LepakLah
Tech

Online Banking Security in Malaysia: Why SMS OTP Is Being Phased Out

Bank Negara Malaysia's updated RMiT policy made SMS OTP non-compliant as a standalone second factor. Here is what device binding, cooling-off periods on new phones and passkeys actually change for an ordinary Malaysian account holder.

Lepaklah Editorial7 min read
A person holding a smartphone while using a banking app.
A person holding a smartphone while using a banking app.

Somewhere in the last two years, the six-digit code stopped arriving by SMS and started living inside your banking app — and almost nobody told you why. That switch is the most visible part of a much bigger change to online banking security in Malaysia, one that Bank Negara Malaysia (BNM) finished writing into binding rules and that every licensed bank, insurer, takaful operator and e-wallet in the country now has to follow.

The short version: the regulator decided the SMS network is no longer a safe place to send anything that protects your money.

The longer version is worth understanding, because four of the five changes are things you can check or turn on yourself this week.

What changed in November 2025, and why SMS lost

BNM's Risk Management in Technology policy — everyone calls it RMiT — is the rulebook for how regulated financial institutions handle technology risk. It covers IT governance, cloud, cybersecurity and, most relevant here, how a bank is allowed to verify that you are you.

The version issued in November 2025 replaced the June 2023 edition. The important shift was not that new ideas appeared. It was that ideas which had been sitting at the level of guidance — nice-to-have, best practice, encouraged — were rewritten as mandatory standards.

The scope is wide. It is not just Maybank and CIMB. It reaches licensed Islamic banks, development financial institutions like Bank Rakyat and BSN, insurers and takaful operators, approved e-money issuers including Boost, TNG Digital and GrabPay, and payment system operators. If it holds a BNM licence, the rules apply.

You can read the policy document yourself on the Bank Negara Malaysia website. It is dry, but the authentication section is short.

The headline change: the updated policy requires MFA "more secure than unencrypted SMS" and resistant to interception or manipulation by a third party. SMS OTP on its own no longer qualifies.

Two attacks drove that. The first is SIM swap — a fraudster convinces a telco to port your number onto a SIM they control, and every code meant for you arrives on their phone instead. The second is straightforward interception, using tooling that reads codes in transit before you ever see the notification.

Neither is theoretical in Malaysia.

What this means in practice: if your bank still sends you a plain SMS code as the only thing standing between a stranger and your savings, that bank is behind. Most have already moved you to an in-app approval — Secure2u, SecureTAC, and their equivalents under different names.

If you have not activated yours, that is the single highest-value thing in this article.

One device per account is now the default

The policy requires institutions to restrict digital service transactions "by default to one mobile device or secure device per account holder."

The word default is doing real work. You can still register more than one device — a work phone and a personal phone, say — but you have to ask for it explicitly, and the bank has to keep an auditable record of the exception. The bank is no longer allowed to quietly make multi-device the standard setup.

This is aimed squarely at account takeover, where a fraudster registers their own phone to your account and drains it while your phone sits in your pocket showing nothing unusual.

Practical consequence: when you change phones, expect friction. That friction is the feature.

A newly registered phone comes with a cooling-off period

RMiT now requires "appropriate verification and cooling-off period for first time enrolment of digital services or secure device," plus the same treatment for unusual bursts of high-value transactions.

Translated: a phone you registered twenty minutes ago should not be able to move your entire balance. Banks are expected to apply time-based limits that loosen as the device builds a history.

Several banks had already gone there voluntarily. Maybank applied a 12-hour cooling-off period on transfer limit increases from July 2024. OCBC publishes its own cooling-off rules for the same reason.

The logic is simple. When a scammer gets in, the first thing they do is raise the daily transfer limit. The cooling-off window is the gap in which you — or the bank's fraud desk — can still stop it.

If you are ever told to wait twelve hours before a big transfer, that is not the app being broken.

Changing your registered phone number got harder, on purpose

The old process at many institutions was circular: to change your registered number, confirm an OTP sent to your current number. If that number was already compromised, the fraudster simply approved their own change request.

RMiT now requires "robust verification methods" before a new or replacement mobile number is processed — verification through a channel independent of the one being replaced. In practice that means identity re-verification, biometric step-up, or a branch visit for higher-risk changes.

Expect to be asked to show up in person more often than you used to. That is the rule working.

Your code is now tied to the payment, not the session

The most technically interesting change is transaction binding. The policy requires that the authentication code be generated locally by the sender, and be "specific to the confirmed identified beneficiary and amount."

A code approved for RM500 to Account A cannot be reused to push RM50,000 to Account B. This closes the OTP-redirect attack, where a fraudster lets you authenticate normally and then swaps the transaction details underneath you.

This is why your in-app approval screen now shows the recipient name and the exact amount. Read it. Every time. It is the only part of the chain that a machine cannot check for you.

BNM also now requires institutions to offer a cryptographic key-based or passwordless option — passkeys, digital certificates — as an alternative to password login. Passkeys are still thinly adopted in Malaysia, but if your bank offers one, it is the strongest option on the menu.

What to check in your banking app this week

Six things, none of which take long:

  1. Activate in-app secure approval. If you are still receiving SMS codes as your only second factor, fix that first.
  2. Check your registered devices. Remove any phone you no longer own. Most apps bury this under Settings → Security.
  3. Check your registered phone number. If it is an old number you no longer control, change it now, while the process is still calm.
  4. Set your transfer limit to what you actually use. A RM50,000 daily limit on an account you use for groceries is free money for whoever gets in.
  5. Know where the kill switch is. Most Malaysian banks now offer a single control that freezes online banking, ATM and card access at once. Find it before you need it.
  6. Save the scam hotline. The National Scam Response Centre is reachable on 997.

If money has already left, speed matters more than paperwork. Freeze first, report second.

For what happens after a scam — and who you escalate to when the bank's answer is unsatisfying — see our guide on escalating a bank or insurance complaint to FMOS. To check an account number or phone number before you transfer anything to a stranger, Semak Mule is free and takes seconds. And for the broader question of what a Malaysian institution is allowed to do with your data in the first place, PDPA gives you more rights than most people use.

FAQ

Is SMS OTP now illegal in Malaysia?

No. SMS OTP is not banned outright — it is non-compliant as a standalone second factor for digital service transactions at BNM-regulated institutions. A bank may still use SMS for low-risk notifications or as one element in a stronger stack.

Why does my bank only let me use one phone now?

Because RMiT requires device binding to default to one mobile or secure device per account holder. You can request a second device, but the bank must treat it as an explicit, recorded exception rather than the normal setup.

What is a kill switch and where do I find it?

It is a single control that temporarily disables access to your account across channels — online banking, ATM card, and debit or credit card — to stop unauthorised access immediately. Location varies by bank; it is usually inside the app's security settings or available through the bank's hotline.

Are passkeys safer than an in-app OTP?

Passkeys are phishing-resistant by design, because the credential is bound to the specific app or website and never leaves your device. An in-app code that displays the beneficiary and amount is strong, but a passkey removes the possibility of you being tricked into reading a code aloud to someone.

Do these rules cover e-wallets too?

Yes. Approved e-money issuers are within RMiT's scope, alongside banks, insurers, takaful operators, payment system operators and remittance institutions.

Lepaklah Editorial

Researched and edited by the LepakLah team.

More from the team
Read us on Google more often.Pick LepakLah as a preferred source and our stories rank higher in your results.
One letter, most Sundays.No noise. Unsubscribe anytime.