Site navigation

Digital Wallets Wide Open to Fraud, Says Which?

Tom Quinn

,

digital wallet security
“It’s clear further investment is needed to make the digital wallet set-up process fit for the threats consumers face in 2025,” said Sam Richardson, Which? Money.

The use of easily compromised one-time passcodes (OTPs) by some banks is leaving consumers at risk of digital wallet fraud on apps, including Apple Pay and Google Wallet, new research from Which? has found.

After a survey of fifteen high-street and digital banks, as well as card providers, the consumer action group found that the majority still use SMS OTPs as one of the main options for adding cards to digital wallets.

That’s despite a rise in warnings regarding the ability of criminals to exploit OTPs by setting up a phoney transaction. After luring victims with phishing scams, these crooks can monitor transactions in real time, tricking people into divulging their card details so they can add them to a digital wallet on their own phone. 

Scammers then simply ask the victim to complete a ‘transaction’ using an OTP code, which is then used to hijack and drain their account.

Of the fourteen providers that Which? investigated that allow cards to be added to digital wallets, just two banks confirmed they do not use OTPs, while a third appeared not to when Which? researchers tested the process.

Barclays, Co-op, and HSBC, along with its sister banks First Direct and M&S Bank, as well as Santander and Virgin Money said they currently use SMS OTPs, though they usually were not the only verification option, while TSB said it is working to set up in-app verification, but is using OTPs in the interim.

Digital-first competitor Starling told Which? that while it still uses OTPs for setting up Apple Pay, it removed them from Google Pay in 2022, while challengers Chase and Monzo differed significantly from the norm, telling Which? they don’t use OTPs for setting up digital wallets, and have never done so.

Cards issued by Halifax, on the other hand, did not use OTP, instead offering more robust methods like in-app approval. Three providers, including American Express, Lloyds Banking Group and NewDay, which operates the John Lewis Partnership Credit Card, did not outline which verification methods they use.

Which? said that in many cases, card providers are missing opportunities to strengthen security and move away from outdated forms of security like OTPs, with the survey highlighting examples of innovation that could add an extra line of defence.

Chase, for example, said that every time a card is added to a digital wallet, customers will receive an app notification to ensure the request is genuine, while Starling told Which? its customers can freeze their cards in mobile wallets using the app, and create virtual cards when they are unsure if a payee can be trusted. 

These virtual cards can then be deleted after a single use, ensuring a fraudster can’t make any further use of a customer’s credentials.

However, some existing security measures are not being implemented. While providers can limit how many digital wallets a card can be added to, when Which? surveyed them on this, most said they do not implement these restrictions.


Recommended reading


Of those that impose limits, Virgin Money allows individual cards to be added to a maximum of five devices, while Starling has a total limit of fifteen devices, and Monzo customers can only add their cards to a digital wallet twice in 24 hours, or three times every thirty days. 

Yet even with limits in place, Which? said there is still leeway for fraudsters, because they need only add one card to a digital wallet to start spending. 

“Banks have known for years that using one-time passcodes (OTPs) to verify account holders is leaving consumers vulnerable,” said Sam Richardson, deputy editor of Which? Money.

“It’s clear further investment is needed to make the digital wallet set-up process fit for the threats consumers face in 2025.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data