The Central Bank of Kuwait has told every local bank and KNET, the shared payments network, to show a minimum set of details whenever they ask you to authenticate something electronically, whether you are logging into a banking app or paying online. The aim, the circular says, is to cut fraud and the theft of logins and one-time codes.
What the message has to show
When money leaves your account: the time of the transaction, the beneficiary’s name, where the money is coming from (the last 4 digits of the card or account, masked), the amount and the purpose.
When no money moves, such as a login or a change to your details: the time, who is asking, and why.
Either way, the request must carry a clear warning not to share the one-time password (OTP) or any authentication content with anyone.
You choose the channel
Banks must let customers choose how codes and approval requests reach them, from the bank’s approved secure channels, including the bank’s own app and SMS. A bank may offer a fallback if the chosen channel fails, but only if it tells the customer about it in advance.
What to do
- Read the whole message before typing the code. If the beneficiary or amount isn’t what you expect, stop.
- Never give the code to anyone, even a caller who says they are from your bank.
- Check in your banking app where your codes are sent, and pick the channel that suits you once the option appears.
The Central Bank has asked banks to confirm compliance and put the requirements into practice across their channels and systems. The report gave no firm completion date.
Photo: a phone held to a contactless card terminal; a generic image. By Isidora.ilic, CC BY-SA 4.0 via Wikimedia Commons.
Source: Central Bank of Kuwait circular to banks and KNET, as reported by Al-Rai, 8 October 2026.
Kuwait One, once a week.
The most useful stories we published this week, in your inbox.
No spam. Unsubscribe anytime.
