Table of Contents
SMS OTP verification has now been out of Philippine high-risk banking for one hundred days: June 30 marked the BSP Circular 1213 deadline, and every bank, e-wallet, and payment operator supervised by the Bangko Sentral was required to phase out text-message codes for the transactions that matter — new payees, big transfers, contact-detail changes, new-device logins. Cyber Watch #011 (Friday Gov Watch) audits the aftermath: what the migration actually changed in your apps, the AFASA liability flip that now makes non-compliant institutions pay for fraud losses, and the new scam surface the migration itself created — push-approval fatigue, the attack that bombs your screen with prompts until you tap approve. One hundred days in, the receipts show a system mid-transformation, exactly where the regulation intended — and exactly where scammers have adjusted.
Key Takeaway
- 📲 The SMS OTP shift is real and enforced: BSP Circular 1213’s June 30, 2026 deadline passed without extension (Deputy Governor Elmore Capule, January 2026: “As of now we are not extending it”) — high-risk transactions now require phishing-resistant, device-bound verification: server-side biometrics against bank-held templates, or FIDO2/WebAuthn passkeys with device attestation.
- ⚖️ The liability flip arrived with it: AFASA’s (RA 12010) compliance grace period expired the same month — where a bank’s authentication or fraud systems fall short, liability for unauthorized-transaction losses shifts to the institution; the Supreme Court’s August 24 ruling in the BDO Unibank case signals courts are already operating in this posture.
- 🔔 The new scam surface is the migration’s own shadow: in-app push approvals replace interceptable codes — but push approvals can be FATIGUE-BOMBED (the MFA-fatigue playbook: steal credentials, flood prompts, wear the target into one tap). The BSP’s own layering rule (biometrics + device binding + behavioral signals + risk scoring, never push alone) exists precisely because of this vector.
- 🧾 The scale receipts that made this non-negotiable: Philippine digital fraud runs at rates among the world’s highest (a cited 13.4% — roughly triple global norms), average loss ₱44,700 per incident, and real-time fraud monitoring is now mandatory for institutions above ₱75M average monthly transaction value.
- 🧭 Your move this weekend: a five-app-point audit — update every banking app, enable biometrics, register passkeys where offered, review approved payee lists, verify your registered numbers — before the push-fatigue crews find your apps still on legacy settings.
The 100-Day Tape: What the SMS OTP Deadline Actually Did
The receipts, from the compliance primary-adjacent sources (Authsignal’s Circular 1213 analysis, IPID’s compliance breakdown, the KasKasan consumer explainer — concordant on every provision):
- What was banned: the SMS OTP — email one-time PINs too — as the verification factor for HIGH-RISK transactions — adding a new payee, updating registered contact details, initiating large transfers, logging in from a new device. The scope is universal: commercial banks, digital banks, e-money issuers (GCash and Maya among them), payment system operators including InstaPay and PESONet participants, credit card issuers, remittance companies — no small-institution carve-out.
- What replaced it: two approved families — server-side biometrics validated against bank-held templates, and FIDO2/WebAuthn-standard passkeys with device attestation. In the app: face ID, fingerprint, and device-bound approval prompts. Crucially, biometrics ALONE does not satisfy the rule; the BSP requires layered authentication — biometrics combined with device binding, behavioral signals, and transaction risk scoring.
- What SMS OTP still does: exactly ONE permitted use remains — confirming the existence or ownership of a registered mobile number. If a “bank” text asks you to read out a code for anything else, it is not the regulation’s OTP anymore; it is an attack.
- The fraud-system floor: institutions offering complex electronic services or averaging over ₱75M monthly transaction value must run real-time fraud detection — behavioral anomalies, geolocation, blacklist screening, device-change events — alongside the authentication upgrade. Third-party biometrics vendors carry their own due-diligence and data-protection obligations under the circular.
The AFASA Liability Flip: When the Bank Pays
- The two-part statute: RA 12010 (July 20, 2024) is, first, a criminal law — financial account scamming, money muling (lending or selling your account is a crime with 6-8 year exposure), social engineering schemes — with penalties up to 10-12 years and ₱1M-2M fines when victims are senior citizens, up to life imprisonment for economic-sabotage scales. Second, it is a liability law: institutions must hold disputed funds, run the required fraud systems, and — where authentication and controls fall short of the standard — bear the losses.
- The June 2026 convergence: the compliance grace period expired in the same month as the SMS OTP deadline — the PHLaw.AI analysis frames it plainly: banks and e-money issuers were required to have fraud management systems and stronger authentication in place by then; where they do not, liability for unauthorized transactions shifts from depositor to institution.
- The judicial signal: on August 24, 2026 the Supreme Court ruled in the case against BDO Unibank that a bank cannot demand the return of money a depositor has already — the ruling runs with the statute’s consumer-protective grain. For the ordinary account holder, the combined posture means: strong authentication is now YOUR first duty, system adequacy is the BANK’s liability.
- Why the numbers forced this: the Philippines’ digital fraud incidence runs among the world’s highest (the cited 13.4% figure — near-triple global averages), with average losses of ₱44,700 per incident. The SMS code — passable through any telecom channel, liftable by SIM swap, phishable in real time — was the door the regulation closed.
The New Scam Surface: Push-Approval Fatigue
Every security migration displaces its attack. The SMS OTP era’s signature crimes were smishing and SIM swap; the device-bound era’s emerging signature is MFA fatigue — push bombing:
- The mechanics, receipt-documented (SoSafe’s glossary entry, MSP Blueshift’s 2026 analysis): attacker obtains your credentials first (phishing, breach reuse); triggers the approval prompts your bank’s new system legitimately generates; floods them — dozens, often at 2 a.m.; until you approve one to make it stop, or approve by accident, or approve after a fake “bank support” call tells you to. The 2022 Uber breach (Lapsus$) is the canonical corporate case; consumer banking is the next mass application.
- Why PH banking is fertile ground: the entire country migrated AT ONCE (June 30) — millions of users newly trained to expect approval prompts for transfers, on apps most have never opened the security settings of. Fatigue attacks exploit exactly that training window.
- The control the BSP wrote for this: the layering mandate (biometrics + device binding + behavioral signals + risk scoring — never a bare push approval) is the systemic answer; the personal answer is the refusal protocol below.
- The standing rule set, series-consistent: never approve a prompt you did not trigger; deny and report immediately (a denied prompt flags the credential compromise); verify transaction context inside the app (amount, payee) — never from the notification; remember the number-confirmation OTP carve-out keeps SOME legitimate texts flowing, so the smishing playbook (the series’ smishing defense guide) stays loaded too.
The Weekend Audit: Five Checks on Every Banking App You Own
- 1 — Update everything: authentication upgrades (passkeys, biometric flows) ship through app updates — an out-of-date banking app may still be offering the legacy path that creates liability debates. Update from the official store only.
- 2 — Enable biometrics + register passkeys: turn on face/fingerprint login and device-bound approval; where the app offers passkey registration (FIDO2), register it — passkeys are the phishing-resistant endgame the circular names.
- 3 — Audit payee lists: the new-payee flow is the highest-risk transaction under the rule; review every approved payee on every account, remove dormant entries, and treat any unexpected new payee as an incident.
- 4 — Verify registered numbers: number-ownership SMS OTP remains the one SMS use — confirm each bank holds your CURRENT number (a stale number = both a lockout risk and a takeover vector if reassigned by telcos).
- 5 — Turn on notification context: in app settings, enable detailed transaction notifications — when a push shows amount and payee, fatigue attacks lose their camouflage; a prompt with no context gets denied on principle.
The OFW Money Angle: Verifying From Abroad
- The remote-verification trap: OFWs manage PH accounts from abroad — the audit is harder through time zones and roaming. Do it while on Wi-Fi with the apps updated; every piece of this checklist completes remotely except device-bound biometrics, which requires the physical device YOU hold — your advantage, not your obstacle.
- The family-account reality: accounts managed with a spouse or parent in PH still bind to ONE device set for passkeys — agree who holds the approving device, and rehearse the refusal protocol with them (the family verify ritual pattern applies to bank prompts exactly as it does to AI voice cloning).
- The remittance lane: the safe-transfer guide carries the standing transfer-security stack; the 100-day shift adds one receipt: transfers from abroad that trigger new-device verification will now prompt BIOMETRIC approval on the registered device — expect that prompt on your own phone, never approve it “for someone” on theirs.
- The scam-call overlay: the fake “bank support” follow-up call is the fatigue attack’s closer — banks do not call to ask you to approve prompts; the boss-text playbook logic extends: urgency + approval-request = deny first, verify by calling the bank’s official line yourself.
The Watch: Enforcement Receipts to Track Next
- BSP enforcement actions: the circular carries supervisory consequences for non-compliance — the first public enforcement/fine receipts (or quiet remediation) are the next scoreboard.
- Passkey rollouts by institution: GCash, Maya, BPI, BDO, GoTyme, UnionBank each ship device-bound flows at different speeds — the rollout ledger doubles as the consumer-choice map.
- The next GASA fraud-rate print: the 13.4% baseline — whether the 100-day migration bends it at the next Philippines report.
- Push-fatigue case receipts: the first documented consumer-banking fatigue attacks in PH (if they surface on community forums or BSP consumer-assistance data) — the series tracks the vector’s arrival.
- AFASA case law: post-August 24 SC posture — restitution rulings that harden the liability flip into precedent.
Frequently Asked Questions
What is BSP Circular 1213?
The Bangko Sentral ng Pilipinas regulation (issued June 2025, implementing AFASA/RA 12010) that required every BSP-supervised financial institution — banks, e-money issuers, payment operators, remittance companies — to phase out the SMS OTP and its email twin for high-risk transactions by June 30, 2026, replacing them with phishing-resistant, device-bound verification: server-side biometrics or FIDO2/WebAuthn passkeys, always layered with device binding and risk scoring. The deadline was confirmed un-extended by Deputy Governor Elmore Capule in January 2026.
Are SMS OTPs completely banned in the Philippines now?
Not completely — one use remains permitted: confirming the existence or ownership of a registered mobile number. What was banned June 30, 2026 is using SMS codes to AUTHORIZE high-risk transactions (new payees, large transfers, contact-detail changes, new-device logins). Any text asking you to read out a code for anything beyond number confirmation is not the regulation’s OTP in action — treat it as an attack and never share it.
Can scammers still steal money if my bank uses biometrics?
Yes — every control has an adjacent attack. The device-bound era’s emerging vector is MFA fatigue (push bombing): scammers who already hold your credentials flood your phone with approval prompts until you approve one — often at night, sometimes paired with a fake bank-support call. The defense is behavioral: never approve a prompt you did not trigger, deny and report immediately, verify transaction details inside the app itself. Biometrics plus your refusal discipline is the layered defense the BSP’s rule expects.
What does AFASA mean for my money if my account gets drained?
RA 12010 (the Anti-Financial Account Scamming Act) shifts liability to the institution where the bank’s authentication or fraud systems fall short of the required standard — its compliance grace period expired in June 2026, the same month as the OTP deadline. It also obliges banks to temporarily hold disputed funds, and the Supreme Court’s August 24, 2026 BDO ruling runs with that consumer-protective grain. Your own duty under the regime: enable the strong authentication your app offers and document what you did. The series’ AFASA reimbursement claims guide details the claims path.
What should I do if I get repeated approval prompts I did not request?
Deny the prompt, change the account password immediately from a trusted device, contact the bank through its official published channels, and review recent access history. Do NOT approve anything to “make it stop” — approval completes the attacker’s login. Do NOT act on any call or text that follows “explaining” the prompts — that call is part of the attack. The denial itself protects you; the password change closes the door the attacker was knocking on.
About This Analysis
This article is security intelligence for informational purposes only and is not legal or financial advice. Regulatory provisions are summarized from BSP Circular 1213 secondary analyses, RA 12010 primary text, and cited case reporting as of October 9, 2026; application to a specific account dispute depends on your institution’s terms and the facts of the case. Verify with your bank and, where needed, consult counsel.






