বাংলা E-Paper 📍 Dhaka 📅 Monday | 31 August 2026, 16 Bhadro 1433 PID registration number 06
HEADLINE
Advertisement

OTP fraudsters increasingly adopt sophisticated tactics

Published : Monday, 31 August, 2026 at 12:00 AM
Mizanur Rahman
As the use of digital transactions, mobile financial services (MFS), internet banking and online services continues to grow rapidly, fraud involving one-time passwords (OTPs) is also becoming an increasing concern in Bangladesh.

While fraudsters once relied mainly on phone calls to directly ask users for OTPs, their methods have now become far more sophisticated and technology-driven. They are using phishing links, fake websites, fraudulent customer-care services, malicious apps, malware, remote-access tools and social engineering to obtain users’ authentication information.

Fraudsters are contacting customers by posing as representatives of banks, bKash, Nagad, Rocket, mobile operators and various government and private organisations. In some cases, victims are told that their accounts will be closed, their KYC information needs to be updated, a transaction has been made in their name, or that they have won a prize.

By creating fear, anxiety or temptation, fraudsters eventually persuade victims to disclose OTPs, PINs and other confidential information.

The National Cyber Security Agency (NCSA), in its awareness guidelines, has also warned users about the theft of OTPs, banking information and personal data through phishing, fraudulent phone calls and malicious links.

Chief Consultant of the Meet Expert and Cyber Crime Awareness Foundation Adviser Syed Zahid Hossain said that OTP fraud is no longer limited to conventional phone calls. 

According to him, fraudsters are using social media, phishing websites, fake customer-care numbers, SMS messages and the identities of trusted organisations to gain customers’ confidence.

A total of 81,423 incidents of fraud across the country’s payment ecosystem involving MFS, cheque and card-based transactions caused losses of Tk 92.60 crore in 2025

In many cases, he said, fraudsters first collect some personal information about a potential victim. They then use that information to call the person while posing as an official of the relevant bank, MFS provider or service organisation.

As a result, the fraud appears more credible to the victim.

Experts say an OTP itself is not necessarily a weak security measure. Rather, it becomes a major tool for fraud when users are deceived into revealing the code to scammers.

The potential financial losses from such fraud are increasing alongside the expansion of digital financial transactions in the country.

According to Bangladesh Bank data, various types of fraud across the country’s payment ecosystem caused losses of Tk 92.60 crore in 2025. During the year, a total of 81,423 incidents of fraud were reported involving MFS, cheque and card-based transactions.

Of the total losses, around Tk 82.72 crore could not be recovered. This means only 10.7 per cent of the total amount lost was recovered.

However, these figures do not directly represent the number of OTP fraud cases. Rather, they indicate the broader scale of risks associated with digital financial fraud in Bangladesh.

Meanwhile, the Bangladesh Financial Intelligence Unit (BFIU) received a record 30,199 Suspicious Transaction Reports (STRs) and Suspicious Activity Reports (SARs) during the 2024-25 fiscal year, 74 per cent higher than the previous fiscal year.

Of the total reports, 20,524 were STRs and 9,675 were SARs. Surveillance has been strengthened over various suspicious activities, including online gambling, digital hundi, cryptocurrency and foreign-exchange transactions.

The risk of OTP theft is no longer limited to phone calls or phishing links.

In July 2026, Bangladesh Government’s BGD e-GOV CIRT issued an alert about GoldFactory/GoldPickaxe, a mobile banking trojan. Such malware can steal facial biometric data, identity documents and authentication information, and may target e-KYC and banking authentication systems.

Installing APK files from unknown sources or untrusted applications and keeping unnecessary Accessibility and Notification Access permissions enabled can also expose users to significant risks.

According to a warning issued by Chattogram District Police, malware can abuse such permissions to collect OTPs, passwords and private messages.
Fraudsters are also attempting to gain control of victims’ mobile devices by using remote-access applications.

As a result, simply keeping OTPs confidential will not be enough to prevent future fraud. The security of mobile devices, app permissions, e-KYC, biometric authentication and technological capabilities for detecting suspicious transactions all need to be strengthened simultaneously.

Experts believe that OTP fraud cannot be stopped through customer awareness alone. An integrated system involving banks, MFS providers, mobile operators, regulatory agencies and law-enforcement authorities needs to be developed.

Artificial intelligence and behavioural analytics can be used to immediately flag unusual activities, such as a sudden transfer of a large amount of money compared with a customer’s normal transaction pattern, a login from a new device or a transaction originating from an unusual location.

At the same time, authorities and service providers need to take prompt action to identify and shut down fake customer-care numbers, phishing websites and fraudulent SMS campaigns.

Rapid action after a complaint is received is also crucial to tracing the flow of stolen money and preventing further losses.

According to Syed Zahid Hossain, investigations should consider every possible avenue, including the sharing of OTPs, SIM cloning, changes to mobile numbers and possible misuse of an organisation’s internal systems.

The growing sophistication of OTP fraud therefore underscores the need for a multi-layered security approach-combining user awareness with stronger technological safeguards, real-time monitoring, rapid response mechanisms and closer coordination among financial institutions, telecom operators, regulators and law-enforcement agencies.



Loading...
Loading...
Editor : Iqbal Sobhan Chowdhury
Published by the Editor on behalf of the Observer Ltd. from Globe Printers, 24/A, New Eskaton Road, Ramna, Dhaka.
Editorial, News and Commercial Offices : Aziz Bhaban (2nd floor), 93, Motijheel C/A, Dhaka-1000.

Phone: PABX- 41053001-06; Advertisement: 41053012; 01793317829, 01550707291, E-mail: [email protected], ‍[email protected] Online: email: [email protected] 41053014; 01550707297 Advertisement: 01550707296
🔝
Advertisement