Why Citi Mobile Token Is More Secure Than SMS
Unlike SMS-based verification codes — which can be intercepted through SIM-swapping attacks, SS7 network vulnerabilities, or social engineering of mobile carrier support staff — the Citi Mobile Token generates codes locally on your registered device using a cryptographic seed that never leaves the device.
The token is additionally protected by biometric verification (fingerprint or face recognition), meaning that even if your device is stolen, the attacker cannot generate valid authentication codes without your biometric. This dual-layer protection (device possession + biometric) satisfies the Federal Reserve's guidance on strong customer authentication for commercial banking platforms.
Token Management and Troubleshooting
New device: If you replace your mobile device, you must re-register the Citi Mobile Token. Contact your security administrator or call 800-285-1709 to initiate the re-registration process. You will receive a new QR code to bind the token to your new device.
Token not generating codes: Ensure your device clock is synchronized (Settings > Date & Time > Automatic). TOTP codes depend on precise time synchronization between your device and Citi's authentication servers. A clock offset of more than 30 seconds will cause code validation failures.
Biometric not working: If biometric verification fails repeatedly, the app will fall back to your device PIN/passcode. If all unlock methods fail, uninstall and reinstall the Citi Mobile Token app, then contact 800-285-1709 to re-register the token.
Hardware tokens: Organizations that prefer physical tokens can request RSA SecurID hardware tokens through their relationship manager. Hardware tokens use the same TOTP algorithm and are accepted at all CitiBusiness authentication prompts.