Back to all articles
Advisories

GCash replaces SMS OTPs with in-app authentication

Sep 1, 2026 · 3 min readBy KasKasan Buddies

GCash is replacing SMS-based OTPs with secure in-app OTPs to make transactions harder for scammers to intercept.

  • The text message OTP you have been using to approve your GCash transactions for years is being retired — and the replacement is significantly harder for scammers to steal. GCash has announced the full rollout of its In-App One-Time Passwords feature, replacing traditional SMS-based OTP authentication by June 22, 2026.
  • Starting that date, users will receive their OTPs through secure push notifications directly inside the GCash app — no more waiting for text messages or switching between apps. Authentication becomes instant with one-tap approval for transactions.
  • Why this change is bigger than it sounds:

GCash is replacing SMS-based OTPs with secure in-app OTPs to make transactions harder for scammers to intercept.

  • The text message OTP you have been using to approve your GCash transactions for years is being retired — and the replacement is significantly harder for scammers to steal. GCash has announced the full rollout of its In-App One-Time Passwords feature, replacing traditional SMS-based OTP authentication by June 22, 2026.
  • Starting that date, users will receive their OTPs through secure push notifications directly inside the GCash app — no more waiting for text messages or switching between apps. Authentication becomes instant with one-tap approval for transactions.
  • Why this change is bigger than it sounds:

The text message OTP you have been using to approve your GCash transactions for years is being retired — and the replacement is significantly harder for scammers to steal. GCash has announced the full rollout of its In-App One-Time Passwords feature, replacing traditional SMS-based OTP authentication by June 22, 2026. 

Starting that date, users will receive their OTPs through secure push notifications directly inside the GCash app — no more waiting for text messages or switching between apps. Authentication becomes instant with one-tap approval for transactions. 

Why this change is bigger than it sounds:

For years, SMS-based OTPs have been targeted by scammers as a means of accessing user accounts. The switch to In-App OTPs is an important step toward addressing these vulnerabilities — by sending OTP requests directly to the user's authenticated GCash app, GCash ensures that only the intended user can receive and use the unique OTPs.

In plain terms: an SMS OTP can be intercepted through SIM swap fraud, phishing pages that harvest codes in real time, or social engineering calls where scammers pretend to be bank representatives. An in-app OTP lives inside your authenticated GCash app — it never travels through the telecom network, and a scammer on a different phone cannot receive it no matter what they try.

GCash Chief Information Security Officer Miguel Geronilla confirmed: "Our upgrade to In-App OTPs is a strategic move to put an end to phishable SMS OTPs. We will shift users to instant, GCash app-verified authentication to increase the security of their daily transactions." 

This is not just a GCash decision — it is the law:

The change comes in line with the Bangko Sentral ng Pilipinas directive under the Anti-Financial Account Scamming Act (AFASA), which requires financial platforms to phase out SMS OTPs by June 2026. GCash's June 22 rollout puts them ahead of the BSP's end-of-June deadline — and every other bank and e-wallet in the Philippines is required to follow the same transition by June 30. 

In-App OTPs are part of GCash's broader Multi-Factor Authentication strategy — a security standard that adds multiple layers of protection. Even if a password or MPIN is compromised, MFA significantly reduces the chances of unauthorized access. GCash has already implemented KYC verification and facial recognition through its Double Safe feature — In-App OTPs build on these existing layers. 

What you need to do before June 22:

Update your GCash app to the latest version immediately — in-app OTPs are delivered through push notifications, which require an updated app to function. If your app is outdated, you may miss OTP notifications and be locked out of transactions.

Enable push notifications for GCash on your phone if you have them disabled. Go to your phone's Settings → Notifications → GCash → Allow notifications. This is non-negotiable for the new system to work.

Make sure your GCash account is fully verified. Unverified accounts may face additional restrictions during the transition.

One critical reminder that does not change:

In-app OTPs are delivered only to your authenticated GCash app — no legitimate GCash process will ever ask you to share your OTP with another person, read it aloud over a call, or enter it on a third-party website. If anyone asks for your OTP in any channel — text, call, Messenger, or otherwise — it is a scam. The upgrade makes the system more secure. Your behavior protects the last mile. 

What this means for the broader digital banking ecosystem:

GCash's June 22 rollout is the most visible implementation of a transition happening across every BSP-licensed bank and e-wallet in the Philippines right now. Maya, GoTyme, BPI, BDO, Metrobank, UnionBank — all are required to replace SMS OTPs with phishing-resistant authentication by June 30, 2026.