Is SMS OTP Ending in India? Singapore Already Killed It — and Your Fix Is Already in Your Phone
Singapore removed the OTP to protect its people. India kept it and quietly handed you a better lock instead — one that's probably sitting switched off inside your phone right now.
Short answer: Not by force — at least not yet. Singapore has already ordered its big banks (DBS, OCBC, UOB) to remove SMS OTP; India is moving the same direction but by nudge, not ban. RBI’s rules (effective 1 April 2026) require two-factor authentication with at least one dynamic factor and push banks to offer alternatives — while NPCI has, since 7 October 2025, allowed fingerprint/face UPI on GPay, PhonePe and Paytm (up to Rs 5,000). Biometric is safe because your fingerprint never leaves your phone. The catch: the fix is optional, and it’s sitting switched off in most people’s phones right now.
The thing you trust is the thing that’s failing you
The OTP feels like security. A secret code, just for you, expiring in minutes. What could be safer?
This: a code you can read is a code you can be tricked into sharing. A scammer doesn’t need to break a bank’s firewall. They need you to read six digits down the phone — “Sir, your KYC needs updating, tell me the OTP” — and you do the breaking for them.
The bill for that design is not small. In 2025, Indians lost roughly Rs 22,495 crore to cyber fraud across about 2.81 million complaints — up 24% in a year. Digital-arrest scams alone drew 30,000+ complaints and, by the Supreme Court’s estimate, losses near Rs 3,000 crore. A large share walked out through one door: a single OTP, shared by the victim.
What Singapore actually did — and why it worked
Singapore didn’t make the OTP “more secure.” It took the dangerous option away.
On 9 July 2024, the Monetary Authority of Singapore and the banks’ association told the big three — DBS, OCBC, UOB — to phase out SMS OTP for customers on digital tokens. The token lives inside the banking app; there’s no code to read out, so there’s nothing to phish. By 2026 the switch was largely done.
Think of it as a seatbelt. One approach: keep reminding people to buckle up, and hope. The other: the car won’t move until the belt is on. Singapore chose the car that won’t move.
Where India actually stands
Two things are true at once, and most people know neither.
One — RBI is nudging, not banning. The Authentication Directions (notified 25 September 2025, effective 1 April 2026) require two factors on every digital payment, at least one of them dynamic. Crucially, RBI did not ban OTP. It kept OTP as one option and told banks to also offer better ones: fingerprint, face, device tokens, QR approvals.
Two — the better lock is already in your phone. Since 7 October 2025, NPCI has allowed biometric UPI on Google Pay, PhonePe and Paytm — approve a payment with your fingerprint or face instead of a PIN, for now up to Rs 5,000. The safe method Singapore ran an entire migration to reach? Part of it is already installed on your phone. You just haven’t switched it on.
The fear everyone has — and why it’s the wrong one
“If my fingerprint leaks, I can’t change my finger.”
It sounds airtight. It’s also wrong. With on-device biometrics, your fingerprint never goes anywhere. Your phone’s own sensor checks you, inside the phone. Google Pay, the bank, some server in a data centre — none of them receive your fingerprint. The phone just vouches: yes, it’s them. There is no central vault of your finger to be stolen, which is precisely why you never need to “reset” it.
The thing you’re scared of isn’t happening. The thing that should worry you is quieter — and it’s about to get louder.
The scam doesn’t die. It changes shape.
When reading out a code stops working, the fraud won’t vanish — it will move. Instead of “tell me your OTP,” it becomes “just approve it.”
“Put your fingerprint to receive the money.” “There’s a request on your screen — say yes, I’ll handle the rest.” Biometrics stop the scam where you read out a code. They do nothing about the scam where you put your own finger on it.
So the real rule was never about technology. It’s one sentence, worth more than any setting:
You never approve, enter a PIN, or use a fingerprint to receive money. Only to send it. Anyone who asks otherwise is lying — always.
So, good or bad?
Good. Clearly good. A tool that was broken from the start is on its way out, and a genuinely better one — sitting in your hand — is arriving.
But one honest question remains, and it isn’t aimed at any party or at RBI. It’s about design. Singapore protected its people by removing the dangerous default. India left the old lock in place and set a better one beside it — as your choice. And when safety is left to choice, the most vulnerable — parents, grandparents, anyone who finds technology frightening — are the ones who stand at the broken door the longest.
Closing that gap isn’t the regulator’s job now. It’s yours. Today.
What to actually do
- Turn on biometric UPI today. Open your app, enable fingerprint/face. Thirty seconds. Then do it for the people at home who can’t.
- Never approve to receive. Treat every approval request like a stranger at your door. This one line stops half the scams cold.
- Move past SMS OTP where you can. Wherever your bank offers a device token or passkey, use it. Less code in transit, less to steal.
Singapore changed the lock. India handed you a new key — and left it in your pocket. The only thing left is to take it out and use it.
Take action
Sources
- MAS / Association of Banks in Singapore media release, 9 July 2024 — major banks (DBS, OCBC, UOB) to phase out SMS OTP for digital-token users
- RBI Authentication Directions, notified 25 September 2025, effective 1 April 2026 — two-factor authentication with at least one dynamic factor; alternatives to OTP encouraged, OTP not banned
- NPCI circular, 7 October 2025 — on-device biometric (fingerprint/face) authentication for UPI on GPay/PhonePe/Paytm, capped at Rs 5,000, opt-in, blocked on rooted devices
- I4C / Ministry of Home Affairs — Indians lost approximately Rs 22,495 crore to cyber fraud in 2025 across about 2.81 million complaints (up 24% year-on-year)
- Supreme Court estimate — digital-arrest scams: 30,000+ complaints in 2025, losses near Rs 3,000 crore
Will SMS OTP be discontinued in India?
Not by force — not yet. RBI's Authentication Directions (notified 25 September 2025, effective 1 April 2026) require every digital payment to use two factors with at least one dynamic factor, and they push banks to offer alternatives to SMS OTP such as biometrics, device tokens and QR approvals. But RBI has not banned OTP; it remains one option among several. This is different from Singapore, where the regulator ordered major banks to remove SMS OTP outright.
Is fingerprint or face UPI payment safe?
Yes, and safer than a PIN or OTP in the ways that matter. On-device biometric authentication uses your phone's own sensor to verify you locally. Your fingerprint or face data never leaves the phone and is never sent to Google Pay, PhonePe, Paytm or your bank — the phone only sends a 'yes, it's them' signal. Since October 2025, NPCI has allowed biometric UPI on GPay, PhonePe and Paytm for payments up to Rs 5,000.
What did Singapore do about OTP?
On 9 July 2024, the Monetary Authority of Singapore and the Association of Banks in Singapore announced that major retail banks — DBS, OCBC and UOB — would phase out SMS one-time passwords for customers using digital tokens. Digital tokens inside the banking app replaced the code, so there is no OTP for a scammer to trick out of you. By 2026 the migration was largely complete.
If my fingerprint can't be changed, isn't biometric riskier than an OTP?
It sounds logical but it's the wrong fear. With on-device biometrics your fingerprint is never transmitted or stored by the app or bank, so there is no central copy to be stolen and no reason to 'reset' it. The real risk today is not stolen biometrics — it's being socially engineered into approving a transaction yourself. Remember: you never approve, enter a PIN, or use a fingerprint to RECEIVE money. Only to send it.
What should I do right now to protect my payments?
Three things. First, open your UPI app and turn on biometric authentication (about 30 seconds) — and set it up for elderly family members who can't. Second, treat every approval request like a stranger at your door: no legitimate payment ever asks you to approve to receive money. Third, wherever your bank offers a device token or passkey, use it instead of SMS OTP. Less code in transit means less to steal.
After 5 Years, Your Health Claim Can't Be Rejected for 'You Didn't Tell Us.' Almost Nobody Uses This.
Once a health policy has run 5 continuous years, the insurer can't repudiate a claim on non-disclosure. It's not a new-2026 right — it's been sitting in your policy since 2024. The loss isn't the rejected claim. It's the clause you never read.
When Will NEET UG 2026 Results Come Out? The Honest Answer After the Leak
22 lakh students had to sit a national exam twice because of a leak nobody caught in time. The result date is finally real: 20 July.
The RBI Ombudsman Just Got Bigger Teeth — ₹30 Lakh, Free. Most People Still Won't Use It.
From 1 July, the RBI Ombudsman can award you up to ₹30 lakh for a bank's service failure — for free. The rule isn't the problem. Giving up at 'customer care' is.


