Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› Why does relying on SMS one-time passwords increase…
Authentication, Authorisation & Trust

Why does relying on SMS one-time passwords increase payment risk in PSD2 environments?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Authentication, Authorisation & Trust

SMS one-time passwords can satisfy compliance, but they add a weak operational layer. They create delay, increase abandonment, and are exposed to carrier problems, SIM swapping, and SMS pumping abuse. Because the code arrives through a separate channel that attackers can manipulate, SMS OTP often raises fraud exposure while also making legitimate customers less likely to complete a purchase.

Why SMS OTP Weakens Payment Authentication in PSD2 Journeys

SMS one-time passwords can look like a compliance-friendly step, but they are a brittle payment control. They add friction at the exact moment a customer is trying to complete a purchase, and they depend on a telecom channel that can be delayed, diverted, or abused. In PSD2 environments, that means the authentication step may be present without being operationally strong.

The core issue is that the payment experience inherits the weaknesses of the SMS channel. Delivery delays increase abandonment and support burden, while SIM swap attacks and SMS pumping can turn the challenge step into a fraud surface. The result is a control that may satisfy process expectations yet still raise the chance of failed payments, account compromise, or fraudulent transaction approval.

For practitioners, the distinction matters: a second factor is not automatically a strong factor. In payment flows, the control has to withstand real adversary pressure and still complete reliably under normal customer conditions. SMS OTP often fails both tests at once.

Why the Separate Channel Becomes the Problem

SMS OTP works by moving the verification code outside the browser or app session and into a separate delivery path. That sounds safer than reusing the same login channel, but it also creates a new dependency on mobile networks, carrier routing, handset access, and phone-number control. Any weakness in that chain can become the weakest point in the payment step.

Attackers do not need to defeat the payment page directly if they can take over the phone number or intercept the message. SIM swapping, number porting abuse, and social engineering against the carrier can redirect the code. In other cases, SMS pumping or message abuse can inflate costs and flood the process with unreliable deliveries. The payment system then treats a fragile transport layer as proof of customer intent.

That is why SMS OTP is especially poor when the payment decision itself is high value. The channel verifies possession of a phone number, but not robustly enough to prove that the approved transaction is being authorised by the intended payer at the moment of payment.

PSD2 Compliance Does Not Remove Fraud Exposure

PSD2 and Strong Customer Authentication are about reducing risk, not just adding a checkbox. An SMS code may fit a policy workflow in some implementations, but compliance alone does not make the method resilient to modern fraud patterns. A control can be accepted operationally and still be weak against takeover, interception, or abuse.

In practice, the payment risk shows up in two directions at once. Legitimate customers face slower checkout, failed delivery, and more abandonment. Fraudsters face a channel that can be manipulated without breaching the merchant application itself. That combination is why the business impact is not limited to authentication quality, it extends to conversion, support load, and loss rates.

For payment teams, the important question is not whether SMS OTP exists in the flow, but whether it meaningfully reduces the chance of unauthorised transaction approval compared with stronger methods such as phishing-resistant authentication or app-bound approval.

Risk and Threat Considerations

SMS OTP concentrates both operational and adversarial risk in a channel the merchant does not control. When the code is delayed or diverted, customers abandon checkout; when the number is taken over, the same step can be used to authorise fraud.

Failure mechanism: The payment journey treats telecom delivery as a trustworthy proof step, even though the message path is exposed to carrier failure, SIM swap, and SMS abuse. The result is a fragile approval control that can be bypassed or made unreliable without touching the payment application itself.

Impact: Organisations see higher abandonment, higher support burden, and greater exposure to account takeover and fraudulent transaction approval. Over time, that weakens both fraud outcomes and customer trust in the payment experience.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while PCI DSS v4.0 and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesSMS OTP is an authenticator choice and this framework addresses authenticator assurance and phishing resistance.
Recommendation — Prefer stronger authenticators over SMS OTP for payment approval where higher assurance is required.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Payment-fraud control depends on robust authentication and proof of the approving party.
IA-5 — Authenticator ManagementSMS OTP weaknesses stem from authenticator lifecycle, delivery, and exposure issues.
Recommendation — Use stronger authentication controls for high-risk approval steps instead of SMS OTP. Manage authenticators so weak or fragile factors are not relied on for payment approval.
PCI DSS v4.08.4.2 — Multi-Factor Authentication for Access into the Cardholder Data EnvironmentPayment environments need strong authentication controls where MFA is required for access and sensitive actions.
Recommendation — Apply stronger MFA patterns than SMS OTP for sensitive payment-related access paths.
ISO/IEC 27001:2022A.5.17 — Authentication informationSMS OTP relies on authentication information that must be protected from interception and misuse.
Recommendation — Protect authentication information with methods that reduce interception and reuse risk.

Practitioner Guidance

What to prioritise: Treat SMS OTP as a fallback or transitional control, not the preferred payment authenticator, where the transaction value or fraud exposure is material. If it remains in use, document the specific reason it is still acceptable and where its risk ceiling sits.

What to verify: Check whether failed SMS delivery, SIM swap exposure, and number-recycling risk are being measured as payment-control failures, not just telecom annoyances. If you cannot observe those failure modes, you are likely overestimating the strength of the control.

Practitioner takeaway: In PSD2 journeys, the real question is whether the authenticator withstands fraud pressure and still completes reliably at checkout, and SMS OTP usually trades away both properties.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org