WASHINGTON— Banks and credit unions relying heavily on texted one-time passcodes may need to rethink that strategy fast, as fraudsters increasingly exploit SMS-based verification to take over accounts and push through payment fraud, according to new reporting by BankInfoSecurity on a threat-intelligence report from Recorded Future.
The warning lands as real-time payments accelerate and as regulators overseas begin moving more aggressively away from OTP-only models.
BankInfoSecurity reported that financial institutions have long used one-time passcodes, or OTPs, as a primary authentication control, but that safeguard is becoming less reliable as attackers intercept codes and use them in broader fraud campaigns. Recorded Future said the digitization of banking has fueled a rise in social-engineering scams, with criminals impersonating banks and service providers to convince customers to hand over authentication codes in real time. The result, the report said, is that fraud is becoming more structured, repeatable and increasingly “industrialized.”
For banks and credit unions, the most important takeaway is not that multifactor authentication is dead, but that SMS-based OTP is increasingly the weak link. BankInfoSecurity said Recorded Future stopped short of calling OTP obsolete, but warned that more sophisticated and coordinated attacks are now outpacing traditional fraud controls. In practice, that means institutions that still treat texted codes as a frontline defense—especially for higher-risk transactions—may be leaning on a control that criminals have already learned to exploit at scale.
BankInfoSecurity cited Joe Toomey, head of security engineering at Coalition, saying it is time for organizations to reconsider relying on OTP altogether.
“I do not see any good explanation for businesses to use OTP. FIDO is the best and strongest solution that we have,” Toomey said, referring to phishing-resistant, passwordless authentication. He added that OTP-based systems remain “easy targets” and warned that this is not just a big-bank problem: “You don’t have to be a Google or a Cisco to get hacked through OTP… even small businesses can be affected.”
That warning may resonate especially strongly with community banks and credit unions, where customer convenience and legacy digital-banking workflows have kept SMS authentication deeply embedded in login and payment flows. But BankInfoSecurity noted that the growth of real-time payment systems is compressing the time available for fraud teams to detect and stop suspicious activity, making weaknesses in authentication more consequential. Toomey said one-time password session hijacking is now the most prevalent MFA-bypass attack seen among Coalition’s policyholders, even as SIM-swapping and push-fatigue attacks remain common.
Where Will U.S. Expectations Move?
BankInfoSecurity also pointed to a growing international regulatory shift that could foreshadow where U.S. expectations eventually move. India’s central bank in April updated digital-payment authentication rules to move beyond OTP-only verification, requiring stronger multifactor approaches such as device-based authentication and biometrics. Singapore’s banking sector phased out SMS-based OTPs for account logins in late 2024, major banks replacing them with app-based digital tokens, and the United Arab Emirates recently ended OTP verification across banks as well. Regulators in the Philippines and Europe have also been pressing for tighter controls or more limited use.
In the United States, BankInfoSecurity noted that regulators including the FFIEC and CFPB still recognize OTPs as part of multifactor authentication under longstanding guidance, but rising fraud tied to SIM swapping and social engineering could eventually push supervisors away from SMS-heavy models. That matters because many U.S. institutions still meet MFA expectations on paper while remaining exposed in practice if customers can be manipulated into surrendering codes during live scams.
Authentication is becoming a core fraud battlefield, not just an IT checkbox. BankInfoSecurity reported that the industry is moving toward models that combine multiple signals—device identity, behavioral analytics and biometrics—rather than relying on a single shared secret that can be stolen in real time. As Venable’s Jeremy Grant put it, attackers now use “pixel-perfect replica sites” to trick consumers into handing over OTPs, and the short code window is still “long enough for an account takeover.”
Banks and credit unions may not need to rip out OTP overnight, but they do need to start treating SMS-based codes as a vulnerable control that requires stronger layers around it—especially for high-risk logins, new-device enrollment and faster payments. As fraud becomes more organized, more automated and more real-time, institutions that continue to rely too heavily on texted passcodes may find that what once counted as multifactor security is now simply the next opening for fraudsters, BankInfoSecurity reported.
