If you bank with CIMB, the password you have used to approve online transactions stops working on 19 September. From that date, CIMB moves those approvals into its OCTO app, where you confirm a payment with your face, your fingerprint or your phone's passcode. There is no password option any more, and if you have not set up biometrics or a passcode, the approval fails.

CIMB confirmed the change in an FAQ on its website, reported by Fintech News Malaysia and The Star on 3 September. The bank's tool is called SecureTAC, and it covers online transactions made through CIMB Clicks Web and on merchant checkout pages. When a payment needs approving, a push notification lands on your primary device, you open it, check the amount and the merchant, and approve or reject. "This helps protect your account from unauthorised access and fraud," CIMB said in its FAQ, adding that password approval will no longer be supported.

What CIMB customers should do before 19 September

The catch is in one line of CIMB's notice: SecureTAC approvals fail if you have not already switched on biometric login or a device passcode. Leave it until you are standing at a checkout on the 19th and you will be locked out mid-payment, staring at an error message telling you to go and set it up first.

So do it now. Open the CIMB OCTO app on the phone you actually carry, turn on Face ID or fingerprint approval, or set a device passcode, and make sure that phone is registered as your primary device. That last part matters if you have changed handsets recently: SecureTAC sends the approval to one device, so a prompt sent to a phone in a drawer is a payment you cannot complete.

A person approving an action with a fingerprint sensor on a smartphone

Why the SMS code is being killed off

This is the last stretch of a long push by Bank Negara Malaysia to move banking off the SMS one-time password. The regulator's updated Risk Management in Technology framework steers banks toward device binding and phishing-resistant approval and away from codes sent over text. Security researchers describe the shift as closing off SIM-swap attacks, phishing and account takeovers, per Security Boulevard's read of the rules. It lands amid a broader push on digital risk in Malaysia, from the country's fight over online age checks to its shortage of trained cyber defenders.

The reason is measured in ringgit. Malaysians lost RM2.97 billion to online scams in 2025, up from RM1.57 billion in 2024, across 66,204 reported cases, an 87 per cent jump in the number of cases in a single year. Those figures come from Inspector-General of Police Mohd Khalid Ismail, as reported by The Edge. A one-time code is the weak link in many of those stories: a scammer on the phone only has to talk you into reading six digits aloud. A fingerprint held against your own handset cannot be read out or forwarded to a stranger on a call.

Chart showing Malaysia online scam losses rose from RM1.57 billion in 2024 to RM2.97 billion in 2025

It is worth being honest about what this does and does not fix. Moving approval into the OCTO app removes the code a fraudster can trick out of you, but it also puts you at the last gate. The approve or reject screen shows the amount and the merchant for a reason: someone who has walked you this far will try to rush you past it. Read it before you press yes. And if you are a CIMB customer, open the app and switch on biometric approval before 19 September, not on it.

Images courtesy of Atlantic Money and Onur Binay on Unsplash.