CERT SL issues warning on OTP SMS's

CERT SL issues high level warning on One Time Password (OTP) messages

by Staff Writer 09-05-2020 | 3:31 PM
The Sri Lanka Computer Emergency Readiness Team (SL CERT) has issued a high threat level warning regarding One Time Password (OTP) messages. CERT warns that if you receive your OTP from a local private number, instead of from your service provider, it would mean that the message has come through an unauthorized third party who has access to your OTP messages. CERT further added that the unauthorized third party would normally change the content slightly, except the OTP code, and send it to the user through a private number. For example:   CERT warns that this could result in the loss of access to online bank accounts, social media accounts, email, and even financial losses. Possible safeguards suggested by CERT includes using an authentication application developed by service providers instead of an OTP SMS and requesting a voice call of the OTP instead of an SMS. CERT also urges users to change their password immediately and to set proper account recovery options, if they receive an OTP message through a private number.