
The most important step in addressing cybersecurity risks is personal vigilance. Under no circumstances should anyone share an OTP, PIN, password or verification code with another person. Even if someone claims to be an official of a bank or mobile financial service (MFS) provider, customers should never trust anyone who asks for such information over the phone.
Users should also avoid clicking on unfamiliar links, installing APK files from unknown sources or granting unnecessary permissions to apps. For any bank- or MFS-related assistance, customers should not call numbers provided over the phone. Instead, they should obtain the contact number from the institution’s official app or website and communicate through the verified channel.
If a customer accidentally shares an OTP or other sensitive information, or if money is transferred from an account without authorisation, they should immediately contact the concerned bank or MFS provider without delay. Where necessary, complaints should also be lodged with law enforcement agencies or the National Cyber Security Agency (NCSA). The NCSA has introduced a 333 (8) helpline and an official WhatsApp service at 01308332592 for cybersecurity-related complaints.
With the expansion of the digital economy, OTPs have become an important layer of financial security. However, as fraudsters are rapidly changing their tactics, an OTP alone can no longer be considered the final line of defence. Alongside customer awareness, banks and MFS providers must strengthen their technological capabilities, enhance monitoring, ensure rapid complaint resolution and take effective measures against fraudsters in coordination with law enforcement agencies.
A combination of user awareness, technological safeguards and swift legal action can provide an effective defence against the growing threat of OTP fraud.