
We Keep Hardening the Front Door. It Keeps Being Opened From Inside.
12.08.2026
On 31 March 2026, SMS and email one-time passwords (OTP) stopped being acceptable as the sole authentication method for financial transactions or account provisioning in the UAE. For 3D Secure transactions, they are prohibited even as a second factor.
That deadline came from CBUAE Notice 2025/3057, which required stronger methods such as biometrics, FIDO2 passkeys, device-bound keys, in-app approval, or hardware and software tokens. It also made institutions liable for reported fraud on 3D Secure transactions authenticated with SMS OTP.
No regulator anywhere had gone that far before. The UAE is the first country in the world to mandate it, and it was the right call. This is not the first time the region moved first. SAMA mandated an account verification service before a beneficiary can be added, across the instant payment system and RTGS, in a circular effective May 2023. The EU's equivalent verification-of-payee obligation applied from October 2025, two and a half years later. The CBUAE separately requires the payee name to be displayed before a transfer is confirmed, with payee name verification in place for instant payments.
The weakness was never only the one-time password: it was the channels carrying it. An SMS code can be lifted through SIM swap or interception, while an email code may sit behind a compromised mailbox. Even where the channel holds, a readable code remains shareable, which is why warnings not to share it comes often along with it.
None of the technology was new. Soft tokens and in-app approval have been in this market since 2017, when Emirates NBD launched Smart Pass, mandatory there from 2021. Others moved at their own pace, many still switching through 2025.
That spread is the interesting part. The mandate did not bring app-based approval to the UAE. It closed the residual channels, the places SMS quietly stayed alive alongside the strong control:
That matters for what follows, because a control that exists is not the same as a control with no way around it.
Here is the part that gets less attention. Social engineering unfortunately does not stop working when you close one door. It relocates to the door still open.
Social-engineering losses in retail banking end in one of two payment outcomes.
FIGURE 1: Stronger authentication and device intelligence dramatically reduces the yield from account takeover, but it does not test whether a customer's payment intent is genuine.
The first is account takeover (ATO). The fraudster gets into the account and moves the money themselves. A lot of what the industry has built over the last fifteen years attacks this: device intelligence, behavioral biometrics, session analytics, step-up authentication, and now the stronger authentication methods that 3057 requires.
The second is authorized push payment (APP) fraud. The fraudster never touches the account. The customer is deceived and manipulated into making the payment personally, on their own device, through their own genuine banking session.
Account takeover is gradually getting materially harder. It is not solved, and anyone selling you that is overreaching. Remote access tooling still degrades device signals, and adversary-in-the-middle techniques are advancing faster than many detection stacks. But harder and more expensive is enough to change the economics. When the cost of one route rises while the payoff stays constant, fraudsters have an incentive to shift toward another. Whether this door stays shut is a separate question, and one I suspect we will revisit in the future.
What does not happen is the attacker giving up. Social engineering itself shows no sign of losing its edge: the FBI's Internet Crime Complaint Center recorded reported phishing losses growing 208% in 2025 while complaint volume remained broadly flat, moving from about 193,000 to 192,000. Complaints are not the same as unique victims or attempts, so the figures cannot establish a per-victim extraction rate. They do show that a familiar social-engineering category continued to produce sharply higher reported losses without a corresponding rise in complaint volume.
So the capability remains effective. Only the exit changes, toward the route where identity controls offer the least protection.
You do not have to take the displacement argument on faith when another market has already produced a result consistent with it.
The UK offers a useful comparison. It hardened authentication under strong customer authentication rules, then made reimbursement mandatory for in-scope APP fraud in October 2024. UK Finance's Annual Fraud Report published in 2026 shows what came out the other side.
The reimbursement rule explains the pressure. It converts an in-scope APP loss from the customer's misfortune into a line on the bank's profit and loss. Once the institution pays, prevention becomes a cost decision, and cost decisions get budget. The 50/50 split between sending and receiving institutions creates direct financial pressure on the firm that opened the mule account too.
FIGURE 2: UK Finance data for calendar 2025 shows remote-banking losses (ATO) falling as recorded cases rose, while APP losses and cases both increased.
The argument lives in the gap between the first two remote-banking measures. More recorded cases. Far less money. That is consistent with a control environment reducing fraud yield even when it does not eliminate activity. Web losses specifically nearly halved, down 46% to an all-time low, on effectively flat case volume.
Now the other door. Strip out cards, and the picture is stark: in UK non-card fraud, APP is now more than five times the size of remote banking fraud and moving in the opposite direction.
There is an apparent contradiction here, and it needs clarification. On 1 July 2026 the PSR published an independent evaluation of the reimbursement regime's first year: the policy cut APP losses by around GBP 73 million annually, avoided roughly 35,000 scams, and reduced APP fraud over Faster Payments by about 21%.
So the policy worked, while UK Finance's broader APP series still rose 19%. The measures are not directly comparable: the PSR evaluation uses in-scope Faster Payments data by transaction date and estimates a counterfactual, while UK Finance reports broader APP losses by the date a claim closes. The safe conclusion is that the policy reduced in-scope losses while broader recorded APP losses still rose.
That is the sobering part. In a country with strong authentication rules and a reimbursement regime that independent evaluation says works, broader recorded APP losses still grew by a fifth. The comparison does not prove that stronger authentication caused the increase. The claim is narrower: takeover yield can fall sharply while authorized fraud continues to grow.
Notice 3057 places the UAE among the early jurisdictions moving beyond SMS OTP, with a firm compliance deadline attached. But the UAE does not yet have an APP loss-allocation regime comparable to Britain's. The incentive for displacement arrives before the same commercial pressure to prevent it - for now, at least.
The GCC did not tiptoe into real-time payments. It sprinted. SAMA launched Sarie through an event organized by Saudi Payments in February 2021, and Al Etihad Payments, a CBUAE subsidiary, launched Aani in October 2023. Add the Digital Dirham, which I wrote about here before its first live government transaction and while its public rollout was still being prepared, and you get a payment landscape increasingly built around instant, traceable, account-to-account movement.
Those rails are the open door: excellent infrastructure that also moves money in seconds, sharply reducing the window for recall and recovery.
These are modeled estimates rather than official loss statistics. ACI Worldwide's Scamscope, with GlobalData, estimated UAE APP losses at USD 8.3 million in 2023 and projected USD 30.3 million by 2028, a 26.9% compound annual growth rate. It projected the real-time-payment share to grow from USD 7.1 million to USD 26.8 million over the same period, reaching close to 90% of the total.
The victim side is worse than the modeled loss numbers suggest. The Global Anti-Scam Alliance and BioCatch surveyed around 2,000 UAE residents for their 2024 State of Scams report. The report estimated that more than 40,000 residents fell victim; 27% of respondents said they lost money, at an average of USD 2,194, and only 9% recovered in full. Almost 60% of victims requested reimbursement and received nothing.
Hold those two together. The modeled loss category is forecast to grow at nearly 27% a year, while full recovery remains rare. That keeps the strongest return in prevention.
The wider picture reads the same way. In a 2026 BioCatch survey, 58% of UAE banking leaders reported increasing fraud losses, while 62% estimated that their institutions lost more than USD 5 million annually. The survey is vendor-sponsored perception data rather than audited industry loss data, but it supports the narrower conclusion that attack pressure is not perceived to be easing while the controls change.
The fraud detection most institutions in this region have spent the last few years building is very good at a question that authorized push payment fraud does not ask.
The identity-focused ATO stack establishes whose hands are on the device. Device intelligence, behavioral biometrics and session analytics are strong at distinguishing the account holder from a stranger. But a clean identity answer is insufficient for APP.
In many APP scams, the customer and device are genuine and the physical motor signature remains theirs. Yet session behavior can still expose the context: hesitation, abnormal navigation, an active call, screen sharing or remote access. Notice 3057 itself requires controls for several of these conditions. Behavioral analytics are not irrelevant; they must be designed to detect coaching and duress rather than only an imposter.
The question APP fraud asks is different: does this customer understand what they are actually authorizing?
Many conventional fraud estates do not ask that question directly. The industry built for the threat it had, and the threat is shifting.
This has a practical consequence worth stating plainly. If a green behavioral or device result feeds rule suppression, whitelisting or a score as evidence of legitimacy rather than evidence of identity, that assumption is now working against you. It will keep answering yes on precisely the transactions you most need to question.
The obvious control against authorized push payment fraud is to check who is actually receiving the money, and the region did not wait to be told. It also landed on a different design from Europe, and for this market it is the better one.
Resolve and display takes an IBAN or an alias and shows the payer the registered account name. Match takes a name the payer typed and compares it against the account holder name, returning a match, a close match, or no match. The GCC schemes lean toward the first. The EU obligation that applied from October 2025 is the second.
Matching is more tractable where names are stable Latin-script strings with predictable structure. Now run it across a GCC book.
The result is not simply more failed checks. It is that the gray area in the middle can become very large.
That gray area is where the harm lives, and no single threshold eliminates the trade-off:
FIGURE 3: Why name matching is difficult in this market. Tight and loose thresholds create opposite risks.
Anyone who has spent time on fuzzy matching in sanctions screening knows this shape of problem: the tuning is the entire product, the thresholds are market-specific, and a threshold imported from another market is a poor starting point.
So the regional model resolves rather than matches. You enter an IBAN or alias, the system returns the registered name, and you decide whether it is who you meant. There is no algorithmic matching threshold to tune. Given the naming reality above, that is the right call, and SAMA arriving at it two years before Europe was not luck.
But notice where the decision now sits. The bank has resolved the name accurately and handed the judgment to the customer. Often not even the whole name, since parts are commonly masked for privacy, so the judgment is made on a fragment.
And though it is a material help, the truth is - it does not stop authorized push payment fraud.
A displayed name is only a control if the customer questions it, and a coached customer may not. The fraudster may already have explained that the transfer will show under a holding company, a relative's name, or an unfamiliar business. The display is accurate. The payment still goes. The check can end up lending the bank's credibility to the fraudster's account name.
There is a second-order effect of the authentication mandate that deserves attention.
Financial inclusion in this region is not a slogan. Wage protection programs, wallet-based payroll and low-friction onboarding have brought large populations of laborers and domestic workers into digital finance, many operating in a second or third language, many using formal banking for the first time, and many sending most of what they earn abroad every month to people who depend on it.
That is an unambiguous social good. It can also create disproportionate exposure where customers have less familiarity with what a bank will ask and less capacity to absorb a loss.
Now consider what replaces the SMS code. Many device-based methods assume a reasonably current smartphone, a stable device relationship, and a user comfortable with what they are approving. Where those assumptions hold, protection improves considerably. Where they hold weakly, the benefit may be smaller while coached-payment risk remains.
So the hardening is real, and its benefit may not be evenly distributed. Some customers who benefit least from the new controls may also be especially exposed to the fraud those controls do not address.
The reimbursement question is likely to arrive here in some form. SAMA's Counter-Fraud Framework requires a remediation process and identifies restoring a victim's prior position, including refunding a scam payment, among the corrective actions an institution may take. That is not the UK's prescriptive regime, with its cap, timeline, inter-institution split and dispute path. If comparable machinery is built here, institutions already measuring authorized fraud will be better placed than those discovering it.
Four things worth putting to your own environment, none needing a new platform or a regulatory mandate to start:
Separate authorized from unauthorized loss in your own numbers. In many institutions the two sit in one bucket, or authorized losses are not recorded as fraud at all because the customer approved them. If you cannot see the two categories independently, you cannot see displacement happening.
Audit where a clean device or behavioral result is feeding a legitimacy decision. Find every rule and score treating a green result as evidence the payment is fine rather than evidence the person is who they claim. That inheritance was less dangerous when the dominant threat was account takeover. It is dangerous when the genuine customer is being coached.
Find out what your customers actually do with the beneficiary name you show them. The name is resolved correctly, so the control is only as good as the attention it gets. How much of it is displayed, how long it sits on screen, and whether anyone has ever tested whether a customer notices a name they did not expect. That is a usability question with a fraud loss attached to it.
Shift detection weight toward the beneficiary and the outbound leg. Newly created beneficiaries, first-time payees receiving atypical amounts, and accounts showing rapid onward movement carry information that transaction attributes alone do not. This deserves an article of its own, and it will get one.
The last one is the hardest and most important: put friction at the authorization moment rather than the authentication moment. A coached customer can pass even strong authentication because nothing about their identity is false. A cooling-off period on a first payment to a new beneficiary, or a plain-language restatement of where the money is going, targets the point where the deception lands.
Closing the SMS door was the right decision and the region should get credit for making it. The mistake would be reading a fall in account takeover as a fall in fraud.
