GCash is set to fully roll out its In-App One-Time Passwords (OTPs) feature by June 22, 2026, replacing traditional SMS-based authentication as part of its efforts to strengthen account security and reduce the risk of digital fraud.
The move aligns with the Bangko Sentral ng Pilipinas directive under the Anti-Financial Account Scamming Act (AFASA), which requires financial institutions and digital payment platforms to phase out SMS OTPs and adopt more secure authentication methods by June 2026.
Under the new system, users will receive OTPs through secure push notifications delivered directly within the GCash app. The company says the upgrade is designed to provide a safer and more seamless verification experience while reducing opportunities for scammers to intercept authentication codes.
A Shift Away from SMS-Based Authentication
For years, SMS OTPs have served as a standard security layer for online transactions. However, they have also become a common target for phishing attacks, social engineering schemes, SIM swap fraud, and other forms of cybercrime.
In-App OTPs help address these vulnerabilities by delivering authentication requests directly to a user’s verified and authenticated app session. This reduces the likelihood that codes are intercepted or accessed by unauthorized parties.
The new system also streamlines the verification process by eliminating the need to switch between applications, manually enter codes, or wait for text messages to arrive.
“Our upgrade to In-App OTPs is a strategic move to put an end to phishable SMS OTPs. We will shift users to instant, GCash app-verified authentication to increase the security of their daily transactions,” said Miguel Geronilla, chief information security officer of GCash.
Strengthening Multi-Factor Authentication
The rollout of In-App OTPs forms part of GCash’s broader cybersecurity strategy built around Multi-Factor Authentication (MFA), an industry-standard approach that adds multiple layers of verification when accessing digital accounts and financial services.
According to the company, MFA significantly reduces the risk of account takeover attempts, even if a user’s password or MPIN has been compromised.
The latest enhancement builds on several existing security measures implemented within the platform, including Know Your Customer (KYC) verification and Facial Recognition verification through GCash’s Double Safe feature.
By combining multiple authentication layers, GCash aims to improve account protection without creating additional friction in the user experience.
Supporting Safer Digital Finance

As digital financial services continue to expand in the Philippines, financial institutions face increasing pressure to strengthen defenses against evolving scams and cyber threats.
GCash says the introduction of In-App OTPs reflects its ongoing commitment to improving platform security and supporting safer digital transactions for millions of users nationwide.
The company believes the transition will not only help reduce fraud risks but also encourage wider adoption of secure digital financial services as more Filipinos embrace cashless transactions.
The In-App OTP feature will be fully rolled out to GCash users by June 22, 2026.
For more information, visit www.gcash.com.
.