Nobody picks your pocket in Norway. There is nothing in it: only 2 % of people surveyed in spring 2025 had paid cash at their last purchase in a shop. What there is instead is a single digital key that opens your bank, your tax file and your benefits, and a payment app that most of the adult population has installed. Norwegian online fraud is built around that architecture, which is why it almost never tries to steal something from you — it tries to get you to approve something. The seven mistakes below are the ones that make that work, and the article ends with what to do in the first hour when it already has. Along the way, it also covers why an app such as I am Beezy is the boring answer to the "earn money fast" message that starts a large share of these cases.
Why Norwegian fraud targets your approval, not your password
The criminal script follows the country's payment habits, and Norway's are unusually concentrated.
A country that does not settle in cash
In 2024, 3 156 million payments were made with Norwegian cards, 49 % of them on the national BankAxept scheme, and 27 % of all card payments were made online. Thirty per cent of in-store payments went through a phone. There were 205 million instant payments, the largest share initiated from Vipps and made between private individuals. In a system this digital, the fastest route to someone's money is an instruction they issue themselves.
BankID is the single key
Without BankID you open neither a Norwegian bank in practice, nor skatteetaten.no, nav.no or altinn.no. That concentration is convenient and it is also the target: an approval obtained under a false pretext does more damage in Norway than a stolen password does in most countries.
What that means for how you are approached
The opening move is almost always a reason to act now — a parcel held, an account "under review", an investment closing tonight, a job that pays this week. The urgency is not decoration. It exists to stop you doing the one thing that breaks the whole script, which is checking through a channel the sender does not control.
Which scams are actually running in Norway?
The police publish the working list, and it is short enough to remember.
The families the police name
| Family | How it opens | The tell |
|---|---|---|
| Kjærlighetssvindel (romance fraud) | A relationship built over weeks, then an emergency | The first request for money always has a deadline |
| Pengemuldyr (money mule) | An offer to receive and forward funds for a fee | You are asked for your account, not your skills |
| ID-tyveri (identity theft) | Your details reused to open credit or accounts | Mail or messages about services you never asked for |
| Telefonsvindel (phone fraud) | A call from your "bank" or a public body | They call you and then ask you to authenticate |
| Phishing by SMS or email | A link about a parcel, a fee or a refund | The link takes you somewhere to log in |
| Invoice and director fraud | A payment instruction that looks internal | A changed account number on a familiar invoice |
The police summarise the defence in three words — "Stopp, tenk, sjekk", stop, think, check — and add one instruction with no exceptions attached: do not share BankID, passwords or sensitive personal data, whoever is asking.
The one aimed at young adults specifically
The money mule recruitment deserves separate attention because it does not look like fraud from the inside. Someone offers to pay you for letting a transfer pass through your account. The money is stolen, the account is yours, and the person who forwarded it is the one the case lands on. Lending your account or your BankID to someone else makes you a participant, not a victim.
Why the tells are behavioural, not technical
None of the signals above requires you to inspect a link or read a header. They are all about the shape of the request: who initiated contact, what they want you to do first, and how much time they are giving you.
Mistakes one to three: made in the first ten seconds
These three are responsible for most completed cases, and all three are decided before you have thought about anything.
Mistake 1: answering on the channel that contacted you
Calling back the number in the message, or clicking the link to "check your account", keeps you inside the attacker's environment. The police advice is to reach the organisation through its official channel instead — search for it, or use the number on your card. This single habit defeats phishing and phone fraud outright.
Mistake 2: approving with BankID to "verify" something
A BankID approval is a signature, not a check. Nobody legitimate needs you to sign in order to confirm that you exist, to cancel a transaction, or to stop a payment. If an approval is being requested to undo something, the request itself is the attack.
Mistake 3: reading a payment request as a payment received
On Vipps, a request to send money and a notification of money arriving look similar at a glance, and a buyer or seller in a hurry confuses them regularly. Read the direction of the arrow before you tap. Vipps publishes its own security guidance at vipps.no, and its help pages cover what to do when you suspect you have been defrauded.
Building a side income with I am Beezy, not with a stranger's offer
A large share of the cases above start with a message offering easy money. The defence is not suspicion in general; it is having a legitimate answer already in place. I am Beezy is one such answer, and it pays for attention rather than for access: you watch videos, read articles and see advertising inside the app, every view is credited, and the balance reaches your usual payment method. Nobody else's money touches your account at any stage, which is the whole difference with the offer sitting in your inbox.
What it actually pays
Between 5 and 15 euros a day is the reference across our audience — a real amount, not a life-changing one, and that modesty is itself a signal worth reading. No krone equivalent is published against it; for scale, the European Central Bank reference rate was 1 EUR = 10,9750 NOK on 7 August 2026, and the krone floats.
What a legitimate offer looks like
It pays you for something you did. It never asks you to receive and forward money, it never needs your BankID for anything except identifying yourself to a service you chose, and it does not have a deadline tonight.
Mistakes four to seven: made over days
The slower half of the list is where the larger losses sit, because time makes a bad decision feel considered.
Mistake 4: not checking whether the firm is licensed
Finanstilsynet supervises financial undertakings in Norway and publishes market warnings about companies offering investment services here without authorisation, alongside a register of the firms and individuals that do hold a licence. Checking a name against that register takes a minute and it is the only step that reliably separates an investment from investment fraud. The check has a second use that people miss: a firm that is genuinely licensed will tell you its own registered name and organisation number without hesitating, because it has nothing to lose by doing so. Hesitation at that question, or a name that differs from the one on the website, ends the conversation for you.
Mistake 5: paying outside the platform
Every marketplace conversation that moves to a private transfer loses whatever protection the platform offered. A seller who insists on it is telling you something about the transaction.
Mistake 6: letting someone else use your account or your identity
This covers the money mule case, but also the friendlier version — a relative, a partner, a flatmate who "just needs to receive one payment". The account is registered to you, and so is the consequence.
Mistake 7: waiting before you report
Recovery chances fall with every hour. Waiting because you feel foolish is the most expensive form of embarrassment there is, and the police pages exist precisely because the volume is high enough to be routine.
What do you do in the first hour?
Order matters more than speed of typing. Work down this list without stopping to reconstruct how it happened.
Contact your bank before anything else
The bank can attempt to stop or recall a transfer and can block the card or the account. That window is short. Norwegian banks publish fraud contact routes on their own sites; Nordea, for instance, maintains a page on the different forms of online fraud and what to do. Save that number in your phone now, while nothing is happening, because the moment you need it is the moment you will not want to be searching for it. Do the same for the card-blocking line. Two contacts, two minutes, and they are the difference between acting inside the recall window and acting after it has closed.
Report it to the police
The police describe how to report fraud and identity theft, and also run a tip line for information you want to pass on without filing a case. A report is what makes the loss official for your bank and your insurer.
Who to contact, for what
| Situation | Where to go |
|---|---|
| Money has left your account | Your bank first, then politiet.no to report |
| A firm sold you an "investment" | Finanstilsynet market warnings and licence register |
| A Vipps transfer you did not intend | Vipps help pages, then your bank |
| Your identity has been reused | politiet.no, then the services affected |
| General prevention advice | nettvett.no, run jointly by NorSIS, NSM and Nkom |
The habit that replaces all seven
You cannot memorise every variant, and new ones appear faster than any list is updated. What you can do is fix the reflex underneath them.
Stop, think, check
The police formula works because it targets the only thing every scam needs, which is your immediate response. Put a delay between the message and the action, and use the delay to reach the organisation through a channel you chose. Almost nothing survives that.
Where to keep an eye out
Nettvett.no, run jointly by NorSIS, the national security authority NSM and the communications regulator Nkom, publishes ongoing guidance on safer internet use; politiet.no carries the current fraud patterns; Finanstilsynet publishes its warnings as they are issued. Read one of them once a quarter and you will recognise the next wave before it reaches you. And if the message that started all this was an offer of quick money, replace it with something that pays for what you actually do: I am Beezy credits you for content you consult, on your usual payment method, and never asks for your account so that someone else's money can pass through it.
