To combat fraudsters impersonating bankers and withdrawing money without using cards, the Bank of Thailand is preparing to tighten security by requiring two-factor authentication.

The Bank of Thailand is seeking public comments on a draft of Digital Channel Security regulations to enhance the security of "cardless cash withdrawal" services, preventing fraudsters from impersonating users to withdraw money from ATMs. The regulations will also mandate two-factor authentication (MFA) with a cooling-off period when switching devices and eliminate SMS OTP (One-Time Password) processing.
News report fromBank of Thailand (BoT) It is announced that a consultation paper is being sought for the draft "Guidelines for Maintaining Security of Digital Financial Services (Digital Channel Security)" to enhance the security standards of digital financial transactions and combat increasingly sophisticated fraud.
In the past, the Bank of Thailand (BOT) recognized the importance of preventing such threats and therefore issued guidelines on maintaining the security of financial and payment services on mobile devices (Mobile Banking Security) to raise the minimum security standards necessary for mobile banking services of financial institutions, specialized financial institutions, and e-money service providers. This resulted in a significant reduction in fraudulent activities in the form of money-stealing apps in 2567.
However, fraudsters are beginning to shift their targets to non-bank financial service providers, such as impersonating individuals to conduct transactions on banking applications, using credit cards, and withdrawing cash from ATMs via cardless withdrawal services. They are also employing more sophisticated techniques, such as installing malware on victims' computers to intercept passwords and SMS OTPs for internet banking access.
The Bank of Thailand therefore deems it appropriate to issue guidelines on digital channel security to enhance the security of financial services delivered through digital channels, including mobile applications and internet banking, keeping pace with cyber threats and unauthorized payment fraud, and building confidence in the country's financial and payment systems.
Scope of Application
This coverage includes financial institutions, specialized financial institutions (SFIs), e-money providers, credit card and loan providers that offer money transfer services to individuals using accounts with other financial institutions, or provide cash withdrawal services to individual customers via mobile applications and internet banking.
Secure customer authentication measures.
Financial service providers must enhance customer identity verification at critical stages, with measures divided into three areas:
1. Steps for applying for the service or changing a mobile device. Financial service providers must implement rigorous customer identity verification to ensure that applicants are genuine, and promptly notify customers of the application results via out-of-band notifications such as LINE Official Account, telephone, or email.
In addition, measures must be put in place to mitigate customer risk in the initial period after service subscription or device change, such as temporary service restrictions (cooling-off period), limiting transactions to low-risk items, and temporarily setting minimum transaction limits, etc., in order to limit damage in the event of fraudulent service subscription.
2. Transaction Procedures Financial service providers must use independent two-factor authentication (MFA) methods to verify customer identities, covering at least the following steps: money transfers, creating withdrawal requests via mobile applications, receiving funds at ATMs, and increasing transaction limits.
3. Secure authentication factors. Financial service providers must choose secure identity verification methods that are difficult to forge, and constantly review and update their verification methods to keep pace with new security threats.
For "What-you-know" factors, the system must be able to protect against all possible brute-force attacks. For "What-you-have" factors, secure methods such as mobile applications registered with a financial service provider (device binding) or hard/soft tokens are required.
Furthermore, the use of one-time passwords (OTPs) via SMS for transaction verification and what-you-are verification methods such as facial scanning must be discontinued. This requires highly accurate and efficient technology for detecting identity forgery, in accordance with the Bank of Thailand's guidelines on the use of biometric technology in financial services.
Measures to prevent impersonation of service providers.
To prevent fraudsters from impersonating financial service providers, financial service providers must refrain from sending SMS and email messages with attached links, and have procedures in place to handle and respond to any fraudulent applications or websites.
Security measures for services provided via mobile application.
Financial service providers that offer services through mobile applications must maintain the security of their mobile applications and control the environment on the mobile devices where the applications are installed to ensure that the service provider's applications function securely. This includes measures such as preventing application modifications and protecting against remote application access.
This includes high-value transactions, which require identity verification using facial recognition technology, along with additional biometric detection for forgery, such as facial scanning for transfers exceeding 50,000 baht per transaction or 200,000 baht per day, etc.
The Bank of Thailand is seeking comments and suggestions on the draft Digital Channel Security guidelines from financial institutions, businesses, and the general public from July 23 to August 24, 2569, to be used in the consideration and subsequent issuance of the regulations.
refer : bot.or.th































