JagaShieldBahasa Malaysia

I gave my TAC/OTP to someone — what now

Last verified: 20 Aug 2026

Call your bank's fraud hotline immediately — don't wait to see if anything happens. If the scammer also has your login details, use your banking app's kill switch to freeze your accounts and cards. If money has already moved, call 997 too. No bank or government agency ever legitimately asks for a TAC/OTP; if someone already has yours, the priority now is speed, not shame.

First: this is fixable, and speed is what matters

No bank, and no government agency, will ever legitimately ask you for a TAC (transaction authorisation code) or OTP (one-time password). If someone already has yours — whether you were tricked by a fake call, a phishing link, or a message pretending to be your bank — what matters now is acting fast, not how it happened. Don't spend time on shame or self-blame; spend it on the steps below.

Step 1 — Call your bank's fraud hotline right now

Do this first, before anything else, even if you're not certain anything has been taken yet. Tell them you shared a TAC/OTP and ask them to watch your account and block any suspicious transaction. Every major bank in Malaysia has a 24-hour fraud line — call it immediately rather than waiting to see what happens.

Step 2 — Use the in-app kill switch if your login is also exposed

Banks are required by BNM to provide an in-app kill switch that freezes your own accounts and cards — use it if the scammer has your login details as well as the TAC/OTP. Exactly what it covers varies by bank, so check yours in your banking app or on the banks directory.

Step 3 — If money has already moved, call 997

If you can already see an unauthorised transaction, call 997 (the National Scam Response Centre) as well, and lodge a police report. We cover that full sequence — evidence to keep, how to raise a recall, what recovery realistically looks like — in the first 24 hours guide. Follow it in full rather than guessing the order.

Step 4 — Check your device and change your credentials

From a device you're confident is clean, change your banking app's password or PIN. Check your phone for apps you don't remember installing, or active sessions/devices logged into your banking app that aren't yours. If the TAC/OTP was shared around the same time you installed something (an APK, especially one sent via WhatsApp), that needs its own urgent steps — see I installed an APK from WhatsApp before you do anything else on that device.

FAQ

I only gave the OTP, not my password — am I still at risk?

Yes. A TAC/OTP alone can authorise a transaction if the scammer already has other details (like your card or account number) from the same call or message. Call your bank's fraud hotline regardless of what else you think you shared.

Should I be embarrassed to call my bank about this?

No — bank fraud teams handle this every day, and the sooner you call, the more they can do. Nothing about explaining what happened will make your situation worse; waiting will.

What if the scammer asked for the OTP by pretending to be my bank?

Report this to your real bank's fraud line all the same — they need to know their brand is being impersonated, and they can flag your account regardless of how convincing the impersonation was.

Checklist

  • Call your bank's fraud hotline right now, even if you're not sure anything has happened yet
  • If the scammer also has your login, use the in-app kill switch to freeze your accounts and cards
  • If money has already moved, call 997 and lodge a police report — see the full steps
  • Check your phone for unfamiliar apps or active sessions, and change your banking password/PIN from a device you trust
  • If you installed anything (an APK) around the same time, treat that as a separate, urgent step