MitID, phishing and your role as first line of defence against fraud
The more banking moves to screens and phones, the more interesting it becomes for fraudsters to go after customers' login and money. As a finance worker you are often the first to notice when something is wrong – when a customer calls confused or when a transaction looks suspicious.
NemID was completely shut down on 31 October 2023 and MitID is today the standard for digital log-in to online banking mobile banking and public self-service solutions. The transition was meant to make login more secure but it has also given fraudsters new methods to exploit because many customers are still unsure how MitID approvals work.
| Method | Description |
|---|---|
| Phishing | Phishing emails that look like a bank or authority, asking the customer to click a link or open an attached file |
| Smishing | Fake SMS messages that appear to come from the bank, with a link to a fake login page |
| Vishing | Calls where the fraudster pretends to be the bank and tries to get the customer to disclose payment card, CPR number or MitID codes |
A bank never calls and asks the customer to disclose MitID codes, card numbers or security codes. If you know the customer well enough to recognise a sudden change in behaviour or unusual transfers, it is your job to ask — not just process it. Many fraud cases are stopped because an alert employee asks one extra question.
Access to customer data is a privilege. Always log off when you leave your desk, never share your own login or password, and follow your workplace's rules for which information you are allowed to look up and when. You are just as much a part of security as the technical systems.