I haven’t seen a thread on this yet. It might be interesting/important for some.
In the media, including Yle, it’s often annoying that there is a lot of reporting on thefts, but the news just repeats the same obvious points without accurately explaining how the account was emptied. As far as I understand, some of it involves device hijacking, and it presumably has to target a mobile phone. If you are using a computer, the confirmation usually happens on your phone, so two devices would have to be compromised.
I suspect that in a large portion of these cases, the person themselves approves a transaction initiated by a thief. What puzzles me is that surely no one falls for that multiple times, and on the other hand, if it’s a large sum, 99.9% of people would notice that.
If anyone has any views on this, feel free to comment.
I have considered Nordea to be a bank that doesn’t really offer that many security-enhancing features (I personally have a reckless elderly relative for whom I would need various solutions, but instead, they keep pushing solutions that speed up and simplify money transfers, including international ones).
It’s worth mentioning, if anyone is interested, that Nordea does have one trick that I haven’t seen mentioned anywhere online. If anyone is interested, I can share it; I certainly hadn’t thought of it myself and wouldn’t have known to ask, but it came up during a call with customer service.
It is surprisingly easy to fall for it. You follow a Google suggestion to, say, a wellbeing services county (well-being area) website. They each have their own beautifully designed site and name, so an average Joe might not necessarily notice if there is one extra letter “i” in the address.
And the sites are 1:1 copies of the original; poor Finnish no longer exposes the scam.
Then you try to log in. You get a message on your phone: “YOU ARE INSTALLING THE APPLICATION ON A NEW DEVICE.”
Perhaps you dismiss the message and log in out of habit as you normally would: all your online credentials are lost, because now the scammer can log into anything using a new phone.
Maybe you are 70 years old and don’t understand the message due to a lack of IT skills, and you trust the official-looking government page. And everything is lost, everywhere.
Then the Bank washes its hands of it, declaring the fault is yours, and your life savings are gone.
It is infuriating how old people are forced online to the mercy of wolves and then not helped.
AI has already worsened the problem (though it has surely also helped in the background) and the scams are frighteningly complex. There have been cases where they have called pretending to be from the bank and provided the details of actual officials that can be found online.
I am not laughing at the subject at all; I saw firsthand what kind of distress my loved ones were in. It wasn’t far off that both could have even died from the stress and panic. One was in the hospital for a month. Fortunately, this story had a happy ending through a legal battle, but the bank did nothing but blame the elderly people from start to finish.
I believe every bank should offer the option to disable authentication using bank credentials. When you have credentials for multiple banks, the risk increases that someone could compromise the authentication. For me, Nordea is one bank that allows you to disable this, but other banks don’t really seem to offer any help with this.
Personally, I prefer having one set of credentials for authentication and daily purchases. I keep my savings in a different bank, and I don’t use those credentials for anything else.
And yes, any bank can remove strong authentication from your online banking credentials. You just have to ask.
To get back to the original topic, unfortunately, almost all scams are the result of a lapse in judgment by the victim themselves. I don’t think it’s the bank’s responsibility to reimburse you if you transfer money to a scammer or authorize a transfer yourself.
Whether or not this kind of service should be outsourced to banks is a different matter.
At least at S-Pankki, this wasn’t possible. And with OP, it’s somehow difficult; you have to make a separate agreement and visit a branch, I haven’t quite gotten around to that yet.
Yes, that is a good method, and I use it myself: I use an account at a different bank and do everything I can to keep the bank where I have my larger savings “quiet” and off the grid.
I looked into whether it would be possible to set up an account at Nordea that can only be accessed at a branch, but I concluded that it isn’t possible if you also have an online banking account. I didn’t actually ask customer service, though; I just interpreted it that way myself.
It’s true that almost all robberies are caused by the customers themselves. One tricky issue is device hijacking—for example, if you think you’re accepting cookies, but in reality, you’re downloading hijacking software. That could happen to anyone. Now, in the background, it’s likely that you’ve ended up on a fake website, but such a mistake can happen quite easily. I haven’t been able to tell from the news whether a single wrong click can download malware that “remotely reads” your online banking credentials while you’re using them, but I suspect it can.
You can certainly ask the bank to remove an account from your online banking view, which in principle keeps it safe if scammers gain access to your online banking.
Of course, one should strive to stay away from scam sites, but that is likely not how they work. To my knowledge, malware installed on phones almost without exception requires, for example on Android and Apple phones, that you confirm the installation yourself and grant the necessary permissions. That is why the proportion of scams where a device is hijacked is such an impossibly small piece of the whole.
With these rules, I would consider it likely that you are still quite safe:
Always think before you authenticate yourself anywhere (and perhaps use a different bank for daily purchases and authentication). Still, almost all scams rely on urgency, and by regularly taking 5 seconds to think before entering your credentials, you are almost a god in the eyes of scammers. Routine helps with this.
Do not give out your bank credentials to anyone. Unfortunately, bank scams still work well in Finland, meaning a person poses as a bank employee. A banker will never ask for your online banking username over the phone. I would also add that in the event of a scam, the bank will not ask you to transfer your funds to a “safe account” yourself. These scams seem ridiculously stupid when you read about them in the newspapers, but in a state of urgency and fear, many people don’t think at all.
These scams are indeed a huge problem in Finland and will continue to be. The aging population is certainly not up to speed on banking security, and there are hundreds of thousands of elderly people here whose assets are kept safe mostly by good luck.
Would it be time to separate bank credentials and strong authentication? A digital ID card for handling Kela, Tax, etc., matters and bank credentials for… banking matters.
Banks should create a separate “vault account” that is protected by the customer’s own password, known only to the customer. Larger amounts of money should be kept there, with only normal amounts used in other accounts/cards.
This vault account would protect actual savings. Of course, this would mean a bit more work for customer service, etc. And some people would naturally forget their password, etc. In those cases, they would just book an appointment at the bank and set a new password with their ID. A certain delay (e.g., 24–48 hours) could also be built into this vault account so that money wouldn’t transfer immediately; instead, a notification about the transfer would be sent first, and it would additionally require confirmation. This would prevent money from being transferred without the holder receiving a notification or without requiring further confirmation.
Time protection (Aikasuoja) could also be implemented by allowing the customer to specify the accounts from which payment due dates could be set to a minimum of, for example, 5–10 days in the future.
A couple of years ago, I asked a finance expert whether it is safe to use mobile devices for managing finances and investments. Apparently, the iPhone is extremely well-protected, as long as you use mobile data. I didn’t ask about Android. Wi-Fi can be a weak link. You should definitely change your own Wi-Fi password/set it yourself as soon as you start using it, because your Wi-Fi connection can be used via the default password for things like botnet attacks without you even noticing. And probably for other malicious acts besides cyberattacks, since that allows access to your devices.
But it was reassuring to hear that the phone/iPad itself is quite secure as long as you keep the device’s operating system and the bank’s mobile app updates up to date. It is likely, however, a constant race between bank IT departments, F-Secure, and similar security service providers, and the scammers.
You should absolutely change the password to a secure one when setting up the device. In addition, you should turn off Remote Management in the settings, unless you have a specific reason to use it. This prevents unauthorized login attempts to the router’s admin page.
In principle, both mainstream mobile platforms (iOS, Android) are significantly more secure than the average Windows computer. If you ask any credible cybersecurity expert, you will get the same opinion.
This is simply because the operating system was designed from the start with a fundamentally different security model than traditional operating systems, where software—including malware—running in the same user session can freely access all of the user’s data, meaning they are not isolated from each other (sandboxing). In other words, once malware has managed to nest itself on the computer, no vulnerability is needed for the user to be, so to speak, pwned. On the other hand, this is the reason why a traditional computer is much more versatile, as the only limit is your imagination regarding how software can be combined to process the same data. Sandboxing turns “apps” into silos that can only do one thing. For a banking app, for example, this is good because security is the most important aspect.
In this comparison, the threat model is, of course, network-based attacks and malware (viruses, trojans, etc.). Phones naturally have their own weaknesses, such as the fact that they are always with you, which enables, for example, robberies through extortion or even forcing a finger onto a fingerprint reader.
I’ve heard similar things (that mobile phones are safer) and I don’t doubt it as such. It does make me wonder a bit, though, since it has been implied in the media that mobile phones have been “hijacked” for remote access.
Well, in that case, the owner has undoubtedly approved the installation of the malware themselves. What I haven’t been able to clarify is whether such a thing can be installed just by clicking on something like an “accept cookies” button? Naturally, a crook wouldn’t put “this is malware” in the description, but rather some text about cookies or something similar.