Skip to content
CityAM
Main navigation
  • News
    • News
      • Latest Business News
      • Economics
      • Politics
      • Tech
      • Banking
      • FTSE 100 Live
      • Retail
      • Insurance
      • Legal
      • Property
      • Transport
      • Markets
    • From our partners
      • AON
      • Bayes Business School
      • Canada BIDs
      • Central London Alliance CIC
      • Destination City
      • Halkin
      • Olympia
      • Inside Saudi
      • Tottenham Hotspur Stadium
      • Santander X
      • YEAR SIX Dividend
    • Featured

      The next person to shop your store may not be a person at all

      AI shopping agents are rewriting the rules of online retail across North America

      Submit a story

      Tell us your story.

      Submit
  • Opinion
  • Sport
    • Latest Sports News
      • Sport
      • Sport Business
    • From our partners
      • The Morning Briefing: SBS x CityAM
      • Aramco Team Series
      • LIV Golf
    • Featured

      Cohere's Aidan Gomez bets the house on 'sovereign AI' with Aleph Alpha merger valuing the group at $20bn

      Cohere CEO Aidan Gomez on stage discussing the Toronto AI lab's strategy

      Submit a story

      Tell us your story.

      Submit
  • Life&Style
    • Life&Style
      • Life&Style
      • Toast the City Awards
      • The Magazine
      • Travel
      • Culture
      • Motoring
      • Wellness
      • The RED BULLETiN
      • Do it with Shared Ownership
      • Media Speak Hub
    • Featured

      Moonvalley's Naeem Talukdar is selling Hollywood the one thing rival AI video tools cannot: legal cover

      Moonvalley's Marey AI video model produces Hollywood-grade footage trained on licensed data

      Submit a story

      Tell us your story.

      Submit
  • Investec
  • Events
  • Latest Paper
Thursday 28 August 2025 4:20 pm

One time passcodes fuel rise in digital wallet fraud

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
Digital-first players Chase and Monzo confirmed they have never used them, while Starling has phased them out of Google Pay.

Warnings have emerged over the security of digital wallets, following a report by consumer group Which? found widespread use of easily compromised one-time passcodes (OTPs) by some banks, leaving customers increasingly open to fraud.

The investigation, which surveyed fifteen high-street and digital banks, found that the majority are still relying on SMS OTPs to verify when a card is added to a digital wallet, despite repeated warnings from cybersecurity experts about their weaknesses.

It was noted that criminal actors have been exploiting this system by luring victims into phishing scams, harvesting card details, and then tricking them into entering OTPs under the belief that they are completing a legitimate purchase.

In practice, the code allows fraudulent actors to load the victim’s card onto their personal phone and spend freely online or in-store.

From the fourteen providers that allow cards to be linked to Apple Pay, Google Wallet and other apps, only three do not depend on OTPs.

Digital-first players Chase and Monzo confirmed they have never used them, while Starling has phased them out of Google Pay.

However, household names like HSBC and Santander still issue OTPs via text messages, which leaves consumers reliant on a flawed system that fraudsters have become adept at exploiting.

Convenience over caution

The warnings come alongside new research from card reader provider takepayments, which revealed that UK shoppers continue to prioritise convenience over safety when it comes to how they pay.

A survey of 2,000 consumers found that mobile wallet usage has declined year-over-year, while cash payments have staged a comeback, rising 26 per cent since 2023.

More than half of shoppers still carry physical cash, which has now overtaken mobile wallets as the second most popular in-store payment method.

Among those who prefer mobile wallets, the primary driving force is speed, rather than security.

Nearly three-quarters cited convenience as their top reason for using them, and more than half pointed to faster transaction times.

Just one in five said they viewed mobile wallets as the safest way to pay online. That may prove troubling given the scale of fraud now linked to digital wallets.

Read more

City calls on tech firms to tackle Britain’s fraud epidemic

Over £600m was stolen by fraudsters in the first half of 2025

Moreover, research earlier this year found seven in ten UK fintechs reported rising fraud volumes in 2024, with losses in some cases running into the millions.

Rona Warne, head of marketing UK&I at Global Payments, said businesses need to recognise the tension between speed and trust: “It’s clear that speed and convenience still win over security for many online shoppers. But just as important is giving your customers a choice.”

“Not everyone trusts or wants to use the same payment method every time. Small businesses can stay one step ahead by ensuring they accept cards, mobile wallets and services like PayPal, while keeping the checkout journey as simple as possible.”

An evolving threat

Fraud experts warn that the latest wave of scams marks a new level of sophistication.

By exploiting OTPs, criminals can hijack digital wallets and drain accounts without ever needing to clone a physical card.

Once added to a wallet, stolen credentials can then be used to purchase goods in shops or online, often months after the original scam, to avoid detection.

Gift cards and supermarket vouchers are also common targets, allowing gangs to quickly launder stolen funds.

John Clark, product manager at takepayments, noted that consumers are more alert to security than many firms assume: “All the IT outages in 2024 have only made people more aware of where they’re tapping, swiping or entering their card details.”

“Small businesses should highlight their use of secure gateways and display trusted symbols like Visa Secure and Mastercard SecureCode to build confidence at checkout,” he added.

Which? has urged banks to accelerate investment in stronger authentication methods, pointing to features already rolled out by some challengers, including instant app notifications, the ability to freeze wallet-linked cards, and the option of disposable virtual cards.

However, many incumbents continue to rely on OTPs, leaving what experts describe as “gaps in the net” for fraudsters to exploit.

As Sam Richardson of Which? Money said: “Further investment is needed to make the digital wallet set-up process fit for the threats consumers face in 2025.”

Read more

For all their charm, digital banks still leave me tearing my hair out

Digital bank interface showing user-friendly dashboard with financial analytics and transaction history on a modern screen

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech
  • Business

People & Organisations

  • Cyber crime
  • cyber security
  • digital banks
  • digital wallet
  • Fintech
  • fraud
  • monzo
  • one time passcode
  • Santander
  • Which?

Trending Articles

  • KPMG’s Summer Friday half-day rollback signals deeper woes for Big Four giants

  • Inflation expectations at record high in interest rates signal

  • London Tech Week sums up everything wrong with UK tech

  • UK economy falters as deeper damage to growth to come

  • KPMG report on AI found riddled with AI hallucinations

More from CityAM

  • ZayZoon, the Calgary fintech born on a fishing boat, posts 1,487% growth as earned wage access goes mainstream

    ZayZoon co-founder Tate Hackert built the Calgary fintech around earned wage access
  • Botpress raises $25m as Quebec's Sylvain Perron pitches his startup as the 'infrastructure layer' for AI agents

    Botpress product UI: the Quebec startup pitches itself as the infrastructure layer for enterprise AI agents
  • FluidAI wins US FDA clearance for its surgical monitor as Waterloo's Youssef Helwa targets 100,000 operations

    FluidAI's Origin surgical monitor wins FDA clearance for use in US hospitals
  • City watchdog probes Mastercard, Visa, Paypal for alleged anti-competitive conduct

    Regulation
    Mastercard logo prominently displayed on a sleek office building, symbolizing global financial services and innovation.
  • Chargebacks911, acceptcards Partner to Strengthen Chargeback Prevention for UK Merchants

    Business Wire
  • Money20/20 Europe Celebrates Ten Years of Industry Leadership as AI, Digital Assets and Financial Sovereignty Take Centre Stage

    Business Wire
  • ThetaRay Gamifies Financial Defense at Money20/20 Europe with a Compliance Twist on “Where’s Waldo”

    Business Wire
  • Icon Solutions Showcases How Banks Can Accelerate Digital Asset Innovation with IPF

    Business Wire
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy
  • News
  • Markets & Economics
  • Politics
  • Opinion
  • Life&Style
  • Personal Finance

Follow us for breaking news and latest updates

  • Facebook
  • X
  • Instagram
  • LinkedIn
Copyright 2026 CityAM Limited