As of mid-September 2026, millions of customers will lose access to the ING mobile banking app, a significant action taken in response to the sharp increase in cyberattacks targeting smartphones. This decision underscores the importance of security in today’s digital banking landscape.
Stricter Security Requirements Starting September
From September 15, 2026, the ING app will no longer support older operating systems. Smartphones running Android 9 or 10 and iPhones without iOS 16 will be left behind. Customers who wish to continue using mobile banking will need to upgrade to Android 14 or iOS 17; however, Android 11 and iOS 16 will still be temporarily acceptable.
For those unable or unwilling to replace their devices, ING offers an alternative: a photoTAN generator. This allows customers to continue their online banking activities, albeit without the convenience of the app.
Demand for Transparency with Google Pay
ING finds itself under increasing pressure, not only technically but also legally. A Dutch court recently mandated the bank to disclose its contract with Google Pay. Consumer protection groups, including the Consumentenbond and the Foundation for Victims of Scams, filed the lawsuit.
The court calls for full transparency regarding how customer data is shared with third parties for contactless payments. This case may set a precedent across Europe, potentially affecting similar lawsuits against German banks.
The Surge in Mobile Fraud
ING’s decision is not without significant reasoning, as the threat landscape has escalated dramatically:
NFC attacks on Android devices rose by an astonishing 188 percent within the first four months of 2026, compared to the previous year. Kaspersky security experts recorded approximately 35,600 such attacks, more than double the count from the previous year. Europe and Latin America are particularly affected.
The statistics reveal an alarming trend globally:
- SMS fraud in India increased by 146 percent in the first half of 2026.
- Mobile fraud instances surged by 67 percent, with iOS devices showing a particularly alarming 86 percent increase.
- Fake apps: In Kanpur, authorities arrested an individual who used artificial intelligence to create 121 counterfeit banking APKs. These malicious programs disguised as legitimate apps like PNB One infected over 21,000 devices, causing extensive financial losses.
International Shifts in Cybersecurity Standards
Financial institutions worldwide are following suit. In Vietnam, customers of VPBank and VietinBank must transition their authentication processes by July 30, 2026. New central bank regulations require six-digit Smart-OTP and Soft-OTP codes, each valid for a maximum of twelve months.
Nigeria’s central bank is pushing for enhanced cybersecurity frameworks. Customers are advised to regularly change their access credentials to mitigate risks associated with phishing and credential stuffing.
ING Turkey Sets a New Standard
As security measures tighten elsewhere, ING’s Turkish subsidiary is loosening fee structures. SWIFT transfers through digital channels will now be free of charge, as will euro transfers. Additionally, the first non-euro transfer each month will not incur fees. CEO Alper Gökgöz regards fee-free digital transactions as the new industry standard—a stance that is likely to spark discussions in Germany.

