印度儲備銀行針對數位支付實施更嚴格的安全性規定
RBI Introduces Stricter Security for Digital Payments
於2026年4月1日,印度儲備銀行(Reserve Bank of India, RBI)針對數位支付啟動了一項重大的安全性改革。
On April 1, 2026, the Reserve Bank of India (RBI) launched a major security overhaul for digital payments.
為打擊日益猖獗的網路釣魚與詐騙,RBI現在強制規定所有交易,包括統一支付介面(UPI)與行動錢包,皆必須採用嚴格的雙重身份驗證(2FA)架構。
To combat the rise in phishing and fraud, the RBI now mandates a strict Two-Factor Authentication (2FA) framework for all transactions, including UPI and mobile wallets.
過去,僅需簡單的簡訊一次性密碼(OTP)等單因子驗證即可,但這些方式已被認為不夠安全。
Previously, single-factor methods like simple SMS-based OTPs were enough, but they are no longer considered secure enough.
根據新規則,使用者必須提供兩種獨立的驗證形式,例如使用者所知的資訊(PIN碼)、使用者擁有的物品(註冊裝置),或是使用者本身的特徵(如指紋等生物識別技術)。
Under the new rules, users must provide two independent forms of verification, such as something they know (a PIN), something they have (a registered device), or something they are (biometrics like fingerprints).
