Passkeys are beginning to reshape authentication across the Philippine banking industry as financial institutions move away from passwords and SMS one-time passwords (OTPs) in favor of more secure authentication methods.
The shift comes as banks face increasingly sophisticated phishing attacks that can compromise customer credentials and expose accounts to fraud.
A recent example is BDO’s decision to replace SMS OTPs with in-app push authentication for transaction approvals, marking one of the country’s biggest moves toward modern authentication.
The change also aligns with the Bangko Sentral ng Pilipinas’ (BSP) push for phishing-resistant authentication, encouraging financial institutions to strengthen digital security while improving the customer experience.
Together, these developments signal a broader transformation in how banks verify customer identities.
Instead of relying on passwords that can be stolen or SMS codes that may be intercepted, banks are increasingly turning to passkeys, biometrics, and app-based approvals as the next generation of banking security.
Why passwords and SMS OTPs are no longer enough
Passwords have protected online accounts for decades, but they have also become one of the weakest links in cybersecurity.
Many customers reuse passwords across multiple platforms, while phishing websites continue to trick users into revealing their login credentials.
SMS OTPs were introduced as an additional layer of protection, but cybercriminals have found ways to bypass them through SIM swap attacks, malware, fake banking websites, and social engineering schemes.
Fraudsters can intercept verification codes or convince users to unknowingly authorize fraudulent transactions.

Recognizing these evolving threats, the BSP has been encouraging banks to adopt phishing-resistant authentication methods that reduce reliance on shared secrets such as passwords and OTPs.
The goal is to make customer authentication significantly more resistant to compromise while maintaining a seamless digital banking experience.
Passkeys offer a passwordless future
Among the technologies expected to play a central role are passkeys, a passwordless authentication standard developed through industry collaboration among major technology companies.
Unlike passwords, passkeys rely on cryptographic key pairs. A private key remains securely stored on an account holder’s trusted smartphone, tablet, or computer, while a corresponding public key is stored by the bank.
During login, the device verifies the user’s identity using Face ID, fingerprint recognition, or the device PIN before securely authenticating the account.

Why passkeys are becoming the new standard. (IMAGE CREDIT: IT Masters)
Because users never type a password, phishing websites cannot steal login credentials.
Even if criminals create fake banking pages, passkeys are cryptographically bound to legitimate websites, making them highly resistant to phishing attacks.
Cybersecurity experts believe passkeys represent one of the most important advancements in authentication because they improve both security and convenience. Customers no longer need to remember complex passwords or worry about password leaks from unrelated websites.
Biometrics become the new identity check
Biometric authentication has already become familiar to many banking customers through fingerprint and facial recognition used to unlock mobile banking applications.
However, banks are now also expanding the role of biometrics beyond simple app access.

Modern banking platforms increasingly use biometrics as proof that the legitimate account owner is authorizing a transaction. Since biometric data is unique to each individual, it provides stronger identity verification than passwords alone.
Experts note that biometric authentication is most effective when combined with secure hardware built into modern smartphones. Rather than transmitting fingerprint or facial data to banks, the biometric verification takes place securely on the user’s device, protecting customer privacy while reducing fraud risks.
As smartphone adoption continues to grow in the Philippines, passwordless authentication is expected to become the new standard for securing digital financial services in the Philippines.
Push authentication replaces SMS OTPs

Push authentication explained: Security, risks and benefits. (IMAGE CREDIT: AuthX)
Another major shift is the growing adoption of push authentication, where approval requests are sent directly to a customer’s registered banking application instead of through SMS.
BDO’s migration away from SMS OTPs reflects this trend. Under push authentication, customers receive a secure notification within the banking app that displays the transaction details before asking them to approve or reject the request.
This approach offers multiple security benefits. Since approvals are tied to a registered device, attackers cannot simply intercept an SMS code. Customers can also review transaction information before confirming payment, making it easier to detect suspicious activity.
Security specialists say app-based approvals reduce exposure to phishing and SIM swap attacks while providing a smoother user experience. Instead of switching between messaging apps and banking apps to enter verification codes, the approval process happens within a single secure environment.
What banking customers should expect next
The shift toward passwordless authentication is unlikely to happen overnight, but customers should expect gradual changes over the next few years.
Banks are expected to introduce more device-based authentication, expand biometric verification, and integrate passkeys into both mobile and online banking platforms. Passwords may still exist during the transition period, but they will likely become secondary authentication methods rather than the primary line of defense.
Customers may also notice fewer SMS OTPs, more in-app approval requests, and stronger security checks that happen automatically in the background without creating additional friction.
For consumers, adapting to these technologies may require keeping banking apps updated, registering trusted devices, and enabling biometric features to take full advantage of enhanced security.
A passwordless future for Philippine banking
The growing adoption of passkeys, biometrics, and push authentication signals a major evolution in Philippine banking security.
With BDO replacing SMS OTPs and the BSP encouraging phishing-resistant authentication, banks are laying the foundation for a future where passwords become far less important.
For customers, the transition promises more than stronger protection against cyber threats.
It also offers a faster, more convenient, and more seamless banking experience. As authentication continues to evolve, passwordless authentication is expected to become the new standard for securing digital financial services in the Philippines.
