UAE Central Bank Orders Full Refunds for Victims of OTP SMS Fraud, Demands App-Based Biometric Protection
UAE Central Bank mandates banks and insurers protect customers from OTP SMS fraud, require app-based biometric authentication and full refunds for affected clients.
The UAE Central Bank has instructed licensed financial institutions to provide comprehensive protection against fraud involving one-time passwords (OTP), including biometric verification and encrypted app logins.
The directive requires banks and insurers to investigate reports promptly and, where fraud is proven to have occurred solely through an OTP shared via SMS, to refund the full amount to the customer.
Institutions are also being urged to move customers to in-app authentication methods that use fingerprint or face recognition to harden security on digital banking channels.
Central Bank ruling on liability for SMS OTP fraud
The Central Bank’s disclosure makes clear that liability rests with the financial institution when a fraudulent transaction is completed using an OTP that was transmitted by SMS or text message.
After a customer reports suspected fraud, the bank must verify the claim and provide a full reimbursement if the investigation confirms the operation was enabled only by an SMS OTP.
The measure is explicitly limited to fraud cases that involved sharing or interception of the verification code sent via text, and does not automatically cover other forms of account compromise.
Phased removal of SMS and email OTPs, with a July 25, 2025 transition
The regulator began phasing out OTPs sent by SMS or email from July 25, 2025, replacing them with more advanced, app-based authentication mechanisms.
Under the new approach, authentication takes place within the bank’s official mobile application, using biometric checks such as fingerprint or facial recognition or the app’s private passcode.
The Central Bank framed the change as part of an overall digital infrastructure upgrade to bring UAE banking practices in line with international information security standards.
Bank and insurer technical and customer obligations
Banks and insurance companies are required to implement encrypted “app login” flows and make biometric options available to their customers as primary authentication methods.
Customers are being asked to update their banking applications, enable in-app authentication, and avoid approving any transaction unless merchant details and amounts are fully clear.
The regulator also advised customers to adjust spending limits and security settings where available to reduce exposure to fraud while institutions complete the migration.
Immediate customer actions after suspected fraud
If a customer suspects fraudulent activity, the Central Bank instructs them to notify their financial institution immediately and request a freeze on the card or account through official channels.
The guidance recommends obtaining a reference number for any complaint, changing authentication settings, and modifying transaction limits to prevent further unauthorized activity.
These steps are intended to limit losses while the institution conducts its verification and remediation processes.
Dispute handling and recourse through the banking and insurance dispute unit
When a bank or insurer refuses a fraud complaint, the institution must provide the customer with a clear written explanation for the rejection.
Customers who remain dissatisfied after receiving that explanation may escalate their case to the Banking and Insurance Dispute Resolution Unit (SANDK), which handles unresolved disputes between consumers and licensed financial firms.
The Central Bank emphasized that customer security in the UAE is a primary responsibility and one of its top priorities.
Expected impact on fraud reduction and digital trust
Regulators and industry stakeholders expect the shift away from SMS OTPs to reduce incidents of account takeover linked to intercepted or socially engineered verification codes.
Adopting biometric and in-app authentication also aims to streamline the user experience while raising the bar for attackers seeking to exploit simpler SMS-based systems.
Banks will be judged on both the robustness of technical controls they deploy and the speed and transparency of their response when customers report fraud.
The Central Bank’s guidance represents a clear regulatory signal that legacy SMS OTPs are no longer an acceptable sole line of defence, and that institutions must both prevent fraud and make customers whole when SMS-only authentication is exploited.