Friday, July 31, 2026
spot_img
HomeThai banks block screenshots in security push

Thai banks block screenshots in security push

New rules leave customers confused but aim to curb soaring app fraud losses

THAILAND – A new ban on taking screenshots in Thai mobile banking apps left customers across the country confused, even as banks argued the move was vital to fight cybercrime.

Black screen shocks banking app users

On a humid Tuesday morning in Hua Hin, German retiree Fred tried to transfer his monthly rent of 25,000 Baht via his Thai banking app and then save a screenshot as proof, as he always did. Instead of the usual flash and click, a warning appeared and his display turned black, informing him that screenshots were blocked for security reasons. The uncertainty was immediate: he did not know whether the transfer had gone through or how he would prove the payment to his landlord in a country where the digital transfer slip is central to everyday transactions.

Nationwide rollout sparks irritation

Across social networks and online forums, users from Kasikornbank, SCB, Krungthai and Bangkok Bank reported the same experience. Thailand’s financial institutions had implemented the restriction almost simultaneously, leaving many customers feeling patronised and disrupted in their daily routines. The sudden, sector-wide measure significantly changed payment habits in a society where QR codes and instant transfers are used from street food stalls to car dealerships.

Poor communication blamed for confusion

Many users said they had received no clear advance notice of the change. While short notes appeared in app-store update descriptions, few customers read this fine print before handling their finances, leading to awkward scenes at checkouts and hotel receptions when people could not show proof of payment as usual. Critics argued that banks should have explained the change more prominently and prepared merchants and the public for the loss of manual screenshots.

System tools turned into security shield

From a technical standpoint, the black screen was not a bug but a deliberate use of operating-system permissions now deployed across the banking sector. On Android, Google’s “Flag Secure” function – long familiar from video-streaming apps – was activated so that any attempt to capture the banking screen would produce only a blank image. Thai banks framed the move as a standard that would increasingly define how sensitive financial apps operate.

Response to rising cybercrime threat

By 2025, Thailand had been battling a sharply deteriorating threat landscape in the digital sphere, with cybercriminals relying on increasingly sophisticated tools. The shift was no longer limited to simple phishing emails but included complex malware that penetrated victims’ smartphones. Under growing pressure to protect deposits, all banks were required to take more aggressive steps against fraud.

Remote access Trojans in the crosshairs

One of the most dangerous tools cited by security experts were so‑called Remote Access Trojans, or RATs. These programs allowed attackers to watch an infected phone’s screen remotely, following every step as users opened banking apps, viewed balances and entered passwords. By blocking all forms of on‑screen recording and photography, banks aimed to ensure that any such malware would see nothing but a black surface instead of live financial data.

Central bank tightens cybersecurity rules

The Bank of Thailand (BoT) significantly tightened its cybersecurity guidelines for 2025 and 2026, making robust protective measures mandatory. Financial institutions were obliged to act proactively to reduce fraud or risk substantial penalties if they were found to have left preventable security gaps unaddressed. The sector‑wide screenshot ban was presented as compliance with these more stringent central bank requirements.

Billions lost to app-based fraud

Figures from the previous year showed app‑based fraud caused losses amounting to several billion Baht, equivalent to hundreds of millions of euros. Many victims lost their entire savings after criminals gained full access to their accounts. Banks argued that, faced with such sums, they had little choice but to harden mobile apps, even at the cost of customer convenience.

Usability concerns remain

Despite the security rationale, criticism of user‑friendliness persisted. Observers noted the familiar tension between safety and convenience, with customers experiencing the measure first as a restriction rather than a protection. Banks faced questions about whether less disruptive solutions could have delivered similar security without abruptly overturning established payment habits.

Android hit harder than iOS

The impact was felt most strongly by users of Android phones, whose more open architecture made them both more flexible for developers and more exposed to malware. Apple iPhone owners experienced different, often tighter, system‑level controls under iOS, which already restricted access in some sensitive app areas. Nonetheless, the general trend on both platforms pointed toward stricter rules for security‑critical applications.

Data protection law adds extra pressure

Thailand’s Personal Data Protection Act, the PDPA, also played a role in the policy shift. Banks were legally obliged to handle customers’ personal data with the highest care, including information contained in payment confirmations. A screenshot that automatically synced to cloud storage or was shared via insecure messaging apps could create a potential data leak, so preventing manual captures was framed as a way to limit uncontrolled spread of financial information.

Security expectations versus comfort

Analysts highlighted a psychological paradox among users who demanded maximum protection but were reluctant to surrender familiar shortcuts. Outrage was loud when accounts were emptied by fraudsters, yet similarly strong when banks introduced measures designed to prevent such losses. Institutions were urged to explain more clearly why certain functions had to be restricted and how these steps shielded customers from unseen threats.

Built-in E-Slips replace manual screenshots

The controversy centred on one question: how could people prove payments without screenshots? Industry observers stressed that almost all Thai banking apps, including K-Plus, SCB Easy, Krungthai Next and Bualuang mBanking, already generated a built‑in electronic proof of payment. Many users had simply ignored or overlooked this E‑Slip function because manually taking a screenshot had long felt quicker.

Automatic receipts stored in the gallery

Once a transfer was successfully completed, the apps automatically created a colourful electronic slip containing all key details. If the correct permissions were granted, this image was saved directly to the phone’s photo gallery without any extra step from the user. The stored slip, complete with transaction data, served as a ready‑made proof that could be shared via messaging apps just like a traditional screenshot.

Permission settings decide what users see

Problems typically arose when customers had denied the app access to photos or storage during initial setup, often out of privacy concerns. Without this right, the software could not save the E‑Slip locally, and when manual screenshots were also blocked, users were left with no visible record at all. The practical solution lay in revisiting system settings and adjusting permissions rather than disabling security features.

How to restore visible payment proofs

To restore automatic receipts, customers had to open their phone settings, select the relevant banking app and grant access to “Photos” or “Storage”. After that, each successful transfer generated a new image file, usually including QR codes for verification, the date and time and both parties’ account details. According to banks, this format was harder to forge than simple screenshots and was widely accepted by merchants and public offices.

Security standards set to tighten further

Industry observers expected that the Thai measures would soon become standard for financial apps across Southeast Asia. E‑wallets and other payment providers were likely to follow, if they had not already implemented similar rules. Over time, users would have to get used to banking apps behaving more like high‑security facilities than social media platforms.

Biometrics as next step

Looking ahead, experts saw potential for biometric systems to reduce the need for visual payment proofs altogether. Systems were already being developed to confirm transactions directly between buyer and seller devices via facial recognition or fingerprint authentication, without sending images. Until such technology became commonplace even at the smallest noodle stall in Bangkok, however, the E‑Slip would remain the standard evidence of payment.

What tourists and expats should check

For tourists and expatriates, the changes meant they needed to review banking‑app permissions before reaching the checkout. Ensuring that automatic saving of electronic slips was active, and testing it with a small transfer, could prevent stressful situations in an unfamiliar country. Those who relied on old screenshot habits risked standing at the counter without any proof of payment.

Greater responsibility for users

Commentators noted that part of the responsibility was shifting back to account holders themselves. Customers had to adapt to using the tools as designed rather than clinging to improvised workarounds that had never been the safest option. The adjustment demanded some relearning but promised better protection for personal funds in the long term.

Black screens as deliberate protection

The controversy over the screenshot ban was described as understandable yet, on closer inspection, largely unfounded. Banks argued they were not taking anything essential away but forcing customers to rely on the secure, integrated proof of payment instead of fragile shortcuts. The black screen was presented as a deliberate barrier against modern forms of digital crime, not a malfunction.

For one worried customer, a simple answer

Back in Hua Hin, Fred eventually opened his phone’s photo gallery after his initial shock had subsided. At the top of his recent images, he found the colourful transfer receipt from his bank, saved automatically just before the warning message appeared. His worries had been unnecessary, and the technology had worked exactly as intended, only in a different way than he was used to.

Editorial note on changing rules

The developments described were based on then‑current technical standards and security policies at Thai banks, as well as Bank of Thailand guidance as of November 2025. Readers were advised that app functions and legal requirements could change at short notice and to check official communications from their institution regularly for updates.

RELATED ARTICLES

Most Popular

Recent Comments