বাংলা E-Paper 📍 Dhaka 📅 Monday | 31 August 2026, 16 Bhadro 1433 PID registration number 06
HEADLINE
Advertisement

Stronger surveillance needed in the wake of rising

OTP fraud

Published : Monday, 31 August, 2026 at 12:00 AM
Mizanur Rahman
Syeed Zahid Hossain is the Chief Consultant of Meet Expert and an adviser to the Cyber Crime Awareness Foundation. He works on cybersecurity, cybercrime prevention and digital security awareness in Bangladesh. He recently spoke to the Daily Observer in an interview on the growing threat of OTP fraud and digital financial crimes.

He said: “One-Time Password (OTP), designed to provide an additional layer of security for digital transactions, is increasingly being exploited by fraudsters in Bangladesh. While lack of awareness among users remains a major factor, stronger monitoring; improved institutional security and effective legal action are urgently needed.”

An OTP is a computer-generated, one-time password used alongside a regular password to verify a user's identity or complete a transaction. It usually remains valid for only a short period-between one and five minutes, depending on the institution-and is generally sent through SMS, email or other channels.

The most common OTP fraud involves social engineering. After an OTP reaches a user's phone, fraudsters call and claim that the account has a problem, will be closed or needs verification. They then ask for the OTP. Unsuspecting users share the code, allowing fraudsters to access accounts or complete transactions.

According to Zahid, users generally cannot be defrauded through an OTP if they do not share the code with anyone. However, some recent incidents indicate that OTP-related fraud may involve more sophisticated methods.

A case involving Standard Chartered Bank, for example, reportedly involved a customer who claimed that he neither shared his OTP with anyone nor received a fraudulent phone call. Nevertheless, an OTP arrived on his mobile phone and a transaction was subsequently made from his account.

Such cases raise questions about the security of internal systems. Zahid said financial institutions should investigate whether people with access to internal systems could have altered customers' registered mobile numbers. If a customer's original number is replaced in the system with another number, OTPs could potentially be sent elsewhere.

Other possibilities, including SIM cloning, should also be investigated. The potential involvement of dishonest bank officials, employees or IT personnel cannot be ruled out where evidence points in that direction.

People in rural areas, particularly those with limited education or knowledge of digital security, are considered more vulnerable because many do not clearly understand what an OTP is

Small frauds becoming a major threat: Zahid said OTP fraud cannot be stopped through awareness campaigns alone. Law enforcement agencies need greater capacity, while banks and other financial service providers must strengthen security and accountability.

A major challenge is that fraudsters often deliberately steal relatively small amounts. If Tk20,000 is stolen from a financially well-off customer, the victim may decide that visiting a police station, filing a case, cooperating with an investigation and possibly attending court is not worth the time and effort.

As a result, many victims simply ignore the incident.

Fraudsters can exploit this attitude by taking Tk10,000, Tk20,000 or Tk30,000 from thousands of people instead of stealing a large amount from a single victim. Individually, the losses may appear small, but collectively they can become substantial.

The same problem exists in mobile financial services (MFS). A person losing Tk10,000 through fraud may be reluctant to pursue a lengthy legal process. This creates a vicious cycle involving inadequate reporting, weak accountability and, in some cases, alleged insider involvement.

Rural users particularly vulnerable: The expert said people in rural areas, particularly those with limited education or knowledge of digital security, are considered more vulnerable because many do not clearly understand what an OTP is, why it is sent or why it should never be shared.

The Zahid stressed that the issue applies to bKash, Nagad and all other Mobile Financial Services (MFS).

When a customer reports fraud, an MFS provider should have transaction-related information, including the account to which money was transferred, where it was cashed out and which agent was involved.

Authorities and service providers should use such information to trace fraudulent transactions. If the same agent repeatedly handles suspicious cash-outs, the provider should investigate and take appropriate action.

Zahid said stronger pressure and surveillance from the state and law enforcement agencies are needed, while visible action against agents repeatedly linked to fraudulent transactions appears insufficient.

High MFS charges discourage digital transactions: Zahid also raised concerns over the cost of MFS transactions. For example, transferring Tk1,000 through bKash can involve a Tk10 charge, while cash withdrawal may cost around 1.8 percent or the applicable rate. Such charges place a greater burden on low-income people who frequently transfer small amounts.

Bangladesh Bank, the Finance Ministry and other authorities should therefore review MFS charges and policies so that digital transactions remain financially attractive.

Bangla QR needs a user-friendly policy: Zahid also questioned whether the current cost structure could limit the effectiveness of Bangla QR.

He said similar QR-based payment systems in India, China and Singapore generally do not directly charge customers; instead, charges are imposed on merchants.

If merchants face high charges, they may be reluctant to use Bangla QR. Zahid compared this with POS payments, where some merchants impose two or three percent additional charges on customers despite already paying service charges to banks.

For example, if a customer buys a Tk1 lakh refrigerator and is charged an additional two percent for digital payment, the customer has to pay Tk2,000 extra.

 Since cash payment does not carry the same additional charge, consumers may prefer withdrawing money from ATMs and paying in cash.

Zahid said similar problems exist with Bangla QR. He cited a recent experience at a pharmacy where he was offered a discount but was told that the discount would not apply if he paid through Bangla QR.

Such policies, he argued, could discourage rather than encourage digital payments.

OTP risk comparatively lower with Bangla QR: According to Zahid, OTP-related fraud is comparatively less likely with Bangla QR because the user's own device generally needs to be present.

When a customer uses a mobile banking application to make a Bangla QR payment, a separate OTP generally does not arrive; authentication takes place through the banking application.

However, the risk is not completely absent if criminals obtain the necessary information.

The increasing use of biometric security, including fingerprint and face recognition, can provide an additional layer of protection. Combining biometric authentication with secondary passwords can further reduce risks.

Awareness alone not enough: Zahid's key message to users is straightforward: never share an OTP with anyone. Banks, MFS providers or legitimate institutions should not call customers and ask for their OTP. 

But responsibility cannot rest with customers alone.


Loading...
Loading...
Editor : Iqbal Sobhan Chowdhury
Published by the Editor on behalf of the Observer Ltd. from Globe Printers, 24/A, New Eskaton Road, Ramna, Dhaka.
Editorial, News and Commercial Offices : Aziz Bhaban (2nd floor), 93, Motijheel C/A, Dhaka-1000.

Phone: PABX- 41053001-06; Advertisement: 41053012; 01793317829, 01550707291, E-mail: [email protected], ‍[email protected] Online: email: [email protected] 41053014; 01550707297 Advertisement: 01550707296
🔝
Advertisement