BIN attacks on the rise in Finland – Nordea recommends holding two payment cards
Nordea has noticed an increase in BIN attacks compared with the previous year. The bank recommends customers hold two cards and monitor their transactions.

BIN attacks growing – card details guessed by software
According to Is.fi, a Finnish Reddit user recently received a text message warning of an unclear $1.38 charge to Amazon Prime. The user initially thought the message was a fraud attempt, but after calling Nordea, it turned out the warning was genuine – their card number had been guessed by software. Nordea closed the card and sent a new one.
The attack method is known as a BIN attack. BIN stands for bank identification number and refers to part of the card's number sequence that reveals the issuing bank. Using this information, criminals narrow down the range of possible numbers and use software to guess the card number, expiry date and three-digit security code. Artificial intelligence has further accelerated the automation of these attacks.
"We have observed significantly more BIN attacks recently compared with the same period last year," says Annukka Multanen, fraud prevention specialist at Nordea.
According to Multanen, the intensity of the phenomenon varies rapidly and is not directed solely at Nordea.
"The cases are not directed at a specific operator, but often other financial institutions have also observed growth in case numbers," Multanen states.
Customers cannot prevent the attack themselves
Card details can be lost without any action or theft on the customer's part, such as in a data breach at an online shop. In a BIN attack, criminals test large numbers of number combinations until one matches the details of a real payment card. A card found to be functional may be sold online, and stolen information is exploited particularly in American and Australian online services where purchases can be made without bank authentication.
Nordea monitors card transactions and restricts card use where necessary, and sends a new card to the customer. In some cases, the bank sends a text message in which the customer can confirm or dispute the transaction by replying with the letter A or B.
A small unknown charge on a credit card bill may indicate that the card has been tested to verify its functionality. In such cases, Multanen advises contacting the bank immediately to have the card closed. If the card has been used without authorisation, the customer can file a card dispute.
Nordea: hold two cards
"We always recommend that all our customers have two cards. This way the customer has a spare card if, for example, they themselves close a card," Multanen advises.
Additionally, she recommends keeping the daily security limits, geographical restrictions and internet use settings of cards up to date. All online purchases should be concentrated on one card and card transactions should be monitored regularly.
BIN attacks are not a new phenomenon. In 2022, OP was forced to close combo cards for almost 2,000 customers after their numbers were successfully determined through software guessing. At that time, Petri Aalto, lead risk specialist at the Financial Supervisory Authority, considered the case rare and unlikely to recur – developments have since proved that assessment wrong.
Source: Google News FI — Crime (fi)