A malware complaint tests how UBL authentication and SBP's digital-fraud rules divide responsibility A UBL customer's malware complaint raises a difficult question under SBP's digital banking rules: does successful authentication prove that the customer authorized the transfer? A UBL customer says he opened his banking app with his fingerprint and then saw what looked like an update screen. According to his account, a malicious application had compromised his phone. His UBL digital fraud complaint began after money moved while he could not see what was happening inside the banking session. An OTP reportedly reached the same phone. The customer says the malicious software removed the SMS before he could read it, and he reported the disputed transfers about four hours later. UBL subsequently rejected his complaint after examining its records. One sentence in UBL's response stopped me. The bank said a fraudster added beneficiaries using the customer's device IDs an...
Strategic analysis on geopolitics, financial systems, and Pakistani affairs, blended with personal stories and commentary from Karachi. Written by Munaeem Jamal.