BDO: No system breach on vlogger’s alleged unauthorized transaction
MANILA, Philippines — BDO dismissed as “baseless” the claims of vlogger Maria Jamila Cristiana Gonzales Berenguer alleging a system compromise and insider role in unauthorized transactions.
In a statement on Thursday, the bank said that Berenguer admitted in an interview with ABS-CBN that her mobile device had been in the hands of other people at some point.
According to BDO’s investigation, a password reset was made on September 14, which was immediately followed by device registration. The reset and registration were validated through a one-time password (OTP) sent to Berenguer’s registered device a day before the reported unauthorized transactions.
The bank noted that there was no change in the mobile number used to receive OTPs, and Berenguer’s official device remained the one receiving official communications.
Log-in and registration alerts were also sent to Berenguer’s for these updates, while transaction alerts were also sent promptly on September 15—six hours before the issue was reported via the BDO Hotline.
The bank emphasized that transactions through BDO Pay require a PIN or biometrics, not an OTP. It explained that the OTP is required only for device registration, not for transactions using the platform.
BDO said that despite its repeated efforts to engage with Berenguer, she declined and continued to post several videos that it described as inaccurate.
The bank reiterates that transfer limits were not bypassed, and its security controls remain in place.
“BDO has put in place different features intended to protect clients’ accounts. These controls will not work if clients ignore warning signs and messages sent by the bank through official channels,” it said.
“BDO’s system remains secure, with no evidence of any breach or insider involvement,” it added.
