The Growing Threat of SIM Swap Fraud

As cybercrime and fraud have escalated into a global crisis, one type of scheme is seeing particularly rapid growth: SIM swap fraud. The growing prevalence of SIM swap attacks highlights vulnerabilities in telecom authentication processes and underscores the need for stronger regulatory measures to protect customers. SIM swap fraud is increasingly plaguing the telecommunications industry and its customers. It was recently ranked second, behind synthetic identity fraud, among the most damaging fraud schemes affecting the telecom industry. 1. What is SIM swap fraud? SIM swap fraud is a cybercrime in which criminals gain control of a victim’s mobile phone number by fraudulently obtaining a replacement SIM card. Criminals may first collect personal information through phishing, social engineering, data leaks, or malware, and then use that information to impersonate the legitimate customer. Once the victim’s mobile number is transferred to the criminal’s SIM card, SMS messages including banking OTPs and transaction alerts can be received by the fraudster. SIM swapping requires no advanced technical expertise. Instead, it relies on the fraudster’s ability to manipulate telecom carrier employees into transferring a victim’s phone number to a SIM card under the fraudster’s control. Using basic personal information obtained from public sources or data leaks, fraudsters can carry out attacks with little more than a phone call or a visit to a retail store, without requiring coding or hacking skills. The only tools needed may be inexpensive prepaid SIM cards or burner phones. In a SIM swap attack, the attacker takes control of a legitimate subscriber’s mobile phone number by persuading the mobile telecom provider to link that number to a SIM card controlled by the attacker. SIM swapping is a legitimate procedure that serves a number of purposes, such as replacing a lost or damaged SIM card. It is also used to connect mobile phones to embedded SIMs (eSIMs), which are becoming increasingly common. In a fraudulent SIM swap, however, the attacker uses social engineering techniques to convince the telecom provider to transfer the number, impersonating the legitimate customer and claiming, for example, that the original SIM card has been lost or damaged. When the attack is successful, the legitimate subscriber’s phone loses its connection to the mobile network, preventing them from making or receiving phone calls. 2. 80% of SIM Swap Fraud Attempts Succeed Due to Weak Authentication A study by Princeton University found that 80% of first attempts at SIM swap fraud were successful. One of the main reasons for this high success rate is the use of weak authentication methods by telecom operators, which can be easily bypassed by fraudsters. While each carrier has its own vulnerabilities in the SIM replacement process, none required direct identity verification or implemented strong multi-factor authentication, allowing fraudsters to carry out remote attacks with relative ease. Telecom operators have often prioritized convenience over security, opting for simpler authentication methods to streamline customer service. In doing so, they may inadvertently create opportunities for fraudsters to exploit vulnerabilities. Lowering security standards to reduce friction for customers can ultimately weaken carriers’ defenses against SIM swap fraud. The risks become even more serious when mobile banking applications rely heavily on phone numbers and SMS-based OTPs for identity verification. If a newly registered device can be activated primarily using customer credentials and an OTP, a successful SIM swap attack may give an attacker access to the victim’s bank account. Weak device-binding mechanisms, insecure account recovery processes, inadequate session controls, and insufficient verification when registering a new device can further increase this risk. 3. SIM Swap Fraud Is Not Just a Consumer Problem SIM swap attacks are often viewed primarily as a threat to individual consumers, but they can have direct consequences for organizations as well. When an employee’s phone number is compromised, attackers can intercept one-time passwords (OTPs) sent via SMS and potentially gain access to corporate systems. This puts not only personal accounts at risk but also sensitive corporate data, financial assets, and customer records. One of the most significant concerns is account compromise through SMS-based authentication. Many organizations still rely on mobile phone numbers for password resets or two-factor authentication. If an attacker gains control of an employee’s phone number, they may be able to change login credentials for email accounts, cloud services, or financial systems often without raising suspicion until it is too late. The legal and reputational risks can be equally serious. Under the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018, organizations have obligations to protect personal and customer data. If attackers exploit weak authentication through a SIM swap attack, regulators may consider the incident in the context of data protection requirements. Beyond regulatory compliance, such incidents can also seriously undermine customer trust. 4. Measures to Prevent SIM Swap Fraud For these reasons, security experts recommend that organizations and telecom operators move away from SMS-based authentication and adopt stronger identity authentication methods, such as Identity and Access Management (IAM), authenticator applications, or hardware security keys. Banks can mitigate SIM swap fraud through measures such as strong device binding, risk-based authentication, transaction-level verification, controls over new-device registration, cooling-off periods for high-risk activities, real-time alerts, and server-side authentication and authorization controls. Customers, meanwhile, should avoid sharing OTPs, PINs, or login credentials and should never install banking-related APK files from untrusted or unknown sources. Ultimately, SIM swap fraud demonstrates why mobile banking security cannot rely on a single authentication factor. Instead, phone numbers, devices, customer identity, authentication processes, and transaction behavior should be treated as independent layers of security. SIM swap attacks clearly demonstrate why organizations need protective measures that go beyond the security standards typically applied to individual consumers. 5. Building Digital Trust Beyond SMS-Based Authentication SIM swap fraud highlights a broader challenge: digital security cannot depend on a single authentication factor – especially one tied to a mobile phone number. As digital services become increasingly interconnected, organizations need a more comprehensive approach that can establish trust across the entire digital journey—from identity verification and authentication to device security, transaction protection,
From Open Banking to Banking-as-a-Service: What Comes Next?

Over the past decade, financial innovation has evolved from open banking, which focuses on consumer-authorized data sharing, to banking-as-a-service (BaaS), which uses application programming interfaces (APIs) to make core banking functions more modular and accessible. Open banking & Open Finance The term “Open Banking” emerged around 2016 as a policy initiative aimed at increasing competition in the retail payments sector. The United Kingdom was the first country to explore this approach as a regulatory tool for promoting greater competition in digital payments through the Open Banking Implementation Entity. The idea behind these initiatives was straightforward: by making it easier for third-party providers (TPPs) to access data, regulators could lower barriers to entry, encourage competition, and create more opportunities for innovation in digital payments. A similar approach was taken by the European Union through the Second Payment Services Directive (PSD2), which came into effect in 2018. PSD2 required banks to provide registered third-party providers with access to customer account data through standardized application programming interfaces (APIs). Open Finance takes this concept a step further. While Open Banking mainly focuses on banking and payment data, Open Finance covers a much broader range of financial products and services, including credit, investments, pensions, and insurance. Under an Open Finance model, consumers can give third parties access to a broader set of financial data, potentially providing a more complete picture of their financial lives. While the potential benefits of Open Finance have not yet been fully demonstrated in practice and evidence of its impact remains limited, the concept could give consumers and businesses greater control over their financial data. By making more financial data available, Open Finance could help reduce information gaps, encourage competition, and create opportunities for more personalized financial products. These products could better reflect an individual’s financial profile, spending habits, and long-term goals. Open Finance can also make it easier for consumers to bring together and compare information from multiple providers, helping reduce complexity and make financial decisions easier. Concept of Everything-as-a-Service (XaaS) Against this backdrop, Open Banking is often seen as one of the starting points for the rise of Banking-as-a-Service (BaaS) – a new approach to financial services that brings data-driven capabilities into the way banking services are delivered. BaaS is built around the broader concept of Everything-as-a-Service (XaaS), also known as Anything-as-a-Service. XaaS refers to a wide range of cloud-based and remotely delivered services that companies can access through the Web or similar networks. The idea started with Software-as-a-Service (SaaS), where cloud providers made individual software applications available to customers. Over time, the model expanded into other services such as Infrastructure-as-a-Service (IaaS) and Communications-as-a-Service (CaaS). Eventually, the concept developed into the broader XaaS model, where businesses can access the specific services they need and pay for them on demand. In simple terms, instead of buying a software license and installing the application on individual computers, a business can subscribe to a cloud-hosted application provided by the software company. This approach gives businesses greater flexibility to switch providers while also making software maintenance easier. APIs play a key role in making this possible. They allow different applications and software systems to communicate and work with each other. As XaaS continues to grow, opportunities are also expanding for developers to build third-party applications that connect with existing platforms. The growth of SaaS, for example, has created entire businesses around developers and companies using SaaS platforms. However, APIs and SaaS are not the same thing. APIs do not require SaaS, and they have existed long before the Internet. They can also be used in offline environments. LinkedIn is an example of the SaaS model because it delivers its platform through cloud computing and generates revenue through recurring subscription fees. Facebook, on the other hand, does not operate as a SaaS company. Although it provides data through APIs, its primary source of revenue is advertising, much like Google’s core business model. Unlike SaaS providers, these platforms do not rely on subscription fees for their core services. Bank as a Service What banks can now build with APIs follows a similar XaaS approach. Banking-as-a-Service enables banks to deliver digital banking capabilities through APIs. In other words, banking services can move beyond traditional branches and become part of mobile and web-based experiences. Banks can make their data, functions, and infrastructure available through APIs, allowing other digital platforms and businesses to integrate banking capabilities into their own services. From the customer’s perspective, this can lead to very different types of digital experiences. A bank may continue to interact directly with customers, or it may operate behind the scenes as a white-label service provider. In either case, customers no longer have to interact with their bank in the traditional way. Instead, APIs allow consumers to interact with companies that may not be banks themselves, while still being seamlessly connected to regulated financial institutions through digital interfaces. While Open Banking has opened the door to greater data sharing, its role as a data-sharing mechanism can still have limitations. BaaS, meanwhile, can act as a catalyst for creating more seamless and integrated financial services in the digital economy. This model allows banks to move toward more customer-centric, platform-based business models. For traditional banks, this may also mean rethinking and restructuring how they operate. In many ways, the future of financial institutions could increasingly resemble the broader XaaS model. Making this transition possible requires a connected and collaborative ecosystem, where integration is at the core and APIs become a key enabler. Savyint provides a comprehensive Open Banking and BaaS ecosystem, backed by more than 20 years of experience in the Banking and Financial Services sector, with successful deployments for leading banks and major organizations across Vietnam and Southeast Asia (SEA). Contact us to start your banking digital transformation journey today HERE! Source: From open banking to banking-as-a-service – Nydia Remolin
Global Financial Fraud in Recent Years: Alarming Figures

Financial fraud targeting financial activities is becoming increasingly complex and sophisticated. The use of artificial intelligence (AI) by criminals, together with the widespread standardization and replication of malware and other technologies, is acting as a major driver of fraudulent activities. Financial Fraud Is Increasing Globally In INTERPOL’s March 2026 Global Financial Fraud Threat Assessment, financial fraud ranks among the top five global crime threats, with a 54% rise in fraud-related Notices and Diffusions from 2024 to 2025. Global fraud losses climb to $442 billion. The number of INTERPOL Notices and Diffusions related to fraud increased by 54% between 2024 and 2025. The sharp increase in INTERPOL alerts reflects the growing complexity and scale of cross-border fraud. Payment fraud is increasingly taking place across multiple jurisdictions, making purely domestic control measures no longer sufficient. Payment card fraud losses worldwide dipped 1.2% to $33.41 billion in 2024, according to the Nilson Report, the leading trade publication covering the global payment card industry. This fraud was tied to global card volume of $51.920 trillion. The 2026 AFP Payments Fraud and Control Survey Report provides that payments fraud remains widespread, with 76% of organizations reporting that they experienced attempted or actual fraud in 2025. Checks remain the payment method most frequently impacted by fraud. In 2025, 58% of organizations reported check fraud, outpacing ACH fraud and wire fraud. Despite long-standing awareness of check-related risks, checks continue to present persistent vulnerabilities for many organizations managing payments fraud risk. Business Email Compromise (BEC) remains one of the most common forms of payment fraud, as criminals increasingly exploit impersonation techniques to manipulate organizational processes. A 2025 study by global technology research and consulting firm Juniper Research found that e-commerce fraud is expected to increase from $56 billion in 2025 to $131 billion by 2030, representing a 133% increase over the period. This growth is driven by the rising incidence of friendly fraud, in which legitimate transactions are fraudulently disputed. Key Financial Fraud Trends AI-powered deception AI-powered manipulation is rapidly changing people’s perception of what can be considered trustworthy. Advanced AI tools can generate “deepfakes” — including realistic voices, synthetic videos, and highly personalized text — making it easier to stage scenarios that appear completely authentic, even to generations highly familiar with digital environments. As technology advances and the digital world becomes increasingly visual, victims find it more difficult to question what they see or hear. The boundary between reality and fabrication is becoming increasingly blurred. This creates an increasingly complex and unpredictable fraud landscape. According to Koren, once again, understanding human behavior has become critically important. Fraud Is Becoming More Personalized and Persistent Between 2024 and 2025, the number of fraud incidents involving social engineering increased by 33%. This method is not only growing in scale but is also undergoing a fundamental shift in its approach. To address future forms of fraud, technological expertise alone is no longer sufficient; understanding human behavior is equally essential. One clear trend is that social engineering is no longer simply a technical attack, but has evolved into a prolonged process of influencing individuals. Whereas fraud previously often consisted of a single message, we are now seeing multi-step schemes in which trust is gradually built over days or even weeks. Criminals are increasingly using psychological tactics: they spend time learning about their victims, mimicking their language and behavior, and then gradually influencing them to make decisions that ultimately harm themselves. The Professionalization of Fraud Tools One clear emerging trend is the professionalization of fraudulent online storefronts. Scam websites have evolved significantly: they are no longer crude and poorly designed sites, but professionally built platforms with convincing e-commerce interfaces and close integration with digital marketing channels such as Facebook. Fraudsters can quickly create new stores with a trustworthy appearance within just a few hours, while flexibly adapting their visuals and messaging with remarkable sophistication. One alarming trend that Recorded Future called out is the increasing industrialization of support services and technology that allows fraudsters to maximize their effectiveness. One such popular tool allows scam operators to rewrite the code on an online retailer’s payments page and then steal, or “skim,” payment information as transactions happen in attacks called Magecart. The report points out that there were 10,500 such hacks active in 2025, leading to the compromise of over 23 million online transactions. These highly professional fraudulent commercial environments play a critical role in the constantly evolving fraud economy, targeting online shoppers through highly convincing storefront interfaces. Cross-Border and Distributed Fraud Operations We are also seeing a significant increase in cross-border fraud activities, particularly in the movement of illicit funds. Transactions are distributed across multiple countries, with participants — including both willing participants and individuals who are manipulated or unaware of the scheme — being used to break transaction flows into smaller segments, making them more difficult to trace. The recruitment of “money mules” often relies on psychological tactics involving financial pressure, social influence, and emotional manipulation. The “fraud economy” is becoming increasingly professionalized and global, while also becoming far more adaptable and resilient. Savyint Fraud Detection and Prevention Solutions With more than 20 years of experience in cybersecurity, information security, and cyber safety, particularly in the financial and banking sectors, Savyint has developed a comprehensive ecosystem of solutions for fraud detection, payment security, identity, authentication, and system access control. We leverage AI, AI agents, and the latest security standards to detect and respond to fraud, ensuring that every transaction conducted in our customers’ digital environments is protected in real time and capable of withstanding evolving and increasingly sophisticated forms of fraud over the long term. Our solution ecosystem includes: Contact us today for expert consultation HERE! Reference: https://www.helpnetsecurity.com/2026/03/18/online-fraud-victims-losses-interpol-report https://www.tietoevry.com/en/blog/2026/04/five-payment-fraud-trends-to-monitor https://www.mastercard.com/global/en/news-and-trends/stories/2026/recorded-future-annual-payment-fraud-report.html https://www.financialprofessionals.org/training-resources/resources/survey-research-economic-data/details/payments-fraud The Nilson Report
Ensuring Information Security in Electronic Transactions in Selected Countries

In the era of digital transformation, electronic transactions are becoming increasingly prevalent and have become an important foundation for commercial activities, public services, and social governance. Therefore, many countries have enacted legal regulations to protect parties involved in electronic transactions and ensure information security. 1. European Union 2. United States 3. Canada 4. Australia 5. Vietnam The laws governing electronic transactions in many countries, particularly developed economies, have become relatively comprehensive, covering legal frameworks, electronic signature/trust service regulations, personal data protection, enforcement of violations, international recognition, and clear technical standards. However, challenges remain regarding data security, personal data protection, and legal compliance, which need to be further strengthened and more rigorously developed. Reference:
Open Banking: APIs, Data, and User Consent

Open Banking is the development of a new financial ecosystem based on connections between financial institutions and businesses, supported by APIs. Financial institutions are enabling third parties to integrate services, provide access to banking data, and deliver entire banking services through APIs. So how can APIs, data, and user consent be managed and protected? Key Characteristics of Open Banking Open Banking focuses on serving consumers, with API or SDK technology as its core foundation and operates within the financial ecosystem. Open Banking has three key characteristics: data portability, customer autonomy, and recipient accountability. The International Organization for Standardization (ISO) defines data portability as “the ability to easily transfer data from one system to another without having to re-enter the data.” Based on this definition, in Open Banking, consumers can share their relevant banking data with third-party providers (TPPs), in line with “data portability.” Data portability in Open Banking is supported by standardized and interoperable data technologies, primarily APIs. This is a fundamental principle of liberal democracy, in which marketers are permitted to influence customers but must respect their autonomy. Open Banking empowers customers to control the sharing of their banking data, and this right is supported by customers’ legal rights to share data through Open Banking. Open Banking requires recipients of customers’ banking data (TPPs) to be accountable to customers. Therefore, Fintech companies receiving banking data must be responsible for protecting this data from leakage, theft,… This is why strict management of TPPs through a regulatory system is very important. In summary, these three characteristics of Open Banking all reflect the goal of improving competitiveness, promoting innovation, and strengthening consumer protection. Solutions for Managing APIs, Data, and User Consent With many years of experience in developing security solutions as well as specialized solutions for the Financial – Banking sector, Savyint has developed an Open Banking Tech Stack solution that enables banks to comply with the current legal regulations of each country (such as EU PSD2/3, Philippines AFASA, BSP Circular No. 1213 – 1215, Vietnam Circular No. 64, Circular No. 50, Circular No. 77…), ensuring end-to-end security across API protection, payment, data sharing, and consent management operations. In particular, the solution is flexibly designed by Savyint according to scale, prioritizing the use of existing security infrastructure: small banks can deploy it in a simple and lightweight manner; large banks can scale up to a highly redundant model, ensuring continuous and stable operations even in the event of incidents. Contact us now for consultation HERE!
Detecting and Preventing Real-Time Deepfake Impersonation

If you are concerned about the growing threat of deepfakes, you are not alone. The spread of deepfakes is closely tied to the question of what is real and what is fake, as well as the growing erosion of digital trust. So, what exactly are deepfakes, and how can we detect and prevent them? Let’s explore these questions in today’s article. 1. What Are Deepfakes? Deepfakes are highly realistic forms of synthetic media, typically in the form of video or audio, created using AI to manipulate or fabricate content, making viewers believe that someone said or did something they never actually said or did. As a result, deepfakes are increasingly being used to facilitate financial fraud, undermine user trust, and create risks for legal systems. However, like many other AI technologies, deepfakes also have positive applications, including online education, digital content creation, and enhanced film production. Nevertheless, the risks associated with deepfakes are increasingly beginning to outweigh their potential benefits. 2. How to Detect Deepfakes Deepfakes affect users in three primary ways: by manipulating personal data or images; deceiving viewers into believing that fake content is real; and causing genuine content to be mistakenly identified as fake. So, how can we determine whether content is a deepfake? Below are four key techniques that can help. 2.1 Manual Inspection Using the Naked Eye 2.2 Contextual Checks 2.3 Technical Detection Tools The rapid development of AI technology is making the detection and prevention of deepfakes increasingly challenging. To mitigate and prevent these threats, technology providers, users, and regulators must work together. From a technology perspective, capabilities such as Blockchain-based content provenance and verification need to be strengthened to help establish the origin and integrity of digital content. Users need to develop stronger media literacy, verify content before sharing it or carrying out requested transactions, and report suspicious content. Finally, regulators need to strengthen platform policies and enforcement mechanisms, establish proactive content moderation systems, clearly label deepfake and AI-generated content, introduce effective deterrents against the malicious use of deepfakes, mandate greater transparency for AI-generated content, and work toward global standards for digital integrity. By bringing these efforts together, we have a real opportunity to restore digital trust and give users greater confidence and security in the online environment. Contact SAVYINT’s experts today for consultation on digital fraud detection solutions HERE.
Singapore’s Singpass Introduces Passkeys to Strengthen National Digital Identity

The Government Technology Agency of Singapore (GovTech Singapore) announced the rollout passkey on Jun 30, 2026 as a new login method for Singpass, Singapore’s national digital identity platform. Singpass is every Singapore resident’s trusted digital identity to prove who we are when performing everyday transactions like checking our CPF balance, booking medical appointments, renewing insurance and more. Access over 2,700 services across 800 government agencies and businesses, simply by authenticating with your biometrics or SMS Two-Factor Authentication (2FA). Created by GovTech as a key enabler of Singapore’s digital economy, Singpass facilitates over 41 million transactions every month. Out of 5 million Singpass users, more than 4.2 million people use the Singpass app to easily log in to services, prove their identity over counters, digitally sign documents and do more on the go. Passkeys add to existing authentication methods such as QR login, Face Verification, and SMS One-Time Passwords (OTPs). Passkeys are a secure, password-free way to log in to services with Singpass. They are phishing resistant and use device-based authentication such as facial recognition, fingerprint, or app passcode to verify your identity. If a device is lost or stolen, the Singpass app and passkey on it will be automatically deactivated when the user sets up Singpass on another device. What is a Passkey? A passkey is a cryptographic key designed to replace passwords. As old passwords could easily be stolen, hacked, or even guessed, passkeys would work on a completely different level, with public-private key pairs authentication. Unlike a password, passkeys cannot be shared, remembered, or written down. This makes it far less vulnerable to the types of attacks that commonly target password-based systems. While early biometric authentication technologies laid the foundation for identity verification, the journey toward passkeys began in 2012 with the establishment of the FIDO Alliance, with the mission of eliminating passwords. The passkey revolution began in 2021, when major technology companies adopted the FIDO2 and WebAuthn standards, enabling passwordless authentication. Today, passkeys have become an authentication method accessible to billions of users worldwide. A significant milestone in the evolution of passkeys was the National Institute of Standards and Technology (NIST) formally recognizing synced passkeys in its supplement to the SP 800-63B guidelines. NIST SP 800-63B Supplement This recognition highlights the phishing-resistant nature of passkeys, while demonstrating their potential to replace traditional passwords with a more secure, convenient, and user-friendly authentication method. With NIST’s recognition, passkeys are well positioned for widespread adoption, particularly in highly regulated industries such as banking and healthcare. This is expected to drive the next phase of secure digital identity verification. The Difference Between Passkeys and Passwords Types of Passkeys There are two main types of passkeys, designed for different use cases and, more importantly, different security requirements. Within the digital security ecosystem, the two primary categories are Multi-Device Passkeys and Device-Bound Passkeys. Let’s explore the differences between them. Multi-Device Passkeys Multi-Device Passkeys, also known as Synced Passkeys, are well suited for personal use. They can be seamlessly synchronized across multiple devices, such as smartphones, tablets, and laptops, provided those devices are linked to an Apple, Google, or Microsoft account. This flexibility allows users to access their accounts from any trusted device without having to remember or enter a password. Device-Bound Passkeys In contrast, Device-Bound Passkeys can be viewed as a “security shield” for enterprise environments. Because they are bound to a single device and cannot be copied, this type of passkey provides an additional layer of security that is particularly valuable for organizations with strict data protection and access control requirements. In other words, Multi-Device Passkeys prioritize convenience and flexibility, while Device-Bound Passkeys prioritize stronger control and security. Benefits of Passkeys Benefits for Users Benefits for Developers As these technologies continue to evolve, more people are asking: What is a passkey, and how does it work? Growing interest in passkeys is encouraging technology innovators to invest significant resources in researching, developing, and advancing this technology. Passkeys are set to bring profound changes to security and digital identity while shaping how future generations interact with the digital world. Reference source: https://www.passkeys.com/ Contact us HERE to explore Savyint’s most advanced and secure solutions for authentication and digital identity.
SAVYINT Develops Open Banking Tech Stack – Enabling Secure, Flexible, and Compliant Open Banking Connectivity

Savyint Open Banking Tech Stack enables banks to build and operate an Open Banking ecosystem on a unified architecture, covering TPP management, API management and delivery, consent management, data sharing, and payment initiation. Open Banking is becoming a key pillar of digital transformation strategies across Vietnam’s banking and financial services sector. Through open API, banks can connect with Third-Party Provider (TPP), FinTech, and digital platforms to provide services such as account information access, financial data sharing, and payment initiation. In this context, API serves as the key bridge connecting banks with the broader ecosystem. However, API connectivity also means that banks must extend their security controls beyond internal systems to encompass multiple partners, applications, and users. Every API transaction must be authenticated, access-controlled, and protected to ensure data integrity. At the same time, regulations governing open API deployment, cybersecurity, data protection, and related requirements have been introduced across many countries, including Singapore and Vietnam (Circular No. 64, Circular No. 50, Circular No. 77…), as well as the Philippines (AFASA and BSP Circular Nos. 1213–1215) … Compliance with these requirements has become a critical priority for banks. Banks must not only secure APIs but also protect cryptographic key, authentication information, signature, and evidence associated with data exchange and transaction processing. They must also maintain activity logs, detect anomalous access, and ensure that all operations are traceable for auditing purposes. Therefore, one of the key challenges facing banks today is how to leverage existing infrastructure while integrating the missing capabilities into a unified, comprehensive, scalable Open Banking architecture that can strictly comply with applicable regulations. SAVYINT’s Implementation Solution With extensive expertise in Open Banking, Open Finance, and payment security, Savyint provides a comprehensive HSM-powered Open Banking Tech Stack that enables banks to comply with applicable regulations while strengthening security across API protection, payment processing, data sharing and consent management. SAVYINT’s Open Banking Tech Stack is designed on a Microservices architecture, allowing banks to deploy capabilities in phases, leverage existing systems, and easily expand their Open Banking services in the future. With Savyint Open Banking Tech Stack, banks can build a centralized Open Banking ecosystem where data, consent, and transactions are managed end-to-end on a unified platform. This enables seamless connectivity with FinTech, ecosystem expansion, and the development of new digital financial services, while supporting full compliance with applicable regulations across markets governing open API, data security, and payment transactions.
SAVYINT Provides Core Electronic Transaction Authentication Platform for LPBank

Overview – Industry: Banking & Financial Services – Customer: LPBank – Project: Deployment of SmartOTP for LPBank’s retail customers and internal users SAVYINT successfully provided the core electronic transaction authentication platform (SmartOTP) for LPBank, enabling secure, convenient, and seamless transaction authentication directly within the bank’s digital banking application. The solution strengthens security for both financial and non-financial transactions, reduces reliance on SMS OTP, and supports LPBank in meeting the requirements of Circular No. 50/2024/TT-NHNN and Circular No. 77/2025/TT-NHNN issued by the State Bank of Vietnam. LPBank’s Need for Enhanced Authentication Security in Digital Banking Established in 2008, LPBank has built an extensive network across 34 provinces and cities and is one of the 14 banks classified among the credit institutions of systemic importance within Vietnam’s banking system. Amid growing risks related to impersonation, credential theft, and transaction fraud, as well as the regulatory requirements under Circular No. 50/2024/TT-NHNN and Circular No. 77/2025/TT-NHNN on strengthening security and safety in the provision of online banking services, LPBank – with more than 5 million individual customers using digital banking services – required an authentication solution that complies with State Bank of Vietnam (SBV) regulations and can operate at scale while ensuring strong security, ease of use, and flexible integration with its existing digital banking infrastructure. At the same time, LPBank needed to strengthen the centralized administration and operation of its authentication system. Activities such as service activation, SmartOTP status management, exception handling, authentication history lookup, and transaction monitoring needed to be managed centrally, transparently, and with full traceability. To address these requirements, LPBank selected SAVYINT SmartOTP as its core transaction authentication platform, working with SAVIS as the integration and implementation partner to integrate the solution into its digital banking ecosystem. This enables LPBank to progressively reduce its reliance on traditional SMS OTP while establishing a secure and scalable authentication foundation aligned with its long-term digital banking strategy. The SAVYINT Solution With extensive experience in authentication and security solutions for the Banking & Financial Services sector, SAVYINT provides SmartOTP as the core technology platform for electronic transaction authentication, comprising the following key components: 1. SmartOTP SDK Integrated Directly into the Mobile Banking Application The SmartOTP SDK is integrated directly into the LPBank Plus mobile banking application. Through the SDK, the Mobile Banking application can invoke SmartOTP functions at authentication checkpoints throughout the customer transaction journey. Customers can activate SmartOTP, use biometric authentication where supported, authenticate transactions, and manage their SmartOTP settings directly within the LPBank Plus application. This enables a fast, convenient, and seamless authentication experience while strengthening the bank’s ability to manage transaction risks across its mobile banking channel. 2. Admin Portal for Centralized Administration and Operations The Admin Portal provides bank staff with centralized capabilities to monitor customers’ SmartOTP status, retrieve authentication information, review OTP transaction history, and handle operational incidents. The Admin Portal enables centralized management of SmartOTP-related operations, including: The platform also supports monitoring, investigation, and traceability when required, helping strengthen risk management capabilities and maintain transparency throughout system operations. Deployment Roadmap The project was implemented in phases: Key Use Cases SmartOTP Activation and Service Management Transaction Authentication with SmartOTP PIN Management and Security Controls Administration and Operations through the Admin Portal Monitoring, Logging, and Traceability Helping LPBank Strengthen Transaction Security and Customer Experience While Meeting the Requirements of Circular No. 50/2024/TT-NHNN and Circular No. 77/2025/TT-NHNN Officially going live in June 2026, SmartOTP enables LPBank customers to authenticate transactions directly within the Mobile Banking application, delivering a faster, more convenient, and seamless authentication experience. For LPBank, the solution strengthens transaction risk management, reduces reliance on SMS OTP, enables centralized administration through the Admin Portal, and provides a scalable foundation for more advanced authentication requirements in the future. The function-based SDK integration model also enables flexible integration, easier maintenance, and long-term alignment with the bank’s digital banking ecosystem. At the same time, LPBank has met the requirements under Circular No. 50/2024/TT-NHNN and Circular No. 77/2025/TT-NHNN issued by the State Bank of Vietnam, with the solution applied consistently to individual customers. This provides an important foundation for LPBank to strengthen Digital Trust, protect transactions, and enhance the customer experience throughout its digital banking journey.