Your Pakistani Card Can Be Charged Without an OTP. Who Protects You When It Happens?
I was scrolling through LinkedIn when a UBL advertisement stopped me.
“Don’t Let a Search Lead to a Scam,” it warned. UBL was telling customers not to trust telephone numbers found casually through an internet search. A fraudster can publish a fake number, answer the call and pretend to represent the bank.
Sensible advice.
But I looked at the advertisement and thought about something banks discuss far less often.
What happens when I protect my OTP and nobody asks me for one?
I have used Pakistani cards on international websites where the payment process felt reassuring. I entered my card details, received an OTP and completed the transaction.
But international online payments do not always work that way.
Sometimes there is no OTP.
That raises a question every Pakistani debit and credit card user should understand: if my bank approves an international online transaction without asking me to confirm it, what exactly protected that decision?
And if the protection fails, who bears the loss?
What an OTP Actually Protects
First, we need to clear up one common misunderstanding.
When you shop online, a legitimate merchant normally asks for your card number and expiry date, together with the CVV or CVC printed on the card.
It should not ask for the PIN you use at an ATM.
Never enter your ATM PIN on an ordinary shopping website.
An online purchase is generally a card-not-present transaction, often called CNP. You are not physically presenting your card to the merchant.
This creates a different fraud risk from paying at a shop.
Many Pakistani consumers have therefore learned a simple security rule:
No OTP, no payment.
Unfortunately, it is not that simple.
An OTP is one way of confirming the cardholder's identity. It is not the entire security system.
The more important technology is 3-D Secure, or 3DS.
Visa calls its EMV 3-D Secure programme Visa Secure. Under 3DS, information can pass between the merchant and the bank that issued your card before authorization. The issuer then assesses whether the person attempting the purchase is likely to be the genuine cardholder.
Sometimes the bank challenges the customer.
You may receive an OTP. The bank could instead use another approved authentication method.
But modern 3DS can also operate through what Visa calls a frictionless flow. The issuing bank assesses transaction data and authenticates a low-risk transaction in the background without requiring the customer to do anything.
So one point is crucial:
No OTP does not automatically mean no 3-D Secure.
But the opposite assumption would also be dangerous.
A customer should not assume that every transaction completed without an OTP received the same level of protection.
Pakistan Already Has Rules for Online Card Security
I initially wondered whether SBP should simply require Pakistani banks to introduce 3-D Secure for international transactions.
Then I checked the regulations.
SBP has already acted.
In its 2018 security instructions for digital payments, SBP told banks and microfinance banks to enable the EMVCo 3-D Secure protocol to prevent fraud in online transactions. It required them to prepare implementation plans for all applicable card payments.
By February 2021, SBP said 15 banks had already adopted 3-D Secure. SBP also allowed banks that had implemented the technology to activate customers' cards for online e-commerce without requiring customers to request activation first.
Pakistan therefore does have a regulatory foundation for safer e-commerce.
That changes the argument.
The problem is not simply:
“Why hasn't SBP introduced 3-D Secure?”
It has.
The more useful consumer question is:
What protection applies when an international card-not-present transaction reaches my Pakistani bank and I am not actively asked to authenticate it?
That question deserves a clear answer from every card issuer.
Why Some International Payments Don't Ask for an OTP
Suppose I buy software from an overseas company.
I enter my card number and expiry date, followed by the CVV. I click Pay.
The payment succeeds.
My phone never receives an OTP.
Was the transaction insecure?
Not necessarily.
Visa explains that modern 3DS uses risk-based authentication. The issuer can evaluate information associated with the transaction and decide that the risk is low enough to authenticate it without further customer involvement.
Visa calls this the frictionless flow. If the transaction appears riskier, the issuer can require a challenge, such as an OTP or another authentication method.
This distinction matters because consumers see only the checkout screen.
The bank sees much more.
Still, not every transaction necessarily follows an ordinary customer-challenge path. Payment systems must also handle stored credentials and subsequent payments. Other payment arrangements can affect how authentication occurs.
A customer therefore cannot look at the absence of an OTP and determine exactly what happened behind the scenes.
That is part of the consumer-protection problem.
Imagine Someone Gets Your Card Details
Consider Ahmed, a Pakistani credit-card customer.
Ahmed sometimes uses his card for international software subscriptions. One day, criminals obtain his card number and expiry date, along with the CVV.
They do not have his ATM PIN.
They do not control his banking app.
Now they attempt a $150 purchase at an overseas merchant.
Two very different experiences can follow.
When Ahmed is challenged
The merchant sends the payment through its payment infrastructure. Authentication takes place through 3DS, and Ahmed's issuing bank decides that additional verification is required.
Ahmed receives a challenge.
He did not initiate the transaction, so he does n

Comments
Post a Comment
Please keep discussions respectful and on-topic