KUALA LUMPUR: Malaysian financial institutions should move beyond traditional passwords and one-time passwords (OTPs) and adopt passwordless authentication to counter increasingly sophisticated digital fraud, according to Indonesian digital identity and fraud prevention company VIDA.
Speaking at the AIBP Conference and Exhibition Malaysia 2026, VIDA founder and chief executive officer Niki Luhur said digital fraud has grown into a global criminal ecosystem, where a single compromised device can trigger a chain of attacks, from malware that hijacks banking sessions to stolen funds being channelled through mule accounts before being transferred offshore.
He said conventional authentication methods, including passwords and OTPs, have become increasingly vulnerable as fraudsters now target customers' devices. Criminals can intercept OTPs, hijack authenticated sessions, and impersonate legitimate users once they compromise a device.,
"Authentication should not be treated as a one-time event. We need continuous authentication throughout the session to prevent advanced attacks such as session hijacking," said Niki.
Niki said passwordless authentication verifies a customer's identity using a trusted device and biometric authentication instead of codes that can be intercepted or stolen, making it significantly more difficult for fraudsters to gain control of customer accounts.
To illustrate its effectiveness, Niki showcased how one of Malaysia's leading digital banks has replaced passwords and OTPs with passwordless authentication to strengthen security across the customer journey.
The implementation covers digital onboarding, customer logins, high-risk transactions and account recovery, using device-bound credentials and biometric authentication to reduce fraud risks while improving the user experience.
"There doesn't have to be a trade-off between security and user experience. With the right authentication architecture, financial institutions can deliver both," Niki said.