Kuwait Press Memory Latest news
alanbaGeneral News

From password strengthening to the 'Fraud Shield': How Kuwait Safeguarded Bank Customers' Funds

From password strengthening to the 'Fraud Shield': How Kuwait Safeguarded Bank Customers' Funds

Tareq Arabilim: Protecting bank customers’ funds in Kuwait from fraud no longer relies solely on warning customers not to share their banking data or verification codes. It has become part of a comprehensive supervisory and technological system that spans from the moment a customer logs into their account until the payment transaction is executed, covering cards, text messages, payment links, and cybersecurity.

Over the years, this system has evolved in tandem with the development of electronic fraud methods, gradually shifting from enhancing the security of banking services to building tools aimed at detecting and preventing fraud before it occurs.

This system began early on. The Central Bank of Kuwait (CBK), in its review of measures taken to protect customers, noted the implementation of the two-factor authentication principle for bank websites and related applications in 2009, providing an additional layer of protection against unauthorized access to electronic banking services. As the use of digital services expanded, the CBK continued to tighten security requirements to cover all stages of a customer’s interaction with their account, cards, and financial transactions.

In 2011, the scope of protection broadened to include customer rights and mechanisms for addressing their issues, through the establishment of specialized complaint units at banks and financing companies. This provided an institutional channel for handling and resolving customer complaints. This was followed in 2013 by the introduction of a 24/7 hotline for inquiries, complaints, and feedback, offering customers a direct channel to communicate with the regulatory authority regarding any issues or questions related to banking services.

In 2015, the CBK issued the Bank Customer Protection Guide, establishing a structured framework for the relationship between banks and customers and reinforcing a set of principles related to transparency, professional conduct, and customer protection. The guide’s role did not stop at regulating the relationship between the two parties; it later evolved to give greater emphasis to addressing fraud risks. The Customer Protection Guide emphasizes banks’ responsibility to protect customers’ deposits, savings, and financial assets within the scope of their transactions with the bank, through effective internal control systems capable of curbing fraud, embezzlement, and the misuse of financial services.

With the growing reliance on cards and online shopping, protection measures entered a phase more closely tied to customers’ daily transactions. In 2017, the CBK tightened regulations regarding bank cards and electronic purchases. Key measures included prohibiting the execution of transactions via phone or internet unless a verification code was entered, implementing the 3D Secure system for approving online purchases, setting controls on incorrect password entry attempts, and issuing cards that could not be used until activated by the customer. Consequently, multiple layers of verification were added before allowing a banking transaction to be completed.

In 2018, another tool was introduced that made the customer an integral part of the monitoring system, by mandating banks to provide short message service (SMS) notifications. This enhanced customers’ ability to monitor their banking transactions and detect unusual activities more quickly. This service allows customers to know about transactions executed on their accounts immediately, rather than discovering them later when reviewing their account statements.

As risks shifted from fraud at the level of individual transactions to broader electronic threats, protection in 2020 moved to a more comprehensive level with the CBK’s announcement of the completion of the strategic framework for cybersecurity in Kuwait’s banking sector. The framework aimed to establish an integrated system for dealing with cyber risks and enhancing information security protection in the banking sector, in line with the rapid development of technology and digital banking services.

Results from the implementation of the framework showed that protecting electronic payment systems has become a core pillar of cybersecurity supervision in the sector. The CBK’s Financial Stability Report indicated that supervised entities complied with the security controls outlined in the framework during the first implementation cycle (2020–2021). Furthermore, the entire banking sector obtained ISO/IEC 27001 certification for information security management in 2021, including “Cybernet” and “K-NET.”

Alongside technical hardening, the CBK strengthened the defense line related to the customer themselves in 2021 through the “Let’s Be Aware” campaign, which aimed to raise banking and financial awareness and protect society from electronic fraud methods. This approach continued in subsequent years, focusing on enhancing customers’ ability to recognize fraudulent methods and interact safely with digital banking services.

With the proliferation of electronic payment links, this tool became a new focal point within protection measures. In 2023, regulations governing the electronic payment link service for individual customers were tightened. These included displaying the beneficiary’s details in the account statement, limiting the validity of payment links to 24 hours, and setting daily and monthly caps on the value of transactions that can be executed through these links. These measures were introduced to mitigate risks associated with using payment links for electronic transactions.

In June 2024, controls took an additional step toward empowering customers to know the details of the funds they will pay and the recipient before completing the transaction. The CBK mandated relevant entities to display payment transaction details to the customer before proceeding to the payment gateway. These details must include the transaction amount, the beneficiary’s name, and the purpose of the transaction, along with obtaining the customer’s prior consent. Additionally, the transaction amount was required to be included in the one-time password (OTP) message, enabling customers to match the value shown in the message with the transaction they are executing.

The year 2025 saw the protection system transition to a stage aimed at developing more advanced tools for the early detection and prevention of fraud. The CBK launched the “Fraud Shield Initiatives Acceleration Program,” which aims to enhance the detection and prevention of electronic financial fraud. This initiative involves participation from banks, payment service providers, fintech innovators, and regulatory authorities, with the goal of developing innovative solutions to protect financial transactions and customers.

In the same year, the supervisory framework for customer protection was strengthened. The updated Bank Customer Protection Guide, issued in October 2025, confirmed that combating financial fraud has become a clear part of banks’ responsibilities. This is achieved through effective internal control systems and continuous review of their effectiveness to keep pace with changing fraud methods, alongside protecting financial and personal information and providing secure systems for electronic transactions.

The protection system completed its updates in December 2025 with the issuance of the Cyber and Operational Resilience Framework for Banks and Local Financial Institutions, replacing the Cybersecurity Framework for the Banking Sector issued in 2020. This reflects the ongoing development of regulatory requirements to address evolving risks.

Thus, the journey of banking protection in Kuwait reveals a gradual transformation from securing the customer’s means of accessing their account to building a multi-layered “fence” around their funds, data, and transactions. This begins with secure login and multi-factor authentication, extending to card protection, instant alerts, cybersecurity, payment link controls, and awareness campaigns, culminating in advanced tools for fraud detection and prevention. With the launch of the “Fraud Shield” and the update of the Cyber Resilience Framework, the focus has shifted more toward detecting and preventing fraud attempts early, rather than merely dealing with their consequences after damage has occurred.

Latest news Original source
Link copied ✓