🇲🇾💰 Money

CIMB Mandates SecureTAC for All Online Transactions Starting 19 September

CIMB Bank customers must shift to in-app biometric authentication for online payments as the bank tightens security protocols.

CIMB Bank has announced that it will require SecureTAC approval for all online transactions effective 19 September 2026, marking a significant transition in how the bank’s customers authenticate payments.

According to the original publisher, Fintech News Malaysia, this security update is mandatory for all transactions conducted via CIMB Clicks Web and external merchant websites. The move aims to phase out older verification methods in favor of the more secure SecureTAC system, which integrates directly into the CIMB OCTO App.

To complete a transaction under the new requirement, customers must use their primary device, where a push notification will be sent immediately after a payment request is submitted. Users are then required to review the transaction details within the app before providing authorization through Face ID, fingerprint recognition, or their registered device passcode.

The transition to this system is strictly tied to device security settings. CIMB has clarified that any customer who has not enabled biometric authentication or a device passcode on their smartphone will encounter an error message when attempting to approve a transaction, effectively preventing the payment from being processed.

For the average Malaysian consumer, this shift means that physical possession of a registered primary device is now non-negotiable for online shopping or digital banking. While this adds a layer of friction to the checkout process, it significantly bolsters defense against unauthorized transactions. For SMEs and e-commerce merchants in Malaysia, this change could lead to a brief period of cart abandonment if customers are unprepared for the verification prompt, highlighting the necessity for businesses to ensure their customers are aware of the banking sector’s tightening security standards.

The move also impacts the financial habits of the broader Malaysian workforce and investor base. As digital transactions become the standard, the convenience of one-tap payments is being balanced against the reality of increased cyber threats. With real GDP growth currently at 6.0% and a relatively stable unemployment rate of 3.0% as of May 2026, the Malaysian economy is increasingly driven by digital consumption, making the integrity of these platforms a vital component of national financial health.

This requirement sits within a wider industry trend where Malaysian financial institutions are aggressively moving toward app-based authorization to mitigate rising incidences of online fraud. CIMB has been particularly active in this space; for example, the bank recently made headlines for testing a RM1.38 billion tokenised Sukuk settlement, signaling its ongoing commitment to integrating advanced security and blockchain-based technology into its core banking infrastructure.

Looking ahead, it is clear that CIMB is steering its user base toward a mobile-first security architecture. By centralizing authentication within the CIMB OCTO App, the bank is reducing its reliance on traditional SMS-based verification, which has historically been a point of vulnerability for banking customers.

What remains unconfirmed is how the bank plans to support users who may lose access to their primary device or those who encounter technical glitches during the transition period. Furthermore, it is not yet clear if the bank will introduce additional recovery protocols for users who face persistent authentication errors after the 19 September deadline.

Source

Originally reported by Fintech News Malaysia. Read the original report →

Join the conversation

We post stories like this all day on Threads. Discuss this story on Threads →

More in Money