
Field Notes from the Philippines - Volume 5
Jasmine Paras is Bytecenture's Philippines-based payment UX researcher. This is the fifth in a series of Field Notes from our in-market researchers across ten countries.
If you run a financial app in the Philippines and you fall inside BSP Circular No. 1213's coverage, 25 June 2026 changed your product.
Until that date, an institution facing a fraud claim could point at the transaction log and say the customer entered the one-time password themselves. BSP General Counsel Roberto Figueroa has since said that with the deadline passed, a bank can no longer claim the fault lies with the client where the institution itself failed to comply, and that the consequence can include restitution of the full amount lost.
Two qualifications matter before anyone builds a strategy on that. Circular 1213 does not make OTPs illegal, and it does not reach every app in the country. It requires covered institutions to limit interceptable authentication mechanisms, and its stronger obligations are aimed at BSP-supervised institutions offering complex electronic products and averaging more than P75 million in online transactions per month over the preceding six months. Restitution follows a failure of adequate controls or required diligence, not the mere presence of an SMS somewhere in a system.
With that scoping in place, this is a piece about regulation that lands almost entirely on screens somebody has to build.
The problem the government is responding to
The Philippine fraud profile is unusual: high exposure, comparatively low median loss.
TransUnion's 2025 data put the country's suspected digital fraud rate at 4.1% against a global 3.8%, the sixth consecutive year above the global level. Note what that metric is: a proprietary transaction-risk measure, not a national crime incidence rate. Between August and December 2025, 72% of surveyed Filipino consumers reported being targeted through online platforms, email, calls or texts, against 53% globally. The median self-reported loss was roughly USD 850, about P50,000, against a global median of USD 1,671, about P98,000. TransUnion's own framing is that Philippine fraud is driven more by scale than by severity.
Separately, at an April 2026 media session, BSP Consumer Protection and Market Conduct Office Director Rochelle Tomas cited a 2025 survey finding that 77% of Filipinos said they had been scammed, 30% lost money, and 74% did not report it. The underlying survey, its sampling frame and its wording are not identified in the public report, so treat those as attributed survey figures rather than a documented BSP statistical series.
The composition matters more than the totals. Reporting citing BSP data for 2025 attributes 76% of fraud losses to social engineering, account takeover and identity theft together, 13% to hacking, and 8% to card-not-present fraud. Deputy Governor Lyn Javier has described the shift as cyber risk moving from technical vulnerabilities toward schemes that exploit the human element.
That 76% should be read carefully. It means human-focused and credential-centered fraud dominates losses. It does not mean three quarters of the money was voluntarily authorized by a persuaded victim, because account takeover and identity theft can both occur without the account holder doing anything at all.
What the government tried first, and what it actually achieved
The SIM Registration Act, Republic Act No. 11934, was approved on 10 October 2022. Every SIM must be registered to an identified user before activation, with full name, date of birth, sex, address and a government-issued photo ID. Existing SIMs were subject to their own registration and deactivation transition. Spoofing a registered SIM carries at least six years' imprisonment, a P200,000 fine, or both.
The theory was that scams ran on anonymity. Remove the anonymity, remove the scams.
The honest verdict is partial effectiveness followed by displacement, not failure. By March 2023 officials reported text-scam complaints falling from roughly 1,500 a day to about 100, and the DICT later said observed scam-text volumes had dropped substantially. What did not happen is the elimination of the underlying activity. Five things went wrong.
| What went wrong | The evidence |
| Registration was forgeable | At a Senate inquiry on 5 September 2023, the NBI demonstrated a SIM registered using a fake ID bearing a photograph of a monkey |
| Real identities were stolen to register SIMs | DICT Secretary Ivan Uy described criminals harvesting identities from social media and using fake or fraudulently obtained genuine IDs; seized SIMs were reported as registered under real people's identities |
| The attack moved off SMS | DICT reported migration to Viber, Telegram and Messenger, which sit outside the law. The NTC later said publicly that RA 11934 was not a silver bullet against messaging scams |
| The compliance campaign supplied a pretext | In May 2023 the DICT warned that scammers had reprogrammed their approach around SIM-registration prompts and fake registration links |
| The infrastructure survived | Police continued arresting sellers of registered SIMs, and Globe documented black-market mule SIMs and sender-ID spoofing via rogue IMSI catchers |
Two of those explain why the approach was aimed at the wrong thing.
The data driving the attack was probably not coming from the SIM. The scam texts that alarmed everyone in 2022 were the ones using recipients' real names. The National Privacy Commission's preliminary investigation suggested those names were being scraped or harvested from payment and messaging applications, and said a large breach looked unlikely at the time, without ruling one out. Registering the sending SIM does nothing about a harvested contact database on the other side of the attack.
Making a compliance deadline universal gave scammers a credible new pretext. Every Filipino was told, officially, to expect messages about registering their SIM or losing service. There is direct evidence that criminals exploited that. What the evidence does not establish is the stronger counterfactual, that those campaigns would not have found another pretext, or that the policy produced a net increase in victimization.
The transferable lesson is narrow. Identity verification at the SIM layer provides attribution and enforcement value, but it does not stop an attack whose mechanism is persuasion. A scammer with a properly registered SIM is still a scammer.
What it is doing now

The Anti-Financial Account Scamming Act, Republic Act No. 12010, was approved on 20 July 2024. Rather than trying to make fraud harder to commit, it makes inadequate controls more expensive to keep.
| What AFASA does | Detail |
| Covers e-wallets, not just banks | "Financial account" expressly includes an e-wallet, and the Act reaches banks, non-banks and BSP-regulated payment and financial service providers |
| Sets a restitution standard | An institution can owe restitution where it lacked adequate risk-management systems and controls, failed to exercise the required degree of diligence, or failed its temporary-holding obligations |
| Gives compliant institutions a shield | Institutions found compliant with the prescribed standards are not liable for losses from covered offenses, subject to the Act's conditions |
| Criminalizes the supply chain | Money muling, and the sale, rental or use of financial accounts in fraudulent activity, are offenses in their own right |
| Authorizes temporary holds | Disputed funds may be held temporarily, with coordinated verification, subject to defined procedures and time limits |
| Creates a dedicated BSP office | Circular 1214 designates the Consumer Account Protection Office to inquire into suspect financial accounts under AFASA and coordinate with authorities |
Two things are commonly misattributed to AFASA, and both matter if you are writing a compliance memo.
CAPO is not a general scam-complaint desk. It is the AFASA account-inquiry and coordination office. Ordinary consumer complaints still run through the BSP's consumer assistance process.
The P10 million adjudication threshold is not an AFASA provision. It comes from Republic Act No. 11765, the Financial Products and Services Consumer Protection Act of 2022, which lets the BSP and SEC adjudicate qualifying purely civil claims where the relief sought is solely payment or reimbursement of not more than P10 million. Those decisions remain reviewable by certiorari, so it is not a replacement for the courts.
BSP Circulars 1213, 1214 and 1215 of 2025 implement AFASA. Circular 1213 gave covered institutions one year from effectivity, which the BSP has identified as 25 June 2026. Circular 1215 carries its own transitory provisions for industry protocols, so a single blanket date oversimplifies the rollout.
How this lands on a banking app

Circular 1213 is risk- and scope-sensitive rather than a screen-by-screen specification. It regulates security properties and control outcomes. The table below separates what the circular requires from what a team might build to satisfy it, because conflating the two is how compliance memos go wrong.
| Product surface | What the circular requires | Common implementation |
| Authentication | Limit interceptable mechanisms, including SMS and email OTP, and use stronger authentication commensurate with transaction and institutional risk | Passkeys, FIDO or server-side biometrics with device binding. These are recognized approaches, not the only mandated one |
| Adding a payee | Controls to verify recipient identity; enrollment of fund-transfer recipients is a notifiable event | Risk-assessed step-up authentication on recipient enrollment |
| Changing a registered number | A 24-hour Transaction Pause Period after specified key-account changes, including mobile, email and device changes. The pause may be shortened, or replaced with restrictions and limits, where strong authentication and institutional accountability conditions are met | A degraded account state with its own UI, messaging and support script, plus the qualified alternative path |
| Device policy | Restrict installation of mobile applications on devices assessed as unsecured, including rooted, jailbroken, outdated systems and emulators | Attestation checks at install, plus a support path for the long tail of old Android handsets |
| Device signals | Device-related signals in fraud controls, and logging of authentication mode and device fingerprint information | Client-side signal collection with a privacy notice that survives NPC scrutiny |
| Notifications | Real-time notification of specified account and transaction events, deliverable through mobile apps, messaging apps, email or SMS | Push and an in-app inbox reduce phishing exposure, but they are not the only compliant channel |
| Messaging | Prohibition on clickable links and QR codes sent through email, instant messaging and SMS, with express exceptions, including where prompted by prior customer action, where merely informational, or where the link does not lead to a site requesting sensitive or login data | Notification-to-action journeys rebuilt around in-app deep flows for the non-exempt cases |
| Fraud monitoring | Automated, real-time fraud management, covering behavioral anomalies, velocity, geolocation, account and device changes and blacklist signals, with enhanced requirements for institutions meeting the complex-product and high-aggregate-value criteria | A live FMS rather than a batch job, scoped to whether your entity crosses the threshold |
| Disputes | Temporary holding of disputed funds and participation in coordinated verification, subject to covered transfer types and defined periods | An in-app dispute flow, a time-bounded hold capability, and back-office integration |
Four of them are harder than they look.
The OTP limit is not about user error. An SMS OTP has to leave your systems and cross a network you do not control. NIST treats PSTN out-of-band authentication as restricted, citing SIM and number reassignment and interception risk, and holds that manually entered one-time codes are not phishing-resistant because an impostor can relay the output into a genuine session. Note the precise version of the argument: SIM swap and network interception bypass the customer entirely, while phishing and vishing can sometimes be defeated by a vigilant user. The regulatory point is that authentication should not depend on that vigilance.
Vishing, not smishing. Criminals do call victims and ask them to read out a code, and the BSP and NPC have both warned about it. The term for that is vishing. Smishing is the SMS variant.
The 24-hour pause is a default, not a lock. It is a new account state you have to design, but the circular permits a shortened pause or substituted restrictions where strong authentication and accountability conditions are satisfied. Building the absolute version costs you conversion you did not have to give up.
Your authentication design is now evidence. AFASA liability turns on the adequacy of controls, and Circular 1213 mandates extensive logging including authentication mode and device information. Those logs are expressly required. Risk assessments, vendor due diligence and internal audit material are prudent governance evidence rather than an enumerated statutory checklist, and it is worth keeping the two categories separate in your own documentation.
One requirement that has been widely reported but should not be attributed to Circular 1213: in March 2026 the BSP was reported to be circulating a draft memorandum on server-side biometric authentication that addressed accessibility for elderly users with worn or damaged fingerprints and for persons with disabilities. That is a sensible design concern and may well become binding, but until a final issuance is published it is a proposed standard, not a rule in force.
The tension nobody has resolved
Every control above adds friction, in a market whose two dominant wallets won on the absence of it.
Accessibility is the sharp edge. Any authentication system needs an alternative for users who cannot use the primary authenticator, and NIST requires alternatives in the relevant contexts. If your fallback degrades to an SMS code whenever biometrics fail, you have rebuilt the interceptable channel and kept the compliance cost. That is a product-security problem worth solving on its own terms, whether or not a Philippine circular eventually mandates it.
Scammers have already adapted to the visible half of the regime. Reporting citing PLDT-Smart describes smishing using deliberately broken links, with characters substituted for dots and instructions to repair the address manually, or numeric strings resembling addresses, both intended to evade automated blocking. Take that as reported rather than as a primary telco advisory, but the broader pattern of link obfuscation and sender-ID spoofing is well documented by Philippine telcos.
Is any of it working?
The available evidence is cautiously positive, with one large caveat.
At a Senate budget briefing in September 2026, BSP officials cited PNP Anti-Cybercrime Group figures of 527 AFASA-related cases in 2025, of which 447 were solved or cleared, and reported a decline in online scam incidents in the first half of 2026, partly attributed to greater public awareness. Earlier, in July, Figueroa said the PNP had filed more than 500 cases under AFASA, with CAPO coordinating and acting as a subject-matter resource. Those are enforcement-case counts, not a tally of victim complaints received by the BSP.
Set them against the 74% non-reporting figure. Case counts measure what entered the system, not what happened.
For a product team the consequence is practical: complaint volume substantially understates victimization and should not be treated as a fraud-incidence measure. In-app reporting that takes under a minute is worth more here than in most markets, because the default behavior is silence.
What is still open
| Question | Why it matters to your roadmap |
| What counts as adequate? | AFASA deliberately uses an adequacy and diligence standard. Published BSP adjudications or court review will clarify how it applies; until then teams are specifying against a standard with little public precedent |
| Do the fallbacks hold? | Removing the interceptable channel from the primary path does nothing if the alternative path restores it. Whether fallbacks are hardened or merely present is the next fraud story |
| Does the accessibility standard become binding? | The March 2026 draft memorandum would put real constraints on biometric implementations. Its final form is not yet published |
| Does reporting improve? | Enforcement scales with complaints. If most victims stay silent, the machinery only ever sees what surfaces |
The bottom line
For consumers. Entering an OTP does not by itself absolve a non-compliant institution, and the burden has shifted materially. But restitution is fact-specific and depends on AFASA's statutory conditions, not on the mere fact that pressure was involved. Separately, RA 11765 already allows the BSP to adjudicate qualifying purely civil claims up to P10 million, subject to certiorari review.
For anyone building a financial app here. The Philippines spent four years addressing scams at the identity layer and the messaging layer, and losses kept migrating to whichever part of the system involved a person. The current regime accepts that and ties institutional protection to the adequacy of controls. For covered institutions and covered activities, continued exclusive reliance on interceptable authentication is no longer a defensible baseline, and the deadline for moving off it passed on 25 June 2026.
References and Sources
- Republic of the Philippines. Republic Act No. 12010: Anti-Financial Account Scamming Act. Source for covered financial accounts and institutions, money-mule and social-engineering offenses, adequate-control requirements, restitution, temporary holding, and coordinated verification. lawphil.net
- Bangko Sentral ng Pilipinas. AFASA Booklet with Implementing Rules and Regulations: Circular Nos. 1213, 1214, and 1215. Source for authentication, fraud monitoring, transaction pauses, device controls, notifications, customer security tools, transaction logging, dispute handling, and transitory provisions. bsp.gov.ph
- TransUnion Philippines. Filipinos Face Widespread Digital Fraud Exposure Despite Lower Financial Losses. Source for the 2025 suspected digital-fraud rate, consumer targeting, and median reported loss. transunion.ph
- Philippine Information Agency. BSP Shares ALERT Guide Against Scams. Source for the attributed 2025 survey figures on scam exposure, financial loss, and non-reporting. pia.gov.ph
- Republic of the Philippines. Republic Act No. 11934: SIM Registration Act. Source for SIM-registration requirements and penalties. lawphil.net
- Philippine News Agency. SIM Registration Law Vital in Curbing Text Scams. Source for the reported early reduction in daily text-scam complaints. pna.gov.ph
- Senate of the Philippines. Poe Pushes for Live Selfie Requirement for SIM Registration. Source for the NBI demonstration showing weaknesses in identity-document verification. senate.gov.ph
- Globe Telecom. Globe Warns the Public of the Growing Threat of SMS Spoofing. Source for sender-ID spoofing, rogue IMSI catchers, and black-market mule SIMs. globe.com.ph
- Republic of the Philippines. Republic Act No. 11765: Financial Products and Services Consumer Protection Act. Source for BSP and SEC adjudication of qualifying purely civil financial claims up to P10 million. lawphil.net
- National Institute of Standards and Technology. Digital Identity Guidelines: Authentication and Authenticator Management. Source for the treatment of PSTN-based out-of-band authentication, phishing resistance, and alternative authenticators. nist.gov
This article is a research summary, not legal advice. Product-specific compliance should be checked against the applicable BSP issuance, the institution's supervisory category, and the transaction date.