: This directive, which came into full effect in September 2019 , forced banks to implement Strong Customer Authentication (SCA). Many banks chose SMS-OTP as the most accessible second factor for compliance [6]. 3. Security Risks Identified in 2019 Research
While there isn't a single definitive official document titled exactly "SMS Verification Method 2019.pdf," research from that year focused heavily on the framework and its vulnerabilities. A key paper from July 2019 titled Two Factor Authentication Framework Using OTP-SMS Based on Blockchain addresses the common security and management issues of SMS-OTP [20].
: A common social engineering attack where a hacker tricks a mobile carrier into porting the victim's phone number to a new SIM card [8].
: Proposals for 3D-AES block cipher and other end-to-end encryption methods sought to secure the SMS content itself during transmission [21].
Papers from this era, such as On the Security Verification of a Short Message Service Protocol , highlighted that SMS is not inherently secure because it travels over unencrypted mobile networks [35].