Russian banks reject mandatory confirmation of transactions via MAX messenger
Participants in Russia’s financial market have asked regulators to ease the requirements of the proposed “Anti-Fraud 2.0” law, which mandates that online transactions be verified simultaneously via SMS and the national messenger MAX.
According to a letter from the National Financial Market Council sent to the Bank of Russia and the government, bankers consider the rule excessive and costly, warning it could trigger multibillion-ruble increases in operational expenses and drive up service fees for clients, a Russian outlet reports.
Industry experts also highlighted technical and infrastructure risks, noting that reliance on a single channel could create a “single point of failure” for the entire online transaction system. Analysts argue that the measure is unlikely to substantially improve security, as most fraud today stems from social engineering rather than insufficient verification methods.
Market participants have suggested maintaining alternative authentication methods and either making verification codes free or establishing transparent pricing for their delivery. Cybersecurity specialists emphasise that push notifications, TOTP codes, and biometric verification remain more reliable, while SMS is increasingly considered a vulnerable channel.







