Brig. Gen. Md. Shahjahan Mujib
There was a time when sending money online meant waiting for a brief message, the familiar six-digit OTP (One-Time Password). Receiving that code on our phones brought a sense of relief, as if those few digits were the only key to keeping our money safe. However, times have changed. What was once considered a “secure” method has now become one of the easiest gateways for fraud. That era is gradually coming to an end.
In response, the United Arab Emirates (UAE) has announced that by March 2026, all banks will completely phase out SMS and email-based OTPs. In their place, a new system will take over: biometric authentication, where transactions are approved using a person’s face or fingerprint, effectively making the user their own password. The main motivation behind this move is to combat financial fraud.
The UAE has clearly recognised this challenge. Over the past few years, the country’s banks have undergone massive digital transformation. Online banking, mobile apps, and digital payments have all seen a surge in users. At the same time, cyber fraud and account hacking incidents have also increased. According to the UAE Central Bank, in 2023 alone, customers lost approximately $87 million due to online banking scams.
In many cases, hackers have used social engineering to gain access to users’ phones and collect OTPs. As a result, banks were forced to look for a solution entirely based on user identity rather than external codes or passwords. In many instances, criminals exploited OTPs through phishing links or SIM swapping to drain accounts. In short, no matter how advanced the technology, if the OTP falls into the wrong hands, security is effectively nullified.
This is why biometric authentication is emerging as the most logical and secure alternative. Whether it’s fingerprint, facial recognition, iris scanning, or voice authentication, these methods ensure that only the legitimate user can authorise a transaction. No matter how sophisticated a hacker’s tools may be, replicating someone’s face or fingerprint is nearly impossible. Additionally, biometric data is usually stored in encrypted form and verified locally on the device, greatly reducing the risk of server-side breaches.
Now, consider this from a Bangladesh perspective. Take Mr. Rahim, a government employee living in Mirpur. He commutes to the office daily, returns home in the evening, and occasionally uses online banking to pay bills or send money to his family. One morning, he receives a bank notification: “BDT 200,000 has been transferred from your account.” Rahim is shocked that he did not authorise this transaction. Upon contacting the bank, he learns that the OTP was sent to his phone and had been used.
Further investigation reveals that a fraudster had previously sent him a phishing link, captured his banking credentials, performed a SIM swap, and used the OTP to steal the money. This illustrates the harsh reality- even with OTPs, customers remain vulnerable.
Now imagine the same scenario under a biometric system. Rahim’s bank app would not process the transaction without verifying his face or fingerprint. Even if the OTP was compromised, it would be worthless because biometric information cannot be easily forged. This demonstrates the true strength of the technology. With biometric security, you essentially become your own password like your face, fingerprint, or voice serves as proof that you are the legitimate user.
Biometric security offers numerous benefits for customers. Firstly, there’s no need to memorise codes or passwords. Secondly, the risk of fraud drops dramatically. Thirdly, banks gain assurance that transactions are genuinely initiated by the real account holder. Setting up biometrics may feel a bit bothersome at first, but once it’s done, using it becomes very easy. No more waiting for OTPs, no worries about forgotten passwords; transactions can be completed safely in seconds. It’s not just a technological upgrade; it provides psychological comfort as well.
The role of the government is crucial in this transition. The UAE, for instance, has launched a national digital identity system called UAE PASS, applicable to both citizens and residents. Through this platform, unified biometric authentication is possible across government and private services alike. Once registered, a user’s face or fingerprint alone suffices for all transactions from logging into a bank account to paying taxes or signing official documents.
This model is highly relevant for Bangladesh. While digital banking is rapidly expanding, security threats are growing alongside. Reports of online scams, phishing attacks, and mobile banking hacks are almost daily occurrences. OTPs often provide only a weak security barrier, especially when users are careless or when malware intercepts codes automatically. It is therefore time for Bangladesh to move toward biometric authentication.
Bangladesh already possesses a vast store of biometric data through the National ID (NID) database. If this database is securely integrated with the banking sector, it could revolutionise digital authentication. Banks could begin with pilot projects to introduce biometric logins and transactions, while the Bangladesh Bank could issue policies to ensure data protection, encryption, and user consent.
However, technology alone is not enough, awareness is equally important. Many users still believe OTPs are entirely secure, unaware that they can be hacked or stolen. Banks should regularly conduct digital security awareness campaigns, particularly targeting rural and less tech-savvy users. True success will be achieved when awareness reaches the grassroots level.
The future of banking will no longer depend on passwords or OTPs. Your identity itself will be the key.
The UAE’s experience shows that biometric security is not just a convenience, rather it’s a necessity. If Bangladesh adopts this system in time, online banking will become safer, more convenient, and more trustworthy. For customers like Rahim, it will bring both peace of mind and a real sense of security.
Once, we memorised passwords; later came the “OTP era.” Now, even that era is fading into history.
From now on, your face, fingerprint, and voice will stand guard over your security. This transformation is not only just technological but also a revolution of trust. It envisions a banking ecosystem where humans themselves are the reflection of their own security. The UAE has taken the first step on this new journey; others will learn, adapt, and together build a safer, smarter, and more connected digital world. Because in today’s age, cybersecurity is no longer a luxury, it is an absolute necessity.
The writer is an NDU, PSC




