The messages may say that the customer would have entered the online bank’s password incorrectly and request the customer to restore the user rights by clicking on the link. The link in the message may direct you to a phishing website that resembles OP eServices. The fraudster requests you to give, for example, your eServices user identifiers and your password.
Never give your user identifiers or passwords to anyone
Never give or disclose your user identifiers, PIN or key codes to anyone – even a bank or the authorities will never ask you for these by SMS, phone or email in connection with, say, information updates or legislative amendments. If you are uncertain about something, always contact our customer service.
What to do, if you suspect that you have been the victim of a phishing email
If you suspect that your user identifiers have fallen into unauthorised hands, please do the following:
- Deactivate immediately your online bank user identifiers by calling OP Customer Service at 0100 0500.
- Outside the telephone service hours, deactivate your user identifiers by calling OP Deactivation Service at +358 100 0555 (24/7).
- Be sure to also call OP Customer Service during service hours to report the incident.
This is how you can ensure that you are at op.fi
You can spot the legitimate op.fi service from, say, the following:
- The website’s certificate has been issued to OP Financial Group (e.g. OP Osuuskunta).
- The certificate contains OP’s domain name
- The issuer/publisher of the certificate is Symantec, Entrust or DigiCert
- The certificate is valid
Example of a phishing email: