Making your digibank online login more resistant to phishing scams

DBS/POSB continues to strengthen our multi-layered defence against scams and fraud, so you can bank safely with peace of mind. As part of an industry-wide effort to step up protection against phishing scams, we will be strengthening the authentication process for digibank online logins.

Starting 29 July 2024, digital token users will need to authenticate their digibank online account login using their digital token. They can no longer use One-Time Passwords (OTPs) sent by text messages (SMS) or generated via the Digital Token.

Why We Are Doing This

While OTP was introduced as a multi-factor authentication option, scammers are increasingly using fake websites or social engineering to phish for customers’ OTP. In many cases, scammers use fake websites or text messages to deceive victims into providing their OTPs, which then enable them to access the victims’ accounts.

This new measure strengthens the authentication process, making it harder for scammers to fraudulently access a customer's account(s) and funds without physical access to their mobile device, adding a layer of protection against phishing scams.

To strengthen protection against phishing scams, banks in Singapore, in consultation with MAS, will progressively remove SMS One-Time Password (OTP) and Digital Token OTP as options for Digital Token users to perform multi-factor authentication (MFA) when logging in to their banking account(s).

If you’re a digital token user logging into digibank online
  • When logging in, a push notification will be sent to your phone. Tap on it. Or you can open digibank mobile and tap on the ‘Digital Token’ icon
  • Select Approve to confirm that you’re logging in.

If you're currently using the Digital Token or physical token to log in to your digibank mobile app, this change will not impact you.

For a smoother experience, we recommend that you allow digibank mobile to send you push notifications.

laptop
slider
slider
slider
1
Step 1
Log in to digibank online with your User ID & PIN.
2
Step 2
On your screen, select Authenticate now.
3
Step 3
Follow the instructions on the screen and complete the authentication process as shown in the Authentication via digibank mobile tab.
phone frame
slider
slider
slider
1
Step 1a
Go to your mobile device and either tap on the notification.
2
Step 1b
Or go to your digibank mobile and tap on Digital Token.
3
Step 2
Tap on Approve to complete the login.
Get the latest DBS digibank mobile app now!

Frequently Asked Questions

To enhance your security, digital token users can only use their digital token to authenticate their login to digibank online instead of SMS and Digital Token-generated One-Time Passwords (OTPs).
Login to your digibank mobile will not be affected. If you are a digital token user, digibank mobile login will continue with the digital token registered on your device.
To receive push notifications, ensure that your mobile device is connected to the Internet and you have turned on push notifications for your digibank mobile. Learn more on how to enable Push notifications for your Digital Token.

Alternatively, if you did not see the push notification, you may trigger the login authentication by tapping on the digital token icon in your digibank mobile.
This change will only impact digital token users logging into digibank online. Should there be any updates regarding other banking transactions in the future, we will keep you informed.

We encourage all customers to always remain vigilant. Never disclose your banking credentials or sensitive information such as your user ID, PIN or OTPs to anyone under any circumstances.
Was this information useful?

We welcome your feedback

Information is easy to understand and find
Information is useful to answer your inquiries completely
Let's bank safely together
Explore our Bank Safely Hub to learn the latest scam alerts and tips on how to protect yourself.