Uzbekistan

Uzbekistan to ban P2P transfers via websites

Starting November 16, new rules for P2P transfers will come into effect in Uzbekistan, including a ban on transactions through websites and blocking cards when logging in from a new device.

On November 16, updated regulations designed to strengthen the protection of financial services users from cyber fraud will come into effect in Uzbekistan. Specifically, credit and payment institutions will be prohibited from making P2P transfers through websites, and linked bank cards will be temporarily deactivated when logging into an account from a new device.

Credit and payment institutions will have the right to independently set the maximum P2P transfer amount that a user can make without confirmation with a one-time password (OTP code) or other authentication method. The limit will be determined based on the risk management policy of the individual institution.

Credit and payment institutions will be held liable for fraudulent transactions conducted without additional confirmation.

The new requirements also impose additional measures when logging into the mobile app from another device. To retrieve the password for an existing account, the user will be required to undergo biometric identification. A similar procedure will apply when attempting to log into the account from a new device. When logging in from a different device or resetting a password, all bank cards linked to the account must be automatically deactivated. Reactivating them will require confirmation using an OTP code.

Special requirements have been established for threats detected on a mobile device. If a financial institution detects malware or signs of remote device control, it must immediately send the user a push notification and SMS.

The message must inform the client of the need to contact the credit or payment institution to clarify the circumstances.

Additional confirmation will also be required before conducting financial transactions in a mobile app. Before confirming a transaction, the institution must display a warning to the user, after which the client independently confirms that the transaction is being carried out without fraudulent interference.

The new rules also establish requirements for the display of personal data of bank cardholders. In mobile apps, the cardholder's first and last name must be partially obscured. This requirement also applies to the data of participants in money transfers: information about the sender and recipient must also be displayed with their personal data partially obscured.

Cookies on xabarchi

We use cookies to remember your language and theme, and to count how many people are reading right now — that count is anonymous, lasts only while your browser is open, and cannot be tied to you or to another visit. With your permission we also measure how the site is read: Microsoft Clarity, which records page views and on-page interactions, and our own count of returning readers. Nothing that recognises you across visits is measured until you accept.