Beware of phishing – fraudsters request OP customers’ user IDs and key code lists!

Fraudsters are trying to get OP customers’ contact information and user identifiers for OP eServices by sending phishing email messages and possibly also through SMS phishing (smishing). The sender of the message may look something like OP’s customer service. The sender of a phishing message may, for example, inform you that you have received an ‘online telegram’ and asks you to read it by clicking a link in the email, or the sender may ask you to register an imaginary key code device. The link in the message directs to a phishing website that resembles OP eServices. The fraudster requests you to give your contact information, online user identifiers and a photo of your key code list.
If you have given your personal data, such as a phone number, on the phishing website, the fraudster may impersonate the bank's representative and call from a number that has been falsified to look like the phone number of OP's customer service. The phone call may also come from a number that resembles the phone number of OP's customer service. Never give any information to fraudsters!
You can spot the legitimate website of the bank from the following, for example:
  • The website's certificate has been issued to OP Financial Group (e.g. OP Osuuskunta).
  • The certificate contains OP’s domain name.
  • The issuer/publisher of the certificate is Symantec, Entrust or DigiCert.
  • The certificate is valid.
Please note that OP never asks you to log into its online services via a link in an email or text message or to provide your personal data or user identifiers. 
Never give or disclose your user identifiers, PIN or key codes to anyone – even a bank or the authorities will never ask you for these by SMS, phone or email in connection with, for example, information updates or legislative changes. If you wish to make changes to your user identifiers or other details, always do this by logging in to the bank’s own service or by visiting a bank branch. You can check the services approved by OP under ”Services you can access with your user identifiers”. If you are uncertain about something, always contact our customer service for more information.
If you already entered your OP eServices user identifiers on a phishing page, deactivate them immediately! To do so, call OP’s telephone service at 0100 0500 (opening hours Mon–Fri 8–22, Sat 10–16, local network charge/mobile charge). Outside the telephone service hours, deactivate your user identifiers by calling the Deactivation Service, tel. +358 20 333 (24/7). Also report the incident to OP telephone service when it is open again.
Send us an email and attach to it the phishing email you received. How to save a phishing email and send it to us:
Save and send the email as follows (this may vary depending on your email provider):
  1. In the File menu, select Save As
  2. In the Save As dialog box, select the drive and folder in which you want to save the email.
  3. In the File name field, enter a name for the file.
  4. Accept the default file format shown in the Save as type field or select some other file format for saving the file.
  5. Write an email message, attach the file you just saved and send it to
Include your name, contact information and your bank’s name (e.g. OP Mallila) in your email. We will not reply directly to messages sent to this email but you will receive an automatic reply. Also report the event to OP telephone service at 0100 0500, or to your bank.
Example 1 of a phishing email:


Example 2 of a phishing email:

Example of a phishing website: