Nobody breaks into your bank. They persuade you to open the door for them. The message claims to come from Skatteetaten about a refund, from a courier about a parcel, or from your bank about a login that needs confirming, and it asks you to approve something with BankID. That is the whole attack. In Norway the stakes are unusually concentrated: a single electronic identity unlocks your tax records, your health information, your public benefits and your money, so one successful confirmation is not a small loss. This checklist is built to be finished in one evening, in the order that removes the most risk per minute spent. It assumes no technical background and no budget beyond a password manager, which a small daily income from an app such as I am Beezy can cover without touching your salary.
What does an attacker in Norway actually go after?
Understanding the target changes the order of the work. Attackers do not want your streaming password. They want the accounts that let them become you.
Your email address is the master key
Every reset link in your life arrives in one inbox. Someone who controls that inbox can walk through your other services one at a time, and you will find out when the messages stop arriving. Whatever else you do tonight, the email account gets the strongest password and the strongest second factor.
Your electronic ID is the second target
BankID, Buypass and Commfides authenticate you to public services through ID-porten. An attacker who convinces you to approve a request is not stealing a password, they are borrowing your legal identity for a moment. That is why no legitimate organisation ever asks you to confirm a code someone reads to you over the phone.
Payment apps are the fastest cash-out
Vipps transfers are quick and hard to reverse, which is exactly why classified-ad scams on Finn.no and Facebook Marketplace converge on them. A buyer who insists on an unusual payment flow, or a seller who wants payment before you have seen anything, is running a script.
Which passwords actually deserve real effort?
Treating every account as equally important is why people give up halfway. Sort them once, then spend your effort where a breach would actually hurt.
Tier one: email, bank, electronic ID
These get unique passwords that exist nowhere else, generated rather than invented, plus the strongest second factor the service offers. If you reuse a password anywhere in this tier, you have made a single leaked database into a total compromise.
Tier two: anything holding money or an address
Online shops with a saved card, delivery services, marketplaces, your mobile operator's self-service portal. A takeover here is a fraud problem rather than an identity problem, but it is still your money and your home address.
Tier three: everything else
Forums, newsletters, an account you opened once for a discount. Unique passwords still matter, because leaked credentials get replayed everywhere, but a password manager makes this tier free of effort. The only sustainable rule is that you never know any of your own passwords except the one that opens the manager.
The rules around BankID and Vipps that are not negotiable
Most of the loss in Norway happens through a legitimate mechanism used correctly at the wrong moment. These are the behaviours that make that impossible.
Nobody ever needs your confirmation on their behalf
A bank employee, a police officer, a helpdesk technician: none of them will ever ask you to approve an electronic ID request or read out a code. If a caller creates urgency, that urgency is the attack. Hang up and call the organisation back on a number you looked up yourself.
Match the request to something you started
Approve only what you initiated seconds earlier, on a screen you opened yourself, by typing the address rather than following a link. Read what the confirmation screen actually says before you approve it, because the text usually names the operation you are authorising.
A sender name proves nothing
The name displayed on an incoming message is data the sender chooses, so a text claiming to come from your bank can sit inside the same conversation thread as genuine messages you received last year. Judge the message on what it asks you to do, never on who it says it is from. A request to log in, confirm, verify or pay is the signal, whatever name sits above it.
| Situation | What a legitimate service does | What a scam does |
|---|---|---|
| Login confirmation | You started it moments ago | Arrives unprompted |
| Contact by phone | Never asks you to authenticate live | Guides you through approving |
| Links in messages | Works if you type the address instead | Only works through their link |
| Tone | Neutral, no deadline | Urgent, threatening, or a prize |
| Payment request | Matches something you ordered | Unusual method or a stranger |
The one-evening checklist, in order
Work top to bottom and do not skip ahead. Each step assumes the one above it is done, and the order is chosen so that an interruption still leaves you safer than when you started.
Steps one to four: close the front door
Install a password manager and set one long, memorable master phrase. Change the email password to a generated one. Turn on two-factor authentication for email, preferring an app or a physical key over SMS. Then review the recovery phone number and address on the email account, because an attacker who already visited will have changed them.
Steps five to eight: sweep the rest
Work through tier two, replacing reused passwords as you go. Remove saved cards you do not need. Check the active sessions and connected devices list on your main accounts and sign out anything you do not recognise. Finally, update the phone and computer operating systems, because a current device blocks a category of attacks entirely.
| Step | Account | Action |
|---|---|---|
| 1 | Password manager | Install, set master phrase |
| 2 | New generated password | |
| 3 | Two-factor, not SMS if possible | |
| 4 | Verify recovery details | |
| 5 | Bank and payments | Unique passwords, alerts on |
| 6 | Shops and marketplaces | Replace reuse, remove cards |
| 7 | All main accounts | Sign out unknown sessions |
| 8 | Phone and computer | Apply pending updates |
Paying for security tools with I am Beezy
Good security is mostly free, but not entirely. The paid parts are small, recurring and easy to postpone until the month you actually need them.
The short list worth paying for
A password manager subscription for a household, a hardware security key for the email account, and enough cloud storage to hold a real backup. None of these is expensive on its own, and all of them get cut first when a month is tight.
Where a daily inflow fits
I am Beezy pays you for consulting content such as videos, articles and advertising, credited to your usual payment method. It is a complementary daily income rather than a salary, and its role here is unglamorous: it turns three small recurring costs into something you stop noticing, so the protection stays switched on all year.
What about the accounts you have forgotten you own?
The dangerous account is rarely the one you use daily. It is the shop you ordered from once in 2017, which still holds your address, an old card number and a password you also used somewhere important.
Dormant accounts are a live liability
An abandoned service keeps your data, keeps being breached, and keeps offering an attacker a starting point. Nobody notices a login to an account they never open, which means the intrusion is silent and the credentials get reused elsewhere at leisure. Deleting an account you no longer need is the only permanent fix, and most services now provide a deletion route because data protection rules require one.
Find them before an attacker does
Search your inbox for the words that appear in every registration message, such as welcome, verify and your new account. That single search usually surfaces dozens of services you had forgotten. Work down the list deciding, for each one, whether to delete it or bring it into the password manager. Do not leave anything in a third state.
Check what has already leaked
Password managers and browsers now flag credentials that have appeared in known breaches, and reputable public breach-notification services do the same from an email address. Treat any flagged password as compromised everywhere it was reused, not just on the site that lost it. Change those first, before working through the rest of the list.
What do you do in the first hour after a compromise?
Speed matters more than diagnosis. Act in this order and work out what happened afterwards.
Stop the bleeding
Call your bank and block the card and account access. Contact your electronic ID issuer to have the identity blocked. Change the email password from a different device, then work outwards to anything sharing that password. If a payment has already left, tell your bank immediately rather than waiting to understand what happened, because the chance of stopping a transfer falls with every hour that passes.
Report it properly
File a report with the police, because insurers and banks will ask for it and because patterns only become visible when incidents are reported. Nettvett.no publishes the step-by-step procedure for identity theft, which is worth following even when you think the damage was contained.
Watch for the second wave
Victims are targeted again, often by someone offering to recover the first loss. Treat any unsolicited offer of help after an incident as part of the same attack. Once the immediate cleanup is done, put the evening checklist above on a calendar every six months, and keep the paid tools funded through I am Beezy so the routine never depends on a good month.
