CIMB to Require Biometric SecureTAC from Sept 2026

September 03, 2026 subimpact team 0 comments

CIMB to Require Biometric SecureTAC from Sept 2026

CIMB SecureTAC Biometric Authentication Requirement

CIMB SecureTAC is a transaction approval security feature used by CIMB Bank to verify online banking activities. Effective 19 September 2026, CIMB will require customers to authenticate SecureTAC requests using biometric methods (Face ID or fingerprint) or their device passcode through the CIMB OCTO app. This change eliminates password-based authentication for transactions initiated via CIMB Clicks Web and merchant websites, addressing the need for enhanced security in digital banking transactions.

CIMB will require biometric SecureTAC approvals for online transactions starting 19 September 2026, removing password authentication as an option.

Key Facts

AttributeValue
Effective Date19 September 2026
Authentication MethodsFace ID, fingerprint, or device passcode
ApplicationCIMB OCTO app
Affected PlatformsCIMB Clicks Web and merchant websites
Removed MethodPassword authentication
Prior ImplementationMandatory SecureTAC approvals introduced January 2026
Failed Approval ImpactNo suspension of Clicks ID; no funds deducted

What Is Changing with CIMB SecureTAC Approvals?

Starting 19 September 2026, CIMB will require customers to use biometric authentication or their device passcode when approving SecureTAC requests for transactions made through CIMB Clicks Web and merchant websites. The password option previously available through the CIMB OCTO app will no longer be supported as an authentication method for these approvals.

The bank has removed the password option entirely, leaving biometric authentication and device passcodes as the only supported methods from 19 September onwards. CIMB's current notice also states that the requirement will apply to all transactions made through CIMB Clicks Web and merchant websites, rather than referring to them as only selected transactions as in its earlier announcement.

From 19 September 2026, CIMB SecureTAC approvals will only accept biometric authentication or device passcodes, with password authentication fully discontinued.

How Will Users Authenticate SecureTAC Requests?

Customers can authenticate SecureTAC requests using Face ID, fingerprint, or their device passcode through the CIMB OCTO app. When a transaction is initiated on CIMB Clicks Web or a merchant website, a SecureTAC notification will be sent to the primary device linked to the app, where users can review the transaction details before choosing to approve or reject it.

If the transaction is approved, users will then need to verify their identity using one of the supported biometric methods or their device passcode. CIMB said customers who have not enabled any of these authentication methods will receive an error message and will need to set one up before retrying the transaction.

"Customers who have not enabled any of these authentication methods will receive an error message and will need to set one up before retrying the transaction."

— CIMB official notice

Users must have Face ID, fingerprint, or a device passcode enabled on their primary device and available for use with the CIMB OCTO app before the new requirement takes effect.

What Led to This SecureTAC Change?

This latest change follows CIMB's introduction of mandatory SecureTAC approvals for selected transactions made through CIMB Clicks Web and merchant websites in January 2026. At the time, customers could authenticate these requests using biometrics, their device passcode, or their CIMB OCTO app password.

The bank has now removed the password option, leaving biometric authentication and device passcodes as the only methods supported from 19 September onwards. CIMB recommends that customers ensure Face ID, fingerprint, or a device passcode is enabled on their primary device and available for use with the CIMB OCTO app before the new requirement takes effect.

CIMB's January 2026 implementation of mandatory SecureTAC approvals initially allowed passwords, but the September 2026 update removes this option entirely.

Who Is This For?

This requirement applies to all CIMB customers who conduct transactions through CIMB Clicks Web and merchant websites. Users must have the CIMB OCTO app installed on their primary device with biometric authentication (Face ID or fingerprint) or a device passcode enabled to complete SecureTAC approvals.

The bank also states that a failed SecureTAC approval will not suspend a customer's Clicks ID, and no funds will be deducted when an approval fails. This provides assurance to customers who may encounter technical issues during the authentication process.

All CIMB customers using CIMB Clicks Web or merchant websites must enable biometric authentication or a device passcode on their primary device before 19 September 2026.

Common Questions

What happens if I have not enabled biometric authentication or a device passcode?

Customers who have not enabled any of these authentication methods will receive an error message when attempting to approve a SecureTAC request. They will need to set up Face ID, fingerprint, or a device passcode before retrying the transaction.

Will my account be suspended if a SecureTAC approval fails?

No. CIMB states that a failed SecureTAC approval will not suspend a customer's Clicks ID, and no funds will be deducted when an approval fails. This applies to the new biometric and device passcode requirements.

Does this requirement apply to all transactions or only selected ones?

CIMB's current notice states that the requirement will apply to all transactions made through CIMB Clicks Web and merchant websites, rather than referring to them as only selected transactions as in its earlier January 2026 announcement.

Sources and Methodology

This article is based on the official CIMB notice regarding SecureTAC approval requirements for online transactions, as reported by Lowyat.NET. The primary source is CIMB's official notice published at cimb.com.my, referenced in the original article dated 2026.

This article was last updated on 19 September 2026.

Twitter Facebook
Link copied to clipboard!