What's so difficult??
1. Create ocbc clone site to capture login id, pin and otp.
2. Send sms to sinkies. "New transfee added, click on link to login and verify".
3. Sinkie sheep login with id, pin on clone site.
4. Hacker captures info real time, login on OCBC app or real site concurrently.
5. Sinkie/Hacker triggers SMS otp on clone and real site respectively.
6. Sinkie input real OTP on clone site.
7. Hacker enters Sinke's OTP on real site.
8. Hacker successfully login, ACTIVATE DIGITAL TOKEN and take over account.
9. Hacker adds new payee, increase daily transfer limit, empties account.