Your Pakistani Card Can Be Charged Without an OTP. Who Protects You When It Happens?

Can a Pakistani card be charged without an OTP? Learn how 3-D Secure works, why some international payments need no OTP, and how to reduce fraud risk.

Pakistani cardholder making an international online payment, illustrating card fraud risks, authentication and consumer protection.

I was scrolling through LinkedIn when a UBL advertisement stopped me.

“Don’t Let a Search Lead to a Scam,” it warned. UBL was telling customers not to trust telephone numbers found casually through an internet search. A fraudster can publish a fake number, answer the call and pretend to represent the bank.

Sensible advice.

But I looked at the advertisement and thought about something banks discuss far less often.

What happens when I protect my OTP and nobody asks me for one?

I have used Pakistani cards on international websites where the payment process felt reassuring. I entered my card details, received an OTP and completed the transaction. But international online payments do not always work that way. Sometimes there is no OTP.

That raises a question every Pakistani debit and credit card user should understand: if my bank approves an international online transaction without asking me to confirm it, what exactly protected that decision? And if the protection fails, who bears the loss?

What an OTP Actually Protects

First, we need to clear up one common misunderstanding.

When you shop online, a legitimate merchant normally asks for your card number and expiry date, together with the CVV or CVC printed on the card. It should not ask for the PIN you use at an ATM.

Never enter your ATM PIN on an ordinary shopping website.

An online purchase is generally a card-not-present transaction, often called CNP. You are not physically presenting your card to the merchant. This creates a different fraud risk from paying at a shop.

Many Pakistani consumers have therefore learned a simple security rule: No OTP, no payment. Unfortunately, it is not that simple.

An OTP is one way of confirming the cardholder’s identity. It is not the entire security system. The more important technology is 3-D Secure, or 3DS.

Visa calls its EMV 3-D Secure programme Visa Secure. Under 3DS, information can pass between the merchant and the bank that issued your card before authorization. The issuer then assesses whether the person attempting the purchase is likely to be the genuine cardholder.

Sometimes the bank challenges the customer. You may receive an OTP. The bank could instead use another approved authentication method.

Modern 3DS can also operate through a frictionless flow. The issuing bank assesses transaction data and authenticates a low-risk transaction in the background without requiring the customer to do anything.

No OTP does not automatically mean no 3-D Secure.

But a customer should not assume that every transaction completed without an OTP received the same level of protection.

Pakistan Already Has Rules for Online Card Security

I initially wondered whether the State Bank of Pakistan should simply require Pakistani banks to introduce 3-D Secure for international transactions. Then I checked the regulations. SBP has already acted.

In its 2018 security instructions for digital payments, SBP told banks and microfinance banks to enable the EMVCo 3-D Secure protocol to prevent fraud in online transactions. It required them to prepare implementation plans for all applicable card payments.

By February 2021, SBP said 15 banks had adopted 3-D Secure. It also allowed banks that had implemented the technology to activate customers’ cards for online e-commerce without requiring customers to request activation first.

Pakistan therefore does have a regulatory foundation for safer e-commerce. The problem is not simply, “Why hasn’t SBP introduced 3-D Secure?” It has.

The more useful consumer question is: What protection applies when an international card-not-present transaction reaches my Pakistani bank and I am not actively asked to authenticate it?

Why Some International Payments Don’t Ask for an OTP

Suppose I buy software from an overseas company. I enter my card number and expiry date, followed by the CVV. I click Pay. The payment succeeds. My phone never receives an OTP.

Was the transaction insecure? Not necessarily.

Visa explains that modern 3DS uses risk-based authentication. The issuer can evaluate information associated with the transaction and decide that the risk is low enough to authenticate it without further customer involvement. Visa calls this the frictionless flow. If the transaction appears riskier, the issuer can require a challenge such as an OTP or another authentication method.

This distinction matters because consumers see only the checkout screen. The bank sees much more.

Payment systems must also handle stored credentials and subsequent payments. Other payment arrangements can affect how authentication occurs. A customer therefore cannot look at the absence of an OTP and determine exactly what happened behind the scenes.

That is part of the consumer-protection problem.

Imagine Someone Gets Your Card Details

Consider Ahmed, a Pakistani credit-card customer. Ahmed sometimes uses his card for international software subscriptions. One day, criminals obtain his card number and expiry date, along with the CVV.

They do not have his ATM PIN. They do not control his banking app.

Now they attempt a $150 purchase at an overseas merchant.

When Ahmed is challenged

The merchant sends the payment through its payment infrastructure. Authentication takes place through 3DS, and Ahmed’s issuing bank decides that additional verification is required.

Ahmed receives a challenge. He did not initiate the transaction, so he does not approve it. The criminal possesses the card information but cannot complete the required authentication.

The security control has intervened before authorization.

When Ahmed receives no challenge

Now imagine another transaction. Depending on how the transaction has been submitted and authenticated, Ahmed may not receive an OTP or app challenge.

The authorization request eventually reaches Ahmed’s Pakistani issuing bank. The issuer’s systems assess the transaction and decide whether to approve or decline it. The bank approves it.

Ahmed’s first visible sign may be an SMS or app notification: USD 150 charged to your card.

At this point, the notification has not prevented fraud. It has told Ahmed that a transaction has occurred.

I would much rather have my bank stop a questionable $150 payment than send me an excellent SMS two seconds after approving it.

3-D Secure Versus a Transaction Without an Active Challenge

What happens3DS with customer challengeFrictionless 3DSNo active customer challenge
Customer enters card detailsYesYesUsually
Customer must actively authenticateYes, when challengedNoNo active challenge
Issuer can assess transaction riskYesYesAuthorization and fraud controls may still apply
Customer actively confirms purchaseYesNoNo
Customer may first notice through an alertLess likelyPossiblePossible
Main protectionActive authentication plus issuer controlsRisk-based authenticationDepends on transaction type and issuer/network controls

The better question is not merely, “Did you receive an OTP?” It is: How was this particular transaction authenticated and authorized?

Why I Would Not Make SMS OTP Mandatory for Every Transaction

My first instinct was straightforward. Why doesn’t SBP simply require an OTP for every international online transaction?

After examining how modern card authentication works, I think the regulatory question needs to be framed differently. OTP itself has weaknesses.

A fraudster can telephone a customer while pretending to represent the bank and ask him to read out a verification code. The customer complies. The security control has now become part of the social-engineering attack.

A banking-app approval can communicate far more useful information. It can show the amount and merchant, then ask the customer to approve or decline the purchase.

Modern 3DS also deliberately supports frictionless authentication for transactions that an issuer assesses as low risk. So I would not ask SBP to mandate SMS OTP for every international transaction. I would ask for something more useful.

Give Pakistani Customers Control Over International Card Exposure

SBP cannot tell every American or European website how to design its checkout page. It can regulate Pakistani banks.

Pakistani issuers should give cardholders clear control over international card-not-present exposure. Customers should be able to disable international e-commerce when they do not need it.

They should also be able to impose a separate, deliberately low online limit without reducing the entire credit limit on the card.

Most importantly, banks should explain what happens to international transactions that proceed without active customer authentication.

One regulatory option deserves serious examination: international CNP transactions that do not meet a prescribed authentication standard could be disabled by default, while customers who need broader international acceptance could explicitly enable them within defined limits.

That proposal would require careful technical work. Recurring payments and other legitimate payment arrangements cannot simply be treated as fraud.

The customer should know how much international online exposure his card carries.

Digital Security Cannot Assume Every Customer Understands 3DS

The UBL advertisement that started this article illustrates another problem. It tells customers to verify branch telephone numbers through UBL’s official website. That is sound advice.

But consider what the customer needs to know before he can follow it safely. He must distinguish an official bank website from an imitation. He may need to recognize a misleading search result. Then he must understand that the person answering a telephone number found online may not represent the bank.

Pakistan’s digital-payment system serves people with very different levels of digital literacy. A security model cannot assume that every cardholder understands the difference between an internet search result and an official bank page. Nor can it assume that everyone understands the difference between a CVV and an OTP.

The banking system therefore needs controls that protect people before education fails.

Warnings matter. System design matters more.

Before You Use Your Pakistani Card Online

  • Keep international e-commerce disabled when you do not need it, if your bank provides that control.
  • Set a deliberately low online or international transaction limit where your bank allows separate limits.
  • Prefer merchants using 3-D Secure or another recognized authentication mechanism.
  • Turn on immediate transaction notifications.
  • Never disclose an OTP or ATM PIN. Treat an unexpected authentication request as a warning.
  • Consider a virtual card with a controlled limit where your bank offers one.

Your total credit limit and the amount you expose to the internet do not need to be the same.

If You See a Transaction You Did Not Make

Speed matters.

Freeze or block the card immediately through your banking app if that facility exists. Otherwise, contact the bank using the telephone number printed on your card or published through the bank’s official channel.

Do not search casually for a customer-service number. That brings us straight back to UBL’s warning.

Report the transaction as unauthorized and obtain a complaint or dispute reference number.

Then ask a more specific question than “Why didn’t I receive an OTP?” Ask: “Was this transaction authenticated through 3-D Secure? If it was, what authentication method or transaction flow was recorded?”

Also ask whether the payment was processed as a recurring or merchant-initiated transaction, if relevant. Keep the transaction notification. Preserve your correspondence with the bank and record when you reported the fraud.

An Unauthorized Transaction Does Not Automatically Mean an Automatic Refund

An unauthorized transaction does not automatically produce a refund. The circumstances matter.

The bank will examine whether the customer authorized the transaction. Authentication records may matter, as can the circumstances surrounding the payment. Applicable card-network procedures and the bank’s dispute process can also affect what happens next.

Pakistani law nevertheless contains an important consumer safeguard.

Section 41 of the Payment Systems and Electronic Fund Transfers Act, 2007 places the burden of proof on the financial institution or authorized party in an action involving consumer liability for an unauthorized electronic fund transfer. The institution must show that the transfer was authorized or establish the statutory conditions relevant to liability.

That does not mean every disputed card transaction must automatically be refunded. It does mean consumers should not assume that a debit appearing on their statement ends the argument.

Dispute it. Ask how it was authenticated. Ask why it was approved. And keep the evidence.

Prevention, Detection and Reimbursement Are Not the Same Thing

Banks often present digital security as one package. From the consumer’s side, it looks very different.

Prevention tries to stop the fraudulent transaction before the money moves.

Detection identifies suspicious activity or tells the customer what has happened.

Then comes another question: who bears responsibility for the disputed transaction? Only after that do we reach reimbursement, when the customer discovers whether and when the money will actually return.

An SMS alert can provide excellent detection while providing no prevention at all. That distinction should appear in every serious consumer guide to digital banking.

The Question Pakistani Banks Need to Answer

The UBL advertisement is the starting point of this article, not its target. The underlying issue affects the wider banking and card-payment ecosystem.

UBL is right to tell customers to verify telephone numbers. Banks are right to tell us never to disclose our OTPs. Customers also have responsibilities. We need to protect our credentials and report suspicious transactions quickly.

But digital security cannot depend mainly on the assumption that every customer will recognize every scam.

SBP has already required important card-security measures. Pakistan’s banks use 3-D Secure, fraud-monitoring systems and other controls. Consumers now need greater visibility into what happens when those systems make decisions for us.

The next time my phone receives an OTP, I know what to do. I read it. I check the transaction. If it is not mine, I approve nothing.

The transaction that worries me is the one for which my phone never asks.

If my Pakistani bank can approve an international online payment without asking me to confirm it, I want to know what protected that decision. And if that protection fails, I want to know who bears the loss.

Those are questions a digital-payment system should answer before fraud occurs, not after the customer starts filling out a dispute form.

Unknown's avatar

Author: Munaeem Jamal

Blogger and Currently working as SWIFT Support Office in a Bank in Pakistan Bachelor of Arts : Political Science, International Relations and Economic. All posts on health and medications are written by my daughter, Nazeha Maryam Jamal She is a 5th Professional Student of Karachi Medical and Dental College

Leave a Reply

Discover more from Mallick Speaks

Subscribe now to keep reading and get access to the full archive.

Continue reading