Why One-Time Passwords Are Now Full-Time Risks
Entering a one-time password is not only annoying … it’s not safe. These codes can be intercepted and open accounts up to fraud. Authenticating at the network level is the way forward.
Key Takeaways
One-time passwords do not present a good (or safe) customer experience.
Network-powered solutions offer a more secure alternative without customer involvement.
Next-gen fraud-fighting solutions bring a silent and speedy workflow that positively impacts customer journeys.
Does this sound familiar? You try logging in to buy something at your favorite brand, and the company texts you a one-time password (OTP). You never get it. The company texts you another OTP, and you don’t get that, either. The company texts you a third OTP and you bounce. Now the company has lost you as a customer.
You didn’t enjoy the experience … so why would you use OTPs with your own customers? Especially when bad actors use AI to intercept OTPs and hack into accounts. It doesn’t have to be like this. There are safer, more reliable — and less annoying — ways to verify customers and speed business along.
One-time password technology is decades old. The earliest OTP systems can be traced back to the 1960s and 1970s and were used for military purposes, according to LicenseSpring. The capabilities really took off with the vast expansion of mobile phones, and millions of temporary passwords are sent every day across SMS, email, voice calls, and other methods.
Now, several times a day, a user is bouncing back and forth between messaging programs and different apps, looking for that six-digit code, trying to remember it, hoping to enter it correctly, and wondering the whole time why we aren’t using a safer system.
What are the problems with one-time passwords?
Aside from the general user inconvenience, there are real security flaws with one-time passwords:
SIM swaps
This is where bad actors take over accounts with a SIM they control. They can then intercept the OTPs or other security codes to access financial, email, and other accounts.
Vulnerable to malware
Security researchers at Zimperium recently uncovered an Android banking trojan called Rokarolla that can read and send SMS messages, putting OTPs at risk. “The malware has the capability of exfiltrating all SMS messages from the infected device and can also send SMS on behalf of the victim, which can be used to intercept sensitive information such as bank OTPs,” the researchers wrote in a report.
Real-time phishing and OTP interception
Attackers create convincing proxy versions of legitimate login pages. Customers enter their credentials, including the OTP, and attackers use this data to access the real site before the OTP expires. This grants attackers full access, even though the customer correctly completed the multi-factor authentication.
Time-based OTP attacks
A time-based password is less prone to being intercepted. However, attackers can still access key data through:
A stolen or compromised device. Attackers can use the device’s authenticator app to complete the multi-factor authentication and gain access.
Backup codes. Most authenticator apps generate recovery codes. If these codes are insecurely stored, such as in an email or cloud backup, attackers can find the source and gain access.
Social engineering. Attackers call customers to evoke fear of potential bank fraud, which pressures customers to share their time-based OTP.
In all cases, one-time passwords use aggregated, cached, or behavioral data. These require human participation, which provides the opening for bad actors to strike. And 77% of data breaches involve compromised credentials at some point in the attack chain.
Damage starts before security fails
OTPs only hit about 80% conversion on authentication flows, meaning that 20% of legitimate users are lost in the verification process. That’s one in five customers that can’t get into your system to conduct business. This puts a burden on your help desk to recover passwords (assuming customers even go that route).
The rise and scale of AI-generated fraud
AI-powered fraud can clone real voices, generate convincing messages, and manipulate users at scale in ways that feel natural and urgent. It’s no wonder that user authentication remains one of the most exploited touchpoints in application security. Consider that:
Cybercrime costs are expected to reach $23 trillion in 2027, an increase of 175% from 2022
20% of all fraud is attributed to synthetic identity and authentication attacks with account takeover (ATO) surging 141% since 2021
More than 40% of all login attempts are driven by malicious bots
What are alternatives to one-time passwords?
Network-level authentication leverages cryptographic device bindings to confirm identity. For example, network-powered solutions use real-time operator data sourced directly from mobile network operators (MNOs). This allows for:
Continuous monitoring. Instead of just checking for a one-time password, the network actively observes session behaviors and flags real-time anomalies to detect account takeovers.
Contextual awareness. The network evaluates location, time of day, and access history to ensure that the user’s environment matches the profile.
Network-powered solutions remove the reliance on device-specific or easily accessible data. For example, phone number lookup services are popular but reference databases that may be out of date. Device fingerprinting analyzes browser characteristics that can be spoofed. And behavioral biometrics take cues from historical sessions.
Now, when checking if a SIM card has been recently swapped, the answer comes from the network that performed the swap in real time — not from a cached record. This is a key difference because static databases that aren’t frequently refreshed won’t detect a SIM swap and resulting account takeover. Pulling real-time data, however, stops the fraud activity. Also, no human participation means less opportunity for fraud.
Let’s take a look at next-gen fraud-fighting.
Identity Insights: Pre-verification intelligence saves money and stops fraud before it starts
Identity Insights is the risk assessment layer that runs before any verification channel is initiated. This has commercial significance for large enterprises. That’s because fraudulent attempts — synthetic accounts built on VoIP numbers, ATO attacks timed to coincide with SIM swaps, bot-driven credential stuffing on invalid numbers — are identified and blocked before a single OTP is sent.
The steps happen before any verification cost is incurred and before any fraud processing overhead is generated. Identity Insights also surfaces real-time operator signals that are directly actionable in authentication policy decisions.
"Not every transaction carries the same risk, so why apply the same friction? Network signals let you score each interaction in context — approving what's safe, stepping up what's uncertain, and blocking what's not."
Jose Luis Zamorano Priego, Vonage Product Manager, Identity Insights
Silent authentication: The do not disturb for customers
What if the phone number could serve as a true customer credential? Silent authentication makes this possible by verifying phone number possession through the mobile network — inside your app, in seconds — with no passcodes.
When you validate subscriber identity, you are comparing against operator Know Your Customer data used to issue the mobile contract, not a credit bureau approximation. The proof of possession is the cellular data session itself, a cryptographic binding to the physical SIM that cannot be phished, intercepted, or socially engineered. It's designed to plug into existing authentication workflows and fail over when needed. This means higher conversion rates and no exposure to OTP fraud.
Fraud Defender: Protecting the verification channel itself
Bad actors generate fraudulent revenue through toll fraud and SMS pumping attacks on the verification delivery channel. These attacks feature automated systems that trigger high volumes of OTP message sends to premium-rate numbers that the attackers control. This generates telecommunications revenue for the attacker at the enterprise's expense. Fraud Defender provides real-time traffic monitoring and intelligent blocking at the point of outbound message delivery by:
Analyzing verification traffic patterns
Detecting anomalous velocity, high-risk destination prefixes, and known fraudulent routing signatures
Applying configurable blocking rules before messages are sent
Better customer journeys
Next-gen fraud-fighting solutions bring a silent and speedy workflow that positively impacts customer journeys:
Onboarding and new account signup
These are the primary entry points for synthetic identity fraud and automated account farm creation. Identity Insights starts with line type screening to eliminate VoIP and non-mobile numbers and determine whether the number has an established subscriber history or was recently issued. This includes validating that the identity data submitted in the signup form corresponds to the operator's own KYC records for that number. Numbers that fail these checks are blocked before any verification cost is incurred.
Numbers that pass are verified through silent authentication to enable zero-tap account creation for genuine mobile users. A legitimate new user on a real mobile device only has to enter the phone number and tap the next step. There are no OTPs or delays — thereby removing the largest source of onboarding abandonment.
Password and account recovery
ATO attackers place a priority on account recovery, because it provides a path to full account access that bypasses legitimate user credentials. SIM swap attacks are frequently timed to coincide with password recovery attempts. This is when the attacker takes control of the target's number and then immediately initiates recovery.
For this journey, SIM swap recency becomes a mandatory hard-check with a tight look-back window. Any swap activity within the defined risk period triggers either a hard block or mandatory escalation to an out-of-band verification channel. The phone number presented is validated to correspond to the subscriber record on file. Silent authentication is required regardless of network state, meaning there is no passive bypass for this journey.
High-value transactions and sensitive profile changes
Wire transfers, large purchases, changes to payment instruments, and modifications to account access controls all warrant the full signal stack. Identity Insights runs a real-time carrier query covering line type, SIM swap, roaming context, and subscriber match. Verification steps apply silent authentication as the
primary channel with a mandatory secondary challenge for any elevated-risk signals detected in precheck. Risk scores exceeding a configurable threshold trigger hard blocks with full audit logging. This is vital for both internal security governance and external regulatory compliance.
Benefits that go beyond fraud prevention
There’s a perception that added security equals added steps, which then creates friction and lost users. But friction is not just the presence of an extra step. It’s the perceived effort required from the user. A well-designed security mechanism, such as silent authentication, can enhance protection without user involvement.
A focus on low-friction, user-friendly authentication methods has benefits beyond fraud prevention. By protecting the business without disrupting the customer experience, you enable users or customers to spend more time doing business with you.
Frequently asked questions
OTPs present a clunky experience, where customers have to wait for a code — which may never arrive — and then manually enter it. This leads to frustration and potential lost business. Also, bad actors can easily intercept OTPs for account takeovers to harm your business and customers.
No. Network-powered solutions do not rely on device-specific or easily accessible data. For example, silent authentication uses KYC data to verify phone number possession through the mobile network. Unlike OTPs, this removes human participation and passcodes to reduce the risk of fraud.
Network-powered solutions create speedy workflows that boost customer experiences, such as onboarding and new account signup, password and account recovery, and high-value transactions and sensitive profile changes.