The Vulnerability Of Sms Otp And The Risk Of Fake Bts Attacks On Mobile Banking Users In Indonesia

Authors

  • Muhammad Andi Hakim Universitas Pamulang
  • Muhammad Febryan Danuaji Universitas Pamulang
  • Muhammad Rizal Universitas Pamulang

Abstract

. The Rapid Growth Of Mobile Banking Services In Indonesia Has Provided Unprecedented Convenience for financial transactions, yet it has also increased users’ exposure to cybersecurity threats. One of the most critical vulnerabilities is the use of Short Message Service-based One-Time Passwords (SMS OTP), which remain susceptible to interception and manipulation through Fake Base Transceiver Station (Fake BTS) or IMSI Catcher attacks. This study aims to provide an in-depth analysis of SMS OTP vulnerabilities and the risks posed by Fake BTS attacks within the context of mobile banking security, while also examining their impact on user trust and behavioral intention. The analysis explores attack mechanisms, potential exploitation paths, and implications for the integrity of financial transactions. Additionally, this research evaluates mitigation strategies, including multifactor authentication, biometric verification, end-to-end encryption, and the integration of artificial intelligence for threat detection. The findings indicate that SMS OTP has a high level of vulnerability due to weak protection within cellular networks, enabling attackers to intercept authentication codes and gain unauthorized access to user accounts. Furthermore, low cybersecurity awareness and high exposure to social engineering attacks amplify the risks faced by users. This study highlights the urgent need to strengthen mobile banking security architectures through technical enhancements, user education, and more adaptive regulatory frameworks. The results are expected to serve as a reference for users, financial institutions, and regulators in improving the resilience of digital banking security in Indonesia.
Keywords: SMS OTP; Fake BTS; Mobile Banking; Cybersecurity; Multi-Factor Authentication; IMSI Catcher; Encryption; Artificial Intelligence; Digital Security Risk.

Downloads

Published

2026-01-11