India, UAE to Ban SMS OTP-Only Authentication From 2026
SMS one-time passwords have long been used to authenticate financial transactions but are vulnerable to interception through phishing, SIM hijacking and social engineering. The Reserve Bank of India and the Central Bank of the UAE are therefore raising authentication standards, requiring financial institutions to adopt phishing-resistant biometrics, FIDO or passkeys to reduce the risk of account takeovers.
The new rules in India and the UAE will take effect in April 2026. Banks will no longer be allowed to use SMS OTPs as the sole means of authenticating financial transactions and must add biometrics or strong authentication compliant with FIDO standards. The rules do not set transaction-value thresholds, instead strengthening authentication across the board in a move expected to accelerate the phaseout of legacy systems that rely solely on SMS verification.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.