
The ATO Channel Is Tightening. Plan for Where the Fraud Goes Next.
12.08.2026
On 31 March 2026, SMS and email one-time passwords (OTP) stopped being an acceptable way to authenticate a customer in the UAE.
That deadline came from CBUAE Notice 2025/3057, which required licensed institutions to replace them with biometrics, FIDO2 passkeys, device-bound keys, in-app push approval, or a hardware or software token, and moved liability for OTP-linked fraud onto the institutions themselves.
No regulator anywhere had gone that far before. The UAE is the first country in the world to mandate it, and it was the right call. This is not the first time the region moved first. SAMA mandated an account verification service before a beneficiary can be added, across the instant payment system and RTGS, in a circular effective May 2023. The EU's equivalent verification-of-payee obligation applied from October 2025, two and a half years later. The CBUAE separately requires the payee name to be displayed before a transfer is confirmed, with payee name verification in place for instant payments.
The weakness was never the one-time password itself: it was the two channels carrying it. An SMS code can be lifted through SIM swap or interception, and an email code sits behind a mailbox often protected by a password already sitting in a breach corpus. Both fail while the customer does everything right. And where the channel holds, the code is still readable and therefore still shareable, which is why every warning not to share it loses to a confident caller.
The fix was to change what the customer is holding, not to ask them to hold it more carefully.
None of the technology was new. Soft tokens and in-app approval have been in this market since 2017, when Emirates NBD launched Smart Pass, mandatory there from 2021. Others moved at their own pace, many still switching through 2025.
That spread is the interesting part. The mandate did not bring app-based approval to the UAE. It closed the residual channels, the places SMS quietly stayed alive alongside the strong control:
That matters for what follows, because a control that exists is not the same as a control with no way around it.
Here is the part that gets less attention. Social engineering unfortunately does not stop working when you close one door. It relocates to the door still open.
Every social engineering attack in retail banking ends in one of two outcomes.
FIGURE 1: Stronger authentication reduces the yield from account takeover, but it does not test whether a customer's payment intent is genuine.
The first is account takeover (ATO). The fraudster gets into the account and moves the money themselves. A lot of what the industry has built over the last fifteen years attacks this: device intelligence, behavioral biometrics, session analytics, step-up authentication, and now the passkeys and biometrics that 3057 mandates.
The second is authorized push payment (APP) fraud. The fraudster never touches the account. The customer is deceived and manipulated into making the payment personally, on their own device, through their own genuine banking session.
Account takeover is getting materially harder. I want to be careful here: it is not solved, and anyone selling you that is overreaching. Remote access tooling still degrades device signals, and adversary-in-the-middle techniques are advancing faster than most detection stacks. But harder and more expensive is enough. Fraud is a business with an ROI, and when the cost of one route rises while the payoff stays constant, the volume simply moves. Whether this door stays shut is a separate question, and one I suspect we will be revisiting.
What does not happen is the attacker giving up. Social engineering itself shows no sign of losing its edge: the FBI's Internet Crime Complaint Center recorded reported phishing losses growing 208% in 2025 while complaint volume remained broadly flat, moving from about 193,000 to 192,000. Complaints are not the same as unique victims or attempts, so the figures cannot establish a per-victim extraction rate. They do show that a familiar social-engineering category continued to produce sharply higher reported losses without a corresponding rise in complaint volume.
So the capability is intact and improving. Only the exit changes. And it moves to the route where the bank's controls are not merely bypassed but completely missing.
You do not have to take the displacement argument on faith when another market has already produced a result consistent with it.
The UK hardened authentication under strong customer authentication rules, then went further than anyone by making reimbursement mandatory in October 2024. It is the market furthest ahead on precisely the two things the GCC is now doing. UK Finance's Annual Fraud Report published in 2026 shows what came out the other side.
The reimbursement rule is the part that explains the pressure. Making it mandatory does something no volume of guidance achieves: it converts an authorized push payment loss from the customer's misfortune into a line on the bank's own profit and loss. Once the institution pays, prevention stops being a compliance obligation and becomes a cost decision, and cost decisions get budget. The 50/50 split between the sending and receiving institution extends the same logic to whoever opened the mule account, which is the only mechanism anyone has found that makes weak onboarding expensive to the firm responsible for it.
FIGURE 2: UK Finance data for calendar 2025 shows remote-banking losses falling as recorded cases rose, while APP losses and cases both increased.
The argument lives in the gap between the first two remote-banking measures. More recorded cases. Far less money. That is consistent with a control environment reducing fraud yield even when it does not eliminate activity. Web losses specifically nearly halved, down 46% to an all-time low, on effectively flat case volume.
Now the other door. Strip out cards, and the picture is stark: in UK non-card fraud, APP is now more than five times the size of remote banking fraud and moving in the opposite direction.
There is an apparent contradiction here, and it needs clarification. On 1 July 2026 the PSR published an independent evaluation of the reimbursement regime's first year: the policy cut APP losses by around GBP 73 million annually, avoided roughly 35,000 scams, and reduced APP fraud over Faster Payments by about 21%.
So the policy worked. And APP losses still rose 19%. Both are true, because the PSR figure measures against what would otherwise have happened. The intervention slowed the trend rather than reversing it. And that is the shift we expected and expect even further in the future- a shift from ATO to APP.
That is the sobering part, and the reason to cite a market that is not ours. In a country with strong authentication rules, a mandatory reimbursement regime, and an independent evaluation confirming that regime works, authorized fraud still grew by a fifth in a year. The comparison does not prove that stronger authentication caused APP losses to rise, because the markets, reporting rules and policy environment changed at the same time. Where authentication is hardened, takeover yield can fall sharply while authorized fraud continues to grow.
Notice 3057 puts the UAE firmly in the first group, with a date attached. But the UAE has the hardening without the loss allocation that turned prevention into a profit and loss question in Britain. Displacement arrives either way. The commercial pressure to spend against it does not - for now at least.
The GCC did not tiptoe into real-time payments. It sprinted. SAMA launched Sarie through an event organized by Saudi Payments in February 2021, and Al Etihad Payments, a CBUAE subsidiary, launched Aani in October 2023. Add the Digital Dirham, which I wrote about here before its first live government transaction and while its public rollout was still being prepared, and you get a payment landscape increasingly built around instant, traceable, account-to-account movement.
Those rails are the open door. Excellent infrastructure, and also a mechanism for moving money irreversibly, in seconds, on the customer's own instruction.
This is not a forecast built on a hunch, although the figures themselves are modeled estimates rather than official loss statistics. ACI Worldwide's Scamscope, with GlobalData, estimated UAE authorized push payment losses at USD 8.3 million in 2024, up 43% year over year, and projected USD 30.3 million by 2028. It projected USD 26.8 million of the 2028 total, close to 90%, would run over real-time rails.
The victim side is worse than the modeled loss numbers suggest. The Global Anti-Scam Alliance and BioCatch surveyed around 2,000 UAE residents for their 2024 State of Scams report. The report estimated that more than 40,000 residents fell victim; 27% of respondents said they lost money, at an average of USD 2,194, and only 9% recovered in full. Almost 60% of victims requested reimbursement and received nothing.
Hold those two together. The loss category growing at nearly 30% a year is also the one where the customer absorbs the loss almost every time. Prevention is the only place the return currently exists.
The wider picture reads the same way. In a 2026 BioCatch survey, 58% of UAE banking leaders reported increasing fraud losses, while 62% estimated that their institutions lost more than USD 5 million annually. The survey is vendor-sponsored perception data rather than audited industry loss data, but it supports the narrower conclusion that attack pressure is not perceived to be easing while the controls change.
The fraud detection most institutions in this region have spent the last few years building is very good at a question that authorized push payment fraud does not ask.
The ATO stack establishes whose hands are on the device. Device intelligence, behavioral biometrics, session analytics: all of them converge on identifying whether the person operating the session is the account holder or a stranger. On that question they are strong, and they are getting stronger. But they are irrelevant for APP.
In an APP scam, the answer is yes. Correctly, unambiguously, every time. The customer really is the customer. The device really is their device. The typing cadence really is theirs, because nothing about them is being faked. They are being coached, and a coached customer defeats motor-signature detection outright because there is no imposter to detect.
The question APP fraud asks is different: does this customer understand what they are actually authorizing?
Almost nothing in a conventional fraud stack asks that. It is not an oversight. It is that the industry built for the threat it had, and the threat is shifting.
This has a practical consequence worth stating plainly. If a green behavioral or device result feeds rule suppression, whitelisting or a score as evidence of legitimacy rather than evidence of identity, that assumption is now working against you. It will keep answering yes on precisely the transactions you most need to question.
The region already has a beneficiary check. What it does not have is the European version of it, and the difference matters far more than the shared name suggests.
Resolve and display takes an IBAN or an alias and shows the payer the registered account name. Match takes a name the payer typed and compares it against the account holder name, returning a match, a close match, or no match. The GCC schemes lean toward the first. The EU obligation that applied from October 2025 is the second, and it is the one that gets waved through in strategy decks whenever a market decides to catch up.
Matching is close to trivial where names are stable Latin-script strings with predictable structure. Now run it across a GCC book.
Now run the same control across a GCC book.
The result is not that payee verification fails more often. It is that the gray area in the middle becomes enormous.
That gray area is where the harm lives, and there is no tuning that fixes it:
FIGURE 3: Payee-name matching in the GCC creates different failure modes at tight and loose thresholds; neither can be managed safely without local testing.
Anyone who has spent time on fuzzy matching in sanctions screening knows this shape of problem: the tuning is the entire product, the thresholds are market-specific, and a threshold imported from another market is not a starting point; it is a liability. Payee verification here is a genuine engineering problem that deserves genuine engineering effort. Adopting it on the assumption that it is cheap is how you end up with a control that is sometimes worse than no control.
There is a second-order effect of the authentication mandate that deserves attention.
Financial inclusion in this region is not a slogan. Wage protection programs, wallet-based payroll and low-friction onboarding have brought large populations of laborers and domestic workers into digital finance, many operating in a second or third language, many using formal banking for the first time, and many sending most of what they earn abroad every month to people who depend on it.
That is an unambiguous social good. It also produces the segment with the highest exposure to social engineering, the least familiarity with what a bank will and will not ask, and the least capacity to absorb a loss.
Now consider what replaces the SMS code. Biometrics, FIDO2 passkeys, device-bound cryptographic keys, and in-app push approval all assume a reasonably current smartphone, a stable device relationship, and a user comfortable with what they are approving. Where those assumptions hold, protection improves considerably. Where they hold weakly, the account takeover risk falls less than the average suggests, and the exposure to a coached payment stays exactly where it was.
So the hardening is real, and it is not evenly distributed. The segment least protected by the new controls is also the one most exposed to the fraud those controls do not address.
The reimbursement question will arrive here in some form. SAMA's Counter-Fraud Framework requires a remediation process and identifies restoring a victim's prior position, including refunding a scam payment, among the corrective actions an institution may take. That is not the same as the UK's prescriptive reimbursement regime, with its cap, timeline, inter-institution split and dispute path. If comparable machinery is built here, institutions already measuring authorized fraud will be in a very different position from the ones discovering it.
Four things worth putting to your own environment, none needing a new platform or a regulatory mandate to start:
Separate authorized from unauthorized loss in your own numbers. In many institutions the two sit in one bucket, or authorized losses are not recorded as fraud at all because the customer approved them. If you cannot see the two categories independently, you cannot see displacement happening.
Audit where a clean device or behavioral result is feeding a legitimacy decision. Find every rule and score treating a green result as evidence the payment is fine rather than evidence the person is who they claim. That inheritance was less dangerous when the dominant threat was account takeover. It is dangerous when the genuine customer is being coached.
Test name matching on your own book before anyone mandates it. Sample genuine payments, run your matching logic, and measure the false mismatch rate across your actual name population rather than a vendor's demo set. Far better to discover that on your own terms.
Shift detection weight toward the beneficiary and the outbound leg. Newly created beneficiaries, first-time payees receiving atypical amounts, and accounts showing rapid onward movement carry information that transaction attributes alone do not. This deserves an article of its own, and it will get one.
The last one is the hardest and the most important: put friction at the authorization moment rather than the authentication moment. A customer who is being coached will pass every authentication challenge you can invent, because nothing about their identity is false. A cooling-off period on a first payment to a new beneficiary, or a plain-language restatement of where the money is actually going, targets the point where the deception actually lands.
Closing the SMS door was the right decision and the region should get credit for making it. The mistake would be reading a fall in account takeover as a fall in fraud.
