ai

The Silent Weaponization of AI: Why Your SMS OTP is No Longer Safe

By Daffa Albari · 6 March 2026 · 4 min read

The Silent Weaponization of AI: Why Your SMS OTP is No Longer Safe
https://cdn.prod.website-files.com/68650bdba2ff739d61a213d9/697346bfc38af291dccf3cee_Captura%20de%20pantalla%202026-01-23%20a%20las%2011.00.24.png

We live in an era where technology that once felt like science fiction is now being turned against us at scale. A few years back, deepfakes were clumsy — grainy videos that made people laugh more than worry. Today, they’re so convincing that scammers can whip up a hyper-realistic clone of your boss’s voice in minutes and use it to trick someone into wiring millions.

I recently listened to a sobering conversation on the Endgame podcast between host Gita Wirjawan and Niki Luhur, the founder of VIDA (a digital identity company in Indonesia). What struck me most wasn’t just the tech — it’s how everyday “secure” habits we all rely on are now the weakest links.

Here’s the reality check: if you’re still depending on passwords and SMS one-time passwords (OTPs) to protect your bank account, you’re playing a game that’s already rigged.

The Era of Industrial-Scale Deception

Gone are the days of obvious fakes. Criminals now operate like factories. With just a short clip of someone’s voice — maybe from a podcast appearance, LinkedIn video, or even old social media posts — AI tools can generate a near-perfect clone. In under five minutes, scammers can sound exactly like your CEO calling in a panic about an “urgent transfer.”

But it’s not just voice. They layer in hyper-personalization: analyzing your online behavior, writing style, even psychological patterns to craft messages that feel eerily personal. No more generic “Dear Customer” spam — these attacks are tailored to make you drop your guard.

And the countermeasures? Criminals are already one step ahead, using “adversarial noise” — tiny, invisible tweaks to images or audio that fool detection AI while looking normal to the human eye.

The Real Problem: Our “Security” Tools Are the Targets

Niki put it bluntly: “If you still believe that a password is a secure factor, that’s questionable. If you believe an SMS OTP is secure, the proof is that it’s the number one target for phishing today.”

Why? SMS is fundamentally insecure. Scammers don’t need to hack your phone — they just need to intercept or spoof the message.

One of the scariest tactics is the rogue BTS (Base Transmitter Station). Fraudsters load up a van with fake cell towers and drive through neighborhoods. Your phone automatically switches to the strongest signal, which happens to be theirs. Suddenly, they’re in the middle of your conversation thread with your bank. You get a real notification… followed by a fake link that looks identical because it’s in the same SMS chain.

To your phone (and your eyes), it’s indistinguishable from the real thing.

The Dark Underbelly: Scam Compounds and Forced Labor

Cybercrime isn’t a lone wolf in a basement anymore — it’s big business. Recent busts have uncovered syndicates sitting on billions in stolen crypto. Behind the screens? Often victims themselves: software engineers, data scientists, even young graduates lured by fake job ads, trafficked across borders, and forced into “scam compounds” where they work brutal hours under threat to hit quotas.

It’s a chilling human supply chain fueling an industry worth trillions in potential damage.

What Comes Next? Innovation, Not Reinvention

In the global AI race — dominated by the US and China — developing economies like Indonesia can’t afford to chase foundational models from scratch. That takes insane compute power and capital we don’t have.

Niki’s advice is pragmatic: focus on innovation over invention.

  • Ditch SMS OTPs entirely. Move to biometrics + device-bound cryptography like Passkeys (think Apple’s or Google’s passwordless login).
  • Build regional digital trust infrastructure — systems for secure, cross-border identity verification that don’t rely on fragile phone numbers.
  • Adopt zero-trust everywhere: assume data will leak, so protect the encryption keys instead.

Final Thoughts

Trust is the foundation of any digital economy. Once it’s gone, everything slows down — commerce, banking, even everyday communication.

Telling people “don’t click suspicious links” isn’t enough anymore; the links look too real, the voices sound too familiar, the threads appear too legitimate.

We need systemic change: better standards for verifying identity in a world full of AI-generated ghosts.

The conversation with Niki Luhur was a wake-up call. The tools that once kept us safe are now the very things being weaponized against us. The question isn’t if this will touch you — it’s when, and whether we’ll have upgraded our defenses by then.

References:

https://medium.com/media/6c752a300f5bcf8aba4422539b979e79/href

Share this piece

Originally published on Medium. View original →