Back to all articles
Advisories

No more SMS OTPs: Paano na tayo magla-login starting June 25, 2026?

Sep 1, 2026 · 2 min readBy KasKasan Buddies

BSP Circular No. 1213 requires banks to replace SMS and email OTPs for high-risk transactions with stronger authentication methods such as biometrics and device-based verification.

  • Starting today, June 25, 2026, Philippine banks are no longer allowed to use SMS or email OTPs for high-risk transactions. This is not optional — it is the law under BSP Circular No. 1213.
  • Here is what changes, what your bank must now give you, and what you need to do.
  • Why SMS OTPs are gone: SIM swap fraud, phishing pages, and social engineering have made the six-digit text code one of the easiest ways for scammers to access your account. BSP Circular 1213 closes that door permanently for high-risk transactions.

BSP Circular No. 1213 requires banks to replace SMS and email OTPs for high-risk transactions with stronger authentication methods such as biometrics and device-based verification.

  • Starting today, June 25, 2026, Philippine banks are no longer allowed to use SMS or email OTPs for high-risk transactions. This is not optional — it is the law under BSP Circular No. 1213.
  • Here is what changes, what your bank must now give you, and what you need to do.
  • Why SMS OTPs are gone: SIM swap fraud, phishing pages, and social engineering have made the six-digit text code one of the easiest ways for scammers to access your account. BSP Circular 1213 closes that door permanently for high-risk transactions.

Starting today, June 25, 2026, Philippine banks are no longer allowed to use SMS or email OTPs for high-risk transactions. This is not optional — it is the law under BSP Circular No. 1213.

Here is what changes, what your bank must now give you, and what you need to do.

Why SMS OTPs are gone: SIM swap fraud, phishing pages, and social engineering have made the six-digit text code one of the easiest ways for scammers to access your account. BSP Circular 1213 closes that door permanently for high-risk transactions.

What replaces it: Face ID, fingerprint, in-app push approvals, and device-based authentication. Methods that never leave your device and cannot be intercepted by a third party.

4 new tools your bank must now give you:

• Kill Switch — one tap suspends your account and blocks all outgoing transactions the moment you suspect fraud. No calls needed.

• Money Lock — lock a portion of your funds so it cannot be moved digitally without your explicit in-person or strong digital authorization.

• Customizable Transaction Limits — set your own daily caps, transfer limits, and payment restrictions.

• Permission Revocation — view and cut off access that devices, merchants, and third-party apps have to your account.

The rule that matters most: Your bank is now prohibited from sending clickable links or QR codes via SMS, Messenger, or email asking for your login credentials. If you receive one — it is a scam. Full stop.

Your responsibilities under the new law: Activate biometric login. Never share your OTP or PIN with anyone. Never let others use your account. Report suspicious transactions immediately. Under AFASA, lending your account to someone else is a criminal offense.

Do these right now: Update all your banking apps. Enable biometric login. Find your Kill Switch and Money Lock before you need them.

The law is in place. Now make sure your apps are ready.