readiness.
Furthermore, these systems feature advanced deepfake detection and automated transaction-velocity algorithms designed to freeze automated bot attacks in real time before funds can be transferred out of the domestic payment clearing networks.
Looking back to statistics
According to the National Information and Communications Technology Household Survey (NICTHS), 62.5 percent of Filipino technology users reported encountering at least one cybersecurity incident, while 33.4 percent of the population demonstrated awareness of data privacy policies.
“The BSP is equally dedicated to promoting innovation in financial services as to protecting customers from new forms of fraud, including technology-enabled fraud,” said BSP Deputy Governor Lyn I. Javier, whose agency noted that text-message scams and malicious SMS fraud accounted for 57.1 percent of the total cyber threats documented by the state statistics agency.
The national survey further indicated that 1.9 percent of the affected individuals formally reported these digital incidents to authorities, providing the context for the BSP regulatory intervention to discontinue text-based authentication for high-risk online banking activities.