2025-01-01
The Palestine Monetary Authority issued Circular No. 165/2025 to warn banks about a specific electronic fraud pattern involving impersonation and OTP exploitation. The circular mandates that banks link financial transaction approvals to unique, per-transaction OTPs rather than reusing previously accepted codes. Additionally, banks are required to establish financial caps on prepaid mobile top-ups and digital product purchases while enhancing monitoring systems to detect similar fraudulent patterns.
Circular No. (165/2025)
To all banks operating in Palestine
Date: Tuesday, December 02, 2025
The Palestine Monetary Authority urges banks to exercise caution and vigilance regarding a fraudulent style and pattern recently identified based on cases of electronic financial fraud experienced by some citizens, which is summarized as follows:
Citizens receiving calls and/or messages via social communication and contact platforms from individuals impersonating employees working at financial institutions such as banks and electronic payment companies, with the aim of defrauding citizens and obtaining their data through deception and false promises of winning financial prizes, activating applications, or obtaining bank cards or electronic watches, etc.
Fraudsters exploiting citizens' data and some systems accepting the registration of financial movements on customer accounts based on a previously accepted verification code (OTP) instead of linking the authentication of accepting such movements to a verification code specific to each movement. This resulted in multiple and repeated prepaid mobile balance top-up transactions in one day in favor of Palestinian mobile phone numbers, either with the same value or with different amounts.
With the Palestine Monetary Authority's keenness to limit the misuse of the statement display and settlement system services in transferring operations related to electronic financial fraud, and to prevent citizens from falling victim to fraud operations and losing their money, the Palestine Monetary Authority confirms the necessity of taking the necessary measures and controls to limit risks, including:
Linking the acceptance of executing financial movements to the verification code (OTP) specific to each movement, and not allowing new financial movements to be carried out based on a previously accepted verification code.
Setting financial caps for carrying out prepaid payment movements on the system; specifically, prepaid mobile balance top-ups and the purchase of digital products, with the caps being commensurate with the nature of the services and distinguishing between natural and legal customers in accordance with the provisions of Article (8) of Instructions No. (9) of 2024.
Providing scenarios on continuous monitoring systems that serve to detect any similar electronic fraud movements based on the identified patterns and cases.
Supervision Group
Palestine Monetary Authority
Ramallah & Al-Bireh Governorate - Palestine P.O. Box 452
Ramallah & Al-Bireh Governorate - Palestine P.O. Box 452
Postal Code: P6160675 | Phone: +970 2 2415251 | Fax: +970 2 2415310 | info@pma.ps