UAE banks tighten access controls for apps and online shopping, with new security measures

Abu Dhabi: Banks in the country have begun tightening security measures for digital banking services by enhancing customer identity verification methods when accessing banking applications, as well as when making online purchases, in order to reduce the risks of electronic fraud and the theft of login data and verification codes.The new procedures include the use of instant notifications that appear on the banking app when transactions or login attempts are made, and the adoption of additional verification methods before completing some transactions. Thus, ensuring the user’s phone is registered with the bank and the banking application has become an essential part of the authentication process.The customer also receives a text message on their phone after each successful login, or when a transaction is requested, so that they can review the transaction and approve or reject it from within the application. Some systems allow the use of a dedicated PIN for authentication, in addition to biometric verification methods, such as facial recognition or fingerprint, depending on the bank, device type, and service.The tightening measures included electronic payment and purchasing operations. After moving from relying on a one-time password (OTP) that arrives via text message, to authentication through the banking application, a secret number must also be placed within the application itself, based on biometric verification methods, such as facial or eye scans, and containing information known only to the customer.In this case, the process is done by sending an immediate notification to the phone number registered with the bank when an electronic purchase is made. The customer then opens the app, reviews the details of the transaction, approves it by entering the PIN, and then returns to the merchant's website or application to complete the payment process.According to the announcements made by these banks, the new procedures aim to reduce the risks of phishing, theft of verification codes, social engineering, and SIM card swapping, and also allow for the completion of authentication using biometric verification methods available on the phone.Other banks have also emphasised the use of diverse digital banking services by adopting a special PIN for transaction authentication, which is created or activated within the application and used alongside or instead of some traditional verification methods.Authentication is linked to the device's biometric features, such as facial recognition or fingerprinting, so that in some transactions, the user does not need to enter a code that arrives via text message, but rather confirms his/her identity through the application and the biometric means registered on the phone.Banks stated on their websites that these measures come alongside their continued notification to customers about transactions made on their accounts.The Central Bank’s regulations require licensed financial institutions to inform customers of transactions that take place on their accounts when they occur, through text messages or email, depending on the available options, while making transaction details available through telephone and internet banking platforms.This shift reflects a trend towards making banking authentication linked to several elements at once, such as the device registered with the bank, the banking application, the PIN, and the customer's biometric characteristics.In certain cases, modern regulatory frameworks in the country require the use of reliable and effective authentication to verify the user’s identity, which must include at least two-factor authentication, such as knowledge, possession, or biometric characteristics, with additional procedures applied in higher-risk cases.Thus, part of the banking sector is gradually moving from a model of relying on a ‘code’ that arrives via text message, to a ‘model’ that relies on the banking application, instant notification, PIN, or biometric authentication, which enhances protection levels during access to digital services and the execution of electronic purchases, and at the same time makes it more difficult for fraudsters to exploit verification codes.4