UAE Digital Wallet Fraud: One OTP Gives Criminals Unlimited Card Access
Bank customers in the UAE report fraudulent card charges after criminals added their cards to unknown devices using a single verification code. Banks are rejecting refund claims, citing OTP entry as proof of consent.

One Verification Code, Unlimited Losses: UAE Digital Wallet Fraud Explained
Bank customers across the UAE have reported significant financial losses after fraudsters added their payment cards to unknown devices via digital wallets, then carried out multiple purchases in rapid succession — all without the cardholders' knowledge or consent, emirates247.com reports.
The victims say their banks rejected their fraud complaints, arguing that the cards were legitimately linked after a one-time password (OTP) was entered. Customers, however, insist that the fraudsters' possession of that code does not constitute authorisation to add the card or make any purchases.
How the fraud works
According to affected customers, the scheme typically begins with a fake call or message impersonating a bank or official body. The fraudster, using a spoofed electronic page or link resembling the bank's genuine website, tricks the customer into disclosing their card data and the OTP sent to their registered phone number.
Once the OTP is entered and the card is successfully added to a digital wallet on the fraudster's own device, the criminal gains the ability to make repeated transactions without requiring any further verification code from the bank. By the time the cardholder detects the unusual activity, a large number of purchases may already have been processed.
Customers have called on banks to go beyond the OTP as the sole basis for dismissing complaints, demanding technical investigations that examine the device to which the card was linked, its geographic location, the timing and volume of transactions, and whether the spending pattern matches the customer's normal behaviour.
The banking perspective
Banker Issa Al Ali explained that card-linking procedures rely on the OTP as the official means of confirming device ownership. "Entering the code is considered an explicit approval of the process from the perspective of banking systems," Al Ali said.
He added that customers bear responsibility for safeguarding their confidential data, refraining from sharing verification codes with any party, and avoiding links from unknown sources. Al Ali said banks routinely advise customers to activate instant transaction alerts, monitor their accounts for unusual activity, and contact their bank immediately if something appears wrong.
"All objections are studied individually, and the process is checked to ensure the protection of customers and prevent the recurrence of such cases," Al Ali said, adding that protection systems are continuously being strengthened to keep pace with evolving fraud methods.
The technical distinction banks may be missing
Assem Jalal, a management science and IT consultant at G&K Consulting, outlined three stages of card authentication that he says are often conflated in fraud investigations.
In the first stage, a traditional credit card transaction is verified using the card itself along with a PIN or CVV code. For online transactions, the bank sends an OTP to confirm the cardholder's presence and consent.
In the second stage, when a card is added to a digital wallet — such as Apple Pay, Samsung Wallet, or Google Pay — the card number itself is not stored on the device. Instead, a unique token is generated and linked to that specific phone. An OTP is requested only once to approve this initial linking.
The third stage, Jalal noted, is the one most frequently overlooked: every subsequent transaction made through the wallet does not require a new OTP from the bank. The device itself becomes the authentication tool, relying on the user's fingerprint or facial recognition. This means that once a fraudster has successfully linked the card, they face no further verification barriers for any transaction carried out on that device.
Jalal argued that OTP entry at the linking stage should not be treated as the sole piece of evidence when investigating fraud complaints. He called for examination of the specific device used, the timing and pattern of transactions, and the effectiveness of security systems in flagging unusual activity.
Consumer protection standards
The Consumer Protection Standards issued by the Central Bank of the UAE state that a transaction is considered authorised if the financial institution has applied correct and secure verification procedures — unless the customer provides preliminary evidence raising reasonable suspicion that they did not carry out the disputed transaction. The standards further require that unauthorised transactions be refunded within 30 days.
Customers contend that the use of sophisticated social engineering techniques — including impersonation of banks and official bodies, and the use of near-identical fake websites — means that sharing an OTP cannot automatically be equated with informed consent to add a card or authorise purchases. They argue that banks must apply a broader evidentiary standard before attributing the full loss to the account holder.
Source: Google News AE