Verihubs Logo
Home Blog Account Takeover Fraud in the Philippines: Detection Signals
13 min read KYC Published on August 17, 2026

Account Takeover Fraud in the Philippines: Detection Signals

Account Takeover Fraud in the Philippines: Detection Signals

Account takeover is fraud committed against an account that already exists and already passed KYC. The attacker does not create a fake identity, they seize a real customer’s access.

Philippine regulation changed decisively here: BSP Circular No. 1213 required institutions to move away from interceptable authentication such as SMS one-time passwords for high-risk transactions by 30 June 2026.

OTPs retain one permitted use, confirming ownership of a registered mobile number, but no longer authorise transactions.

What Is Account Takeover (ATO)?

Account takeover is unauthorised control of a legitimate customer’s account. The account is genuine, the customer is real, and the relationship has been running normally. What changes is who is operating it.

The attacker’s goal is access rather than identity. Once inside, they move funds, add payees, change registered contact details, or use the account’s standing to reach further. Because everything is done through a verified customer’s credentials, the activity carries that customer’s history and reputation with it.

That is precisely what makes ATO expensive to detect. Nothing about the account is fraudulent. The fraud is in the session.

How ATO Differs from Identity Fraud at Onboarding

Identity fraud at onboardingAccount takeover
When it happensBefore the account existsAfter KYC has passed
What is fakeThe identity or the documentsNothing; only the operator is wrong
Primary defenceDocument verification, liveness, deduplicationAuthentication, device and behaviour signals
Who bears the lossUsually the institutionThe customer, until liability is resolved
Detection windowOne moment, at applicationContinuous, across the account’s life

The two are complementary rather than alternative, and controls built for one do not cover the other. Our guide to identity fraud covers the onboarding side. A firm with excellent onboarding verification and weak session controls has moved its exposure rather than reduced it.

Common ATO Attack Methods in the Philippines

MethodHow it works
SIM swapThe victim’s number is ported to an attacker-controlled SIM, redirecting OTPs
Phishing and smishingFake bank or telco pages and messages harvest credentials and codes in real time
VishingA caller impersonating the bank persuades the customer to read a code aloud
Remote access and screen sharingThe attacker watches the customer’s screen and uses the code as it arrives
Credential stuffingPasswords leaked elsewhere are replayed against financial accounts
MalwareCompromised devices intercept or forward authentication messages

A pattern runs through most of these. The attack does not break the authentication factor. It relocates it, by moving the channel, the device, or the person’s understanding of what they are approving.

Why the SMS OTP Era Ended on 30 June 2026

SMS one-time passwords carried Philippine digital banking for a decade, and their structural weakness was always the same: the factor has to leave the institution’s systems and travel across a telecommunications network the institution does not control.

BSP Circular No. 1213 addressed that directly, requiring institutions to transition away from interceptable authentication mechanisms for financial transactions and high-risk activities. According to Authsignal’s analysis of the circular (March 2026), the coverage extends well beyond login to include adding a new payee, updating registered contact details, and initiating large transfers. Device registrations and credential changes fall inside it too.

The deadline was 30 June 2026, and BSP Deputy Governor Elmore Capule confirmed publicly that the central bank was not extending it.

BSP Circular 1213 phasing out SMS OTPs for high-risk transactions by 30 June 2026 in favour of server-side biometrics and passkeys

OTPs were not abolished outright. The BSP clarified that they retain one permitted use: confirming the existence or ownership of a registered mobile number. What they may no longer do is authorise a transaction.

Two further obligations sit alongside the phase-out. Institutions handling complex electronic services, or with average monthly transaction volumes above PHP 75 million, are required to operate real-time fraud detection covering behavioural analysis. And where server-side biometrics are adopted, Biometric Update reported (May 2026) that the BSP set minimum safeguards including encrypting biometric templates, avoiding storage of raw images, restricting access, enforcing strong monitoring, and ensuring secure retention and disposal.

One design constraint deserves attention because it is easy to fail. The BSP guidelines emphasise that replacement authentication must remain inclusive and accessible, explicitly naming elderly users with worn or damaged fingerprints and persons with disabilities. A biometric rollout that locks out those users has not achieved compliance, it has traded one problem for another.

Detection Signals: Device, Behaviour, and Velocity

Authentication decides who may act. Detection notices when something looks wrong anyway, and the useful signals cluster in three groups.

Device and Network

A session from an unrecognised device, a new device registered immediately before a large transfer, an implausible location change, or many accounts operating from the same device.

Behaviour

Interaction patterns that differ from the customer’s history: navigation speed, typing rhythm, session timing. Automated activity often shows a regularity that human use does not.

Velocity and Sequence

The sequence matters more than any single event. A contact-detail change followed by a new payee followed by a maximum transfer, all inside one session, is a recognisable takeover shape even where each step is individually permitted.

Worth being direct about scope: device fingerprinting and behavioural analytics are their own product category, and Verihubs does not supply them. What Verihubs contributes to this problem sits at the identity layer, covered below.

Step-Up Authentication and Biometric Re-Verification

The design principle that survived the OTP phase-out is proportionality. Not every action needs the same assurance, and the friction should scale with what is at stake.

Low-risk actions such as balance inquiries can proceed on standard session authentication. High-risk actions, which the BSP defines to include third-party transfers, device registrations, and credential changes, require stronger assurance.

The strongest available step-up is confirming that the person operating the session is the person who opened the account. That is a biometric comparison against the identity established at onboarding, and it is the one factor an attacker cannot obtain through a SIM swap, a phishing page, or a persuasive phone call.

Which is why liveness and deepfake detection matter as much at re-authentication as at onboarding. A biometric check that accepts a photograph, a screen replay, or a synthetic face has simply become another interceptable factor, and moving from SMS to a spoofable selfie check is not the transition the circular asked for. Our guide to biometric verification covers how the matching works.

Regulatory Exposure Under AFASA and BSP Rules

This is the section that changes the business case, because ATO controls are now tied to who pays.

Before AFASA, liability for digital banking fraud was frequently contested between institution and customer. Under the Anti-Financial Account Scamming Act, institutions with adequate risk management systems and strong authentication are protected from liability when scams occur despite those controls. Institutions without adequate controls are required to reimburse customers directly.

The BSP has indicated it may consider the use of server-side biometrics when assessing whether an institution has adequate risk controls, an evaluation that could influence AFASA liability in fraud cases.

Read together, the effect is that authentication design has become a liability position rather than a security preference. An institution still authorising transfers on SMS OTPs after 30 June 2026 is not only outside the circular. It is holding a weak position on every disputed transaction that follows.

Other instruments sit alongside AFASA. The Financial Products and Services Consumer Protection Act (RA 11765) governs complaint handling and consumer redress, while the Access Devices Regulation Act (RA 8484) covers unauthorised use of access devices. Behind SIM swap controls sits the SIM Registration Act (RA 11934).

Where the Money Goes Afterwards

ATO is rarely the end of the chain. Funds taken from a compromised account have to land somewhere, and that somewhere is usually a money mule account.

That link has an operational implication for institutions on the receiving side. An account that suddenly begins receiving inbound transfers from unrelated parties, holds them briefly, and forwards them onward may be the destination of a takeover that happened at another institution entirely.

AFASA anticipates this. It requires institutions and account owners to initiate a coordinated verification process on a disputed transaction, including where the information comes from another institution, and regardless of whether the funds remain in the banking system.

Frequently Asked Questions About Account Takeover

What is account takeover fraud?

Unauthorised control of a legitimate customer’s existing account. Unlike identity fraud at onboarding, nothing about the account or the customer is fake. The attacker gains access to a real, verified account and operates it, typically to move funds or change registered details.

Did the BSP ban SMS OTPs?

For high-risk transactions, effectively yes. BSP Circular No. 1213 required institutions to transition away from interceptable authentication mechanisms by 30 June 2026, and the BSP confirmed it was not extending that deadline. OTPs retain one permitted use, confirming the existence or ownership of a registered mobile number, but may no longer authorise transactions.

Which transactions count as high-risk under Circular 1213?

Coverage extends beyond login to include third-party fund transfers, adding a new payee, device registrations, updating registered contact details, and other credential changes. Lower-risk actions such as balance inquiries fall outside the requirement.

Does AFASA make banks liable for scam losses?

It depends on the controls in place. Institutions with adequate risk management systems and strong authentication are protected from liability when scams occur despite those controls. Institutions without adequate controls are required to reimburse customers directly.

How does SIM swap fraud work?

An attacker persuades or deceives a mobile carrier into transferring the victim’s number to a SIM they control. Messages including one-time passwords then arrive on the attacker’s device. Warning signs for customers include sudden loss of mobile service and unexpected notifications about SIM changes.

Is a biometric check enough to replace OTPs?

Only if it resists spoofing. A biometric step-up that accepts a photograph, a screen replay, or a synthetic face becomes another interceptable factor. Liveness and deepfake detection are what make the replacement meaningful. The BSP also requires that replacement authentication remain accessible to users such as elderly people with worn fingerprints and persons with disabilities.

The Factor That Cannot Be Forwarded

Every method that broke SMS OTPs worked the same way: the code had to travel to the customer, so an attacker who could stand between the institution and the customer could collect it. SIM swap intercepted it, phishing harvested it, vishing asked for it politely.

What ends that pattern is an authentication factor that cannot be relocated. A live face, checked against the identity captured at onboarding and tested for liveness, cannot be ported to another SIM or read aloud over a phone call.

That only holds if the enrolment behind it was sound and the liveness check is genuinely resistant to replay and synthetic media. Verihubs eKYC API covers both ends for Philippine institutions: government ID verification across 15+ document types with biometric liveness and deepfake detection at onboarding, and the same biometric matching available for step-up authentication afterwards.

Talk to the Verihubs team about biometric step-up authentication after the OTP phase-out.

View Blog