Security Advisory

Customers using Samsung Galaxy S10/10+, Note 10/10+ 5G devices are advised to temporarily disable fingerprint authentication due to an issue found with Samsung’s fingerprint sensor

Customers utilising Samsung's fingerprint authentication are advised to use alternative methods such as passwords or Pin until a fix has been issued to prevent unauthorised access to their OCBC Mobile Banking / Pay Anyone Applications.

Owners of the affected models are advised to disable fingerprint authentication until a fix is released by Samsung.

To disable fingerprint login:

  • Login to the OCBC Mobile Banking app > Open the side menu > Select Settings > Deactivate OCBC OneTouch > Confirm
  • Login to the OCBC Pay Anyone app > Open the side menu > Select Settings> toggle off the Login with OneTouch

Reference:

https://news.samsung.com/global/statement-on-fingerprint-recognition-issue

How to protect yourself:

  • Verify the transaction details in the SMS message, ensure that it is for the transaction that you are authorising before using the associated OTP. Inform the Bank immediately if the transaction is suspicious.
  • Ensure the OTP is keyed in the correct bank’s mobile application or website. Do not reveal the OTP to anyone.
  • The Bank will not make unsolicited requests for your banking details. Be mindful not to reveal your personal or banking details such as ATM/Credit/Debit Card numbers, Online Banking Access Code, PIN/OTP into mobile applications or websites that you are not sure of.
  • Be on the alert for suspicious emails/SMS messages and websites or mobile messages, purporting to be from the Bank asking for your OCBC Online Banking login credentials such as PIN/OTP etc. Inform the Bank immediately if the transaction is suspicious.
  • Stay vigilant before clicking on any links embedded in the SMS messages or emails.
  • Always type the URL of the website directly into the address bar of the browser.
  • Inform the Bank immediately when there is a change in your contact details such as mobile number or email address so that you continue to receive SMS alerts or e-mail notifications for online banking transactions and activities.
  • Do not transfer funds to any unknown parties.

What you should do

Please call OCBC Contact Centre immediately at 03-8317 5000:
  • You are aware of any suspected fraud or transactions not performed by you including any compromise or loss of your security device or security details.
  • You received a SMS message or email for transactions which you did not perform.
  • You are alerted on change of daily withdrawal limit or add beneficiary for transfer to an account which you do not know of or did not perform.


Learn more about Phishing, Malware and Online Banking security.