The End of SMS OTP: The Global Ban Wave and the Paradigm Shift in Enterprise Authentication

AI Research
Author
恩梯科技
2026-08-21 165 views 8 分鐘閱讀

Once regarded as a cornerstone of digital security, the SMS one-time password (SMS OTP) is being pushed toward extinction by regulators worldwide. Singapore and the United Arab Emirates have ordered financial institutions to retire text-message authentication, while the Reserve Bank of India is explicitly steering the industry toward stronger mechanisms. This is not a single country's policy but a paradigm shift spanning regulation, security, and user experience. For Taiwanese enterprises that still treat SMS OTP as their last line of defense, understanding the data and timelines behind this trend is no longer optional—it is essential risk management.

From Security Cornerstone to Biggest Breach Point: Where SMS OTP Falls Short

The problem with SMS OTP is not that it is "inconvenient," but that it was never designed to withstand modern attacks. The SS7 and Diameter signaling protocols that underpin telecom networks contain known vulnerabilities; by renting or breaching signaling nodes, attackers can silently intercept and redirect text messages without the victim—or any store clerk—ever being involved. The other route is the SIM swap: fraudsters use social engineering to convince a carrier to port a number to their own SIM, after which every OTP flows straight to the attacker.

These are not theoretical risks but escalating real-world damage. The U.S. FBI's Internet Crime Complaint Center (IC3) logged 982 SIM swap cases with roughly US$25.98 million in losses in 2024; UK fraud-prevention body Cifas reported that SIM swap cases surged 1,055% in 2024, from 289 to nearly 3,000; and Australia's IDCARE saw a 240% rise in related help requests, with 90% of victims compromised without any interaction at all. Scaled up, global telecom fraud losses reached US$41.82 billion in 2025. As the attack surface widens, SMS OTP has turned from a defense into a breach point.

The Global Ban Wave: One Table to Read Every Timeline

Over the past year, regulators have shifted from "recommending stronger controls" to "mandating retirement." The overview below shows two distinct tempos: Singapore and the UAE are enforcing hard bans, while India and Taiwan are guiding a transition.

MarketRegulator & BasisKey TimelineDirection
SingaporeMAS & Association of Banks (July 9, 2024 notice)Login OTP disabled within three months of the notice for digital-token usersHard retirement
UAECentral Bank of the UAE, Notice 2025/3057 (May 2025)Migration to app-based auth from July 25, 2025; full removal of SMS and email OTP by March 31, 2026Hard retirement + liability shift
IndiaRBI Directions on Authentication Mechanisms for Digital Payments (2025)Two-factor authentication mandatory from April 1, 2026; SMS OTP not banned outright, but at least one factor must be dynamically generated, with biometrics, device binding, and hardware tokens encouragedGuided transition
TaiwanFSC "Financial FIDO" and security control guidelinesFinancial mobile-identity alliance formed in 2021; Financial FIDO V2 underway, building a cross-system verification hub and gradually expanding eligible servicesStandards-based guidance

Notably, these approaches cannot be lumped together. The UAE is the most aggressive—not only banning OTP but pushing fraud liability back onto banks—while the Reserve Bank of India deliberately preserves flexibility, stating plainly that the new rules do not require discontinuing SMS OTP but rather move the whole ecosystem toward stronger factors. Grasping this distinction is key to correctly judging your own compliance pressure.

The Great Liability Shift: When Banks Answer for Intercepted OTPs

The most consequential aspect of this regulatory wave is the reversal of liability. The UAE Central Bank's Notice 2025/3057 stipulates that if a customer's OTP is intercepted or coaxed out of them in a phishing or SIM swap attack, the financial institution must fully reimburse the loss. In other words, continuing to use SMS OTP is no longer merely a security question—it is a financial liability written directly onto the balance sheet. This explains why major banks such as Emirates NBD, ADIB, and FAB completed their switch so quickly.

The cost of relying on SMS OTP has painful precedents. In the autumn of 2022, around US$400 million in assets was stolen from the FTX exchange via SIM swap—one of the largest such heists ever. U.S. carrier T-Mobile was ordered in arbitration to pay US$33 million over a single SIM swap incident, and venture investor Michael Terpin's US$24 million suit against AT&T has dragged on for years, with the Ninth Circuit overturning an earlier ruling favorable to the carrier in 2024. The message these figures send is consistent: once an authentication mechanism can be intercepted, the losses and lawsuits land on the enterprise itself.

Alternatives Are No Longer Theory: The Hard Data on FIDO and Passkeys

The mainstream answer to replacing SMS OTP is the FIDO standard and passkeys. Their core advantage is phishing resistance: the private key and biometrics stay on the user's device while the server holds only the public key, so even intercepted traffic yields no replayable credential. This is no longer experimental technology—on World Passkey Day 2026, the FIDO Alliance announced that global passkey usage had surpassed five billion, with 90% of people aware of passkeys and 75% having enabled one on at least one account. Enterprises are accelerating too: 68% of organizations have deployed or are deploying passkeys for employee sign-ins, and 82% cite full passwordless as a goal—28% of them already there.

Crucially, adopting passkeys does not trade experience for security; it delivers both. Below are the measured results published by major platforms:

MetricPasskey / FIDO ResultSource
Login success rate98% (passwords only 32%)Microsoft
Login success rate93% (other methods 63%)FIDO 2025 Passkey Index
Login success rate30% higher than passwords (across 800M+ accounts)Google
Login speed8.5 sec (traditional MFA 31.2 sec, 73% faster)FIDO Alliance
Support load81% fewer sign-in-related help desk callsIndustry deployment data

By industry, active adoption already reaches about 60% in fintech, 35% in ecommerce, 28% in B2B SaaS, and 18% in media and entertainment, with a cross-industry average of 33% to 38%. The trend is clear: the sectors moving fastest are precisely those most targeted by fraud.

A Pragmatic Roadmap for Taiwanese Enterprises

Taiwan has not imposed a hard ban like the UAE, but through "Financial FIDO" and its security control guidelines, the FSC has made the direction clear. Rather than waiting to be pushed by regulators or fraudsters, enterprises should take stock early. A pragmatic rollout can follow four steps:

  • Inventory high-risk scenarios: First identify the operations where impersonation causes the greatest loss (e.g., transfers, contact-info changes, admin logins) and upgrade authentication at those points first.
  • Deploy phishing-resistant strong authentication: Lead with FIDO/passkeys, in-app push approval, and device binding, downgrading SMS OTP to low-risk or backup use rather than the primary defense.
  • Adopt risk-based tiering: Dynamically adjust authentication strength by transaction amount and context, balancing security and experience to avoid a blunt, churn-inducing approach.
  • Plan retirement and fallback: Design flows for lost devices, cross-device sync, and account recovery—the most overlooked yet outcome-determining part of any passkey rollout.

Nerdtechnic has long helped Taiwanese small and medium enterprises operationalize security and digital transformation, and we know that upgrading authentication is not a matter of swapping in one tool—it is systems engineering that touches process, risk control, and user experience. We help enterprises inventory high-risk scenarios, evaluate rollout paths for FIDO/passkeys and multi-factor authentication, and integrate existing systems with retirement and fallback mechanisms so that upgrades proceed without disrupting operations. As the era of SMS OTP draws to a close, we aim to stand alongside enterprises and turn this paradigm shift into a genuine competitive advantage rather than a passive compliance burden.

References

  • FBI IC3, "2024 Internet Crime Report" (SIM swap: 982 cases, ~US$25.98M losses) — ic3.gov
  • Cifas, "1055% surge in unauthorised SIM swaps" (2025) — cifas.org.uk
  • IDCARE, "Hijacked Connections: The Reality of Phone Porting and SIM Swap Scams" — idcare.org
  • TNS / CFCA, "The Telecom Fraud Landscape in 2026" (global telecom fraud losses US$41.82B) — tnsi.com
  • Monetary Authority of Singapore (MAS), "Banks in Singapore to Strengthen Resilience Against Phishing Scams" (July 9, 2024) — mas.gov.sg
  • Onlayer, "CBUAE Notice 3057 — What Banks & PSPs Must Do Before March 2026" — onlayer.com
  • IBM, "Strengthening Digital Payment Security with RBI's New Authentication Directions" — ibm.com
  • Taiwan Financial Supervisory Commission, press release on the founding of the Financial Mobile Identity Alliance (June 15, 2021) — fsc.gov.tw
  • Central News Agency (CNA), "FSC plans Financial FIDO verification hub, over 70 firms interested" (Jan 4, 2024) — cna.com.tw
  • tbreak, "UAE Banks Are Phasing Out OTPs" (Emirates NBD, ADIB, FAB rollout status) — tbreak.com
  • Krebs on Security, "Arrests in $400M SIM-Swap Tied to Heist at FTX?" — krebsonsecurity.com
  • Commsrisk, "T-Mobile US Pays $33mn for SIM Swap Cryptocurrency Theft" — commsrisk.com
  • Courthouse News Service, "Ninth Circuit allows crypto investor to pursue claim against AT&T over $24 million hack" (2024) — courthousenews.com
  • FIDO Alliance, "Five Billion Passkeys: A Milestone, Not a Finish Line" (World Passkey Day 2026) — fidoalliance.org
  • FIDO Alliance, "The State of Passkeys 2026: Global Consumer and Workforce Report" — fidoalliance.org
  • Microsoft, "Pushing passkeys forward" (98% vs 32% login success) — microsoft.com
  • FIDO Alliance, "FIDO Alliance Launches Passkey Index" (93% vs 63% login success; 8.5s vs 31.2s) — fidoalliance.org
  • FIDO Alliance, "Passkey Adoption Doubles in 2024" (Google: 30% higher success, 800M+ accounts) — fidoalliance.org
  • FIDO Alliance, "FIDO Passkeys: Passwordless Authentication" (81% fewer sign-in-related help desk calls) — fidoalliance.org
  • MojoAuth, "Passkey Adoption Rates by Industry (2026)" — mojoauth.com

Want to bring these practices into your own company?

Free consultation on LINE

We don't chase volume.

We build long-term relationships with a select few partners worth going deep with.

Free System Health Check

Need Help?

Click here to contact us!

Contact Now