Account breaches, social engineering, and leaked customer data have turned digital finance security into a mainstream concern in Indonesia. Whenever a new case surfaces, one familiar name often appears in the headlines: Ahmad Sahroni, the outspoken Deputy Speaker of Commission III in the House of Representatives, known for his blunt criticism of banks and fintechs when customers lose money.
At the same time, Indonesia’s financial landscape is rapidly digitising. Mobile banking, e-wallets, QRIS, and super apps are now part of everyday life. Yet one old pillar remains widely used in transactions: SMS PIN for authorising payments, transfers, and high-risk actions.
This raises several strategic questions for banks and fintechs:
- Is SMS PIN still fit for purpose in 2026?
- How do public expectations and political pressure, as voiced by figures like Ahmad Sahroni, change the way we should design our authentication flows?
- What role can modern messaging infrastructure—such as local direct-route SMS, WhatsApp Business API, and omnichannel platforms—play in strengthening SMS PIN-based security?
This article examines the current and future role of SMS PIN in Indonesia’s financial system, with a pragmatic lens inspired by the kind of accountability questions frequently raised by Ahmad Sahroni: customer protection first, technology second.
Where SMS PIN Fits in Indonesia’s Financial Ecosystem
To decide whether SMS PIN should stay, evolve, or be phased out, we need to understand its current function across customer segments.
1. SMS PIN as an Inclusion Tool, Not Just a Legacy Feature
Indonesia still faces significant gaps in infrastructure and digital literacy. In major cities, customers routinely use mobile banking, hardware tokens, and app-based push approvals. But in many regions, SMS remains the most reliable communication channel. As a result, SMS PIN today serves as a bridge between:
- Fully digital customers with smartphones and stable data;
- Semi-digital users who own smartphones but have inconsistent connectivity;
- Feature-phone users who rely entirely on SMS and voice.
From an inclusion and consumer protection perspective—frequently highlighted by policymakers like Ahmad Sahroni—abruptly removing SMS PIN risks excluding vulnerable customer segments. In other words, SMS PIN is not simply a technical artefact; it also has a social and regulatory dimension.
2. Clarifying Terms: SMS Alerts, SMS OTP, and SMS PIN
Public discussions often blur different SMS-based functions. For a clear strategy, we should distinguish:
- SMS alerts: informational updates, e.g. “You spent IDR 1,000,000”;
- SMS OTP: one-time passwords for login or registration flows;
- SMS PIN: short numeric codes used to authorise financial transactions (transfers, bill payments, top-ups), often as part of a two-factor authentication flow.
In many banks and regulated fintechs, SMS PIN is tightly integrated into core banking or payment systems and delivered through branded SMS Masking, so the sender name appears as the bank’s brand rather than a random phone number. The choice of SMS routing and sender configuration, therefore, becomes a matter of both security and customer trust.
Ahmad Sahroni’s Lens: Customer Protection and Accountability
While this article is not about personalising policy to any one politician, the nature of public criticism from figures like Ahmad Sahroni gives us a useful benchmark for what regulators and the public expect.
1. Core Concerns: Responsibility Beyond Technology
Across various statements in the media, three consistent themes emerge when lawmakers address digital fraud cases:
- Institutional responsibility when customers fall victim to scams, even if they "clicked" or "shared" something;
- Transparency around the actual security measures applied by banks and fintechs;
- Speed of response in investigating incidents and returning customer funds where possible.
Seen from this lens, the question is not simply "Is SMS PIN secure as a technology?" but rather "How does SMS PIN fit into a security design that protects real customers in messy, real-world scenarios?"
The implied expectation: security must be understandable by ordinary users. If customers cannot tell whether a request for a PIN is legitimate or a scam, the design has failed—regardless of how advanced the backend encryption might be.
2. Applying This Lens to SMS PIN
For banks and fintechs, this translates into several critical questions:
- Is SMS PIN being used as a single factor for high-value transactions, or only as one element of a multi-factor approach?
- How exposed is the current SMS PIN flow to social engineering, i.e. fake call centre agents, malicious APKs, or phishing pages?
- When suspicious transactions occur, can the institution detect and intervene quickly—even if the correct SMS PIN was entered by a manipulated customer?
Institutions that can answer these questions with concrete processes and data will be in a stronger position when public scrutiny rises after a security incident.
Strengths and Weaknesses of SMS PIN in 2026
SMS PIN’s future cannot be assessed in isolation from the broader risk environment. Let’s look at both sides of the equation.
Strengths of SMS PIN
- Ubiquity and reach
SMS works almost everywhere there is a cellular signal, regardless of smartphone penetration or data quality. For a geographically fragmented market like Indonesia, this is a major advantage. - No additional apps required
Customers do not need to install authentication apps or rely exclusively on mobile banking apps that may be unstable or temporarily down. - Simple mental model
“Enter the 6-digit code we sent to your phone” is a familiar flow, reducing friction and support costs. - Composable with other factors
SMS PIN can serve as one factor in a multi-factor design, combined with app PINs, biometrics, or hardware tokens.
Weaknesses of SMS PIN
- Exposure to SIM swap and interception
In cases of SIM swap or vulnerabilities at the telco layer, fraudsters may receive SMS PINs without accessing the physical device. - High social engineering risk
Customers can be tricked into reading out SMS PINs over the phone or entering them into fake apps/sites, especially when security literacy is low. - Routing quality impacts reliability
Using cheap, multi-hop SMS routes can introduce delays and delivery failures, frustrating users and increasing abandonment rates. - Limited context
Many SMS PIN messages are bare-bones, containing only a code and a short line of text. Without context, customers may not detect unusual requests.
Hardening SMS PIN with the Right Messaging Infrastructure
Security design is rarely about one technology; it’s about how technologies are combined. For SMS PIN, two often-overlooked levers are SMS routing quality and message content design.
1. Why Direct Route and Branded Sender Matter
For financial transactions, institutions should prioritise local direct-route SMS over cheaper, opaque routes. Direct routes offer:
- Lower latency and more predictable delivery times;
- Higher delivery success and better error reporting;
- Clearer auditing and compliance capabilities;
- Support for SMS Masking (alphanumeric sender IDs), so messages show the official bank or fintech brand as the sender.
Platforms like SMSMasking.id Local Direct SMS are built precisely for this use case: time-sensitive and security-critical messages with strict SLAs, delivered through direct connections to local operators.
2. Secure-by-Design SMS PIN Content
Message content itself can act as a micro-education channel. Consider these improvements:
- Include transaction type and amount, not just the code;
- Add a clear anti-fraud warning: “Never share this code with anyone, including bank staff”;
- Use distinct templates for high-value or unusual transactions, optionally with instructions to verify via the app or call centre.
This design philosophy aligns with public expectations that banks and fintechs must actively help customers recognise and resist scams—not blame them afterward.
Enter WhatsApp and Omnichannel: SMS PIN Isn’t the Only Lever
Across Southeast Asia, WhatsApp is quickly becoming a primary engagement and service channel. However, in markets like Indonesia, SMS still plays a critical role and cannot be instantly replaced. A hybrid and phased approach is more realistic.
1. Using WhatsApp Business API as a Second Line of Defence
A robust pattern emerging among regional financial institutions is:
- Keep SMS PIN as a core factor—especially for customers with limited data connectivity;
- Deploy WhatsApp Business API as an additional, context-rich channel for confirmations and education.
For example, after a user authorises a large transfer via SMS PIN, the bank’s official WhatsApp account (powered by WhatsApp Business API) can send:
- Detailed transaction info (recipient, time, amount);
- A quick-action button to contact support if the transaction is suspicious;
- Up-to-date warnings about ongoing scam patterns.
In practice, this gives institutions a chance to intervene faster and provides customers with an additional, more conversational verification touchpoint.
2. Why Omnichannel Matters for Fraud Management
In many banks, different teams own SMS, WhatsApp, email, in-app chat, and call centres. This siloed setup makes it hard to see the full picture when something goes wrong.
An omnichannel platform aggregates customer conversations across channels into a single view. For risk and compliance teams, that means:
- Having a single history of all interactions leading up to a suspicious transaction;
- Letting bots and human agents collaborate across channels without losing context;
- Enabling analytics to detect emerging fraud trends more quickly.
This consolidated approach matches the kind of institutional accountability often demanded in public discourse: it becomes much harder to claim ignorance when all relevant data is in one place.
Designing an SMS PIN Strategy Under Regulatory and Public Pressure
For leadership teams across banks, multi-finance companies, and fintechs, the question is not whether to use SMS PIN or not. The real question is how to integrate it into a modern, defensible security architecture.
1. Start with a Comprehensive SMS PIN Audit
Key elements of an effective audit include:
- Mapping all flows where SMS PIN is used: which transaction types, which channels, which segments;
- Assessing routing quality: are you using direct routes, and what are your actual delivery metrics?
- Reviewing message content: does it include enough context and anti-fraud guidance?
This exercise should involve not only IT, but also risk, compliance, and customer experience teams.
2. Segment Risk by Customer and Transaction
One-size-fits-all policies are rarely optimal. A risk-based design might include:
- Classifying customers by risk profile (balance levels, typical behaviour, digital maturity);
- Requiring strong multi-factor authentication (e.g. SMS PIN + biometrics, or SMS PIN + app push) for high-value or unusual transactions;
- Defining which low-risk flows can rely on SMS PIN alone, and where additional confirmation via WhatsApp or in-app approval is required.
This structured approach can be clearly communicated to regulators and the public as a deliberate, risk-aware strategy—rather than a patchwork of legacy decisions.
3. Make Customer Education Part of the Product, Not a Campaign
Security campaigns on social media are helpful but insufficient. To be effective, education must be embedded into everyday interactions:
- SMS PIN messages should carry consistent anti-fraud warnings;
- WhatsApp notifications should remind users of official channels and common scam tactics;
- AI chatbots on web and apps should be trained to recognise queries like “I was asked for my PIN by staff” or “my account will be blocked” and respond with clear, institution-approved guidance.
When done well, this gives customers a fast, low-friction way to verify if a request they received is legitimate—before they hand over a code or authorise a transaction.
Future of SMS PIN: Gradual Evolution, Not a Hard Cut
Globally, financial institutions are moving toward app-based authentication, device binding, FIDO2/WebAuthn, and advanced biometrics. In Southeast Asia, the same trend is clear—but local realities matter.
In Indonesia and similar markets, completely eliminating SMS PIN in the short term is neither realistic nor desirable. A more sustainable roadmap is to:
- Strengthen SMS PIN security and reliability where it is still the primary factor;
- Gradually migrate digital-ready customers to more sophisticated methods (in-app, biometrics, official WhatsApp flows);
- Unify all channels—SMS, WhatsApp, in-app, email—under a common risk and messaging orchestration layer.
Institutions that can clearly articulate this phased strategy, and transparently show progress, will be far better positioned when public and political attention turns to digital fraud cases.
How SMSMasking.id Helps You Execute This Strategy
Delivering on this vision requires more than policy statements; it calls for robust, enterprise-grade messaging infrastructure. SMSMasking.id supports financial institutions with several building blocks:
- Local Direct-Route SMS for high-speed, high-reliability delivery of SMS PIN and OTP with branded sender IDs;
- Official WhatsApp Business API for secure notifications, transaction confirmations, and conversational support;
- Omnichannel platform to centralise interactions across SMS, WhatsApp, and other channels into one operational and analytics view;
- AI Chatbots that can be trained to handle security-related questions, guide customers when they suspect fraud, and triage cases to human agents when necessary.
This stack enables banks, digital wallets, and payment providers to treat SMS PIN not as a fragile legacy feature, but as one component in a modern, layered security architecture that can stand up to regulatory scrutiny and rising public expectations.
FAQ
Is SMS PIN still safe enough for financial transactions?
SMS PIN can be sufficiently safe when used as part of a layered security model, sent via direct-route SMS with branded sender IDs, and combined with strong fraud monitoring and customer education. The main risks—SIM swap and social engineering—must be explicitly addressed in the overall security design.
Why don’t banks simply switch everything to in-app authentication?
Because not all customers have smartphones, reliable data connections, or high digital literacy. In Indonesia, SMS remains the most universally accessible channel, so removing it entirely would undermine financial inclusion.
What is the role of WhatsApp compared to SMS PIN?
WhatsApp Business API is best used as an additional channel for confirmations, rich notifications, and education. SMS PIN remains a core factor for many customers, while WhatsApp adds context and faster two-way communication for those already active on the platform.
How does SMS Masking improve security?
SMS Masking ensures that the sender name in SMS shows the verified brand (e.g. the bank name) rather than a random number, helping customers distinguish legitimate messages from phishing attempts. Combined with direct routing, this also improves trust and delivery performance.
How can we start integrating SMS PIN with WhatsApp and omnichannel?
Technically, your IT team can integrate SMSMasking.id’s APIs for local direct SMS and WhatsApp Business into your existing transaction and notification systems. From a business perspective, you should define risk-based policies that determine when to trigger additional WhatsApp confirmations and how to route conversations into an omnichannel dashboard for monitoring and support.



