Is strong customer authentication working?

Entering a one-time password to complete an online transaction is now mandatory, so is strong customer authentication working? Or have fraudsters simply changed tactics?

Anyone who has shopped online recently will have already become accustomed to the extra step of having to receive and then use a one-time password (OTP) or log onto their mobile banking app to approve a purchase.

This strong customer authentication (SCA) step became mandatory in March, as ecommerce providers were obliged to ensure customers prove their identity through something they know (a password) and something they own (their mobile phone).

The measures were brought in because, according to figures from the banking and financial industries body, UK Finance, remote purchases accounted for four in five (79%) card fraud cases during 2021. By sending the legitimate customer a one-time password or asking them to log into a bank app, the hope is that fraud rates will drop.