Skip to content

Digital security and fraud prevention in banking

MitID, phishing and your role as first line of defence against fraud

The more banking moves to screens and phones, the more interesting it becomes for fraudsters to go after customers' login and money. As a finance worker you are often the first to notice when something is wrong – when a customer calls confused or when a transaction looks suspicious.

§MitID replaced NemID

NemID was completely shut down on 31 October 2023 and MitID is today the standard for digital log-in to online banking mobile banking and public self-service solutions. The transition was meant to make login more secure but it has also given fraudsters new methods to exploit because many customers are still unsure how MitID approvals work.

§The classic fraud methods

MethodDescription
PhishingFalske mails, der ligner en bank eller myndighed, og som beder kunden klikke på et link eller åbne en vedhæftet fil
SmishingFalske sms'er, der ofte ser ud til at komme fra banken, med et link til en falsk log-ind-side
VishingCalls where the fraudster pretends to be the bank and tries to get the customer to disclose payment card, CPR number or MitID codes

§Your role when a customer has been called by "the bank"

A bank never calls and asks the customer to disclose MitID codes, card numbers or security codes. If you know the customer well enough to recognise a sudden change in behaviour or unusual transfers, it is your job to ask — not just process it. Many fraud cases are stopped because an alert employee asks one extra question.

  • 01Tell the customer that the bank never asks for MitID codes over the phone
  • 02Encourage the customer to call the bank's official number themselves if in doubt, rather than calling back to a number they have been given
  • 03Remind the customer that MitID is only safe when the customer has taken the initiative — for example by opening online banking themselves
  • 04React and escalate immediately according to your workplace's procedure if you suspect a customer is being swindled

§Internal security rules you yourself must follow

Access to customer data is a privilege. Always log off when you leave your desk, never share your own login or password, and follow your workplace's rules for which information you are allowed to look up and when. You are just as much a part of security as the technical systems.