Fraud Prevention

Security is a priority at Narvi. Learn how we protect your business, and what you can do to recognise and stop fraud attempts.

section
The problem

Payment fraud across the EEA is rising

Business payment fraud is common and costly, with 79% of organisations hit by attempted or actual payment fraud in 2024 (AFP, 2025) and losses across the EEA reaching €4.2 billion (EBA and ECB, 2024). Narvi is committed to stopping any fraud and impersonation in our name, and to helping you recognise it fast. This page shows how we protect your business, how to tell the real Narvi from a fake, and what to do when something looks off.
section
Security measures

How Narvi protects you

Narvi implemented several technological, operational, and compliance layers to keep your business and your money safe. This is how we work each day to protect you against malicious actors:

Hardware key authentication

You can protect access to your account with a physical security key. We support YubiKey, Trezor and Ledger, plus FIDO2 and passkeys.

Biometric verification

We support a biometric check on top of your login for account access.

2FA on every critical action

Sensitive operations on the platform need a second factor, so a stolen password alone isn't enough.

Regulated as an EMI in Finland

Client funds are segregated and safeguarded at regulated EU banks.

Real people, official channels only

Support is answered by a real person, never a bot, and Narvi will only ever contact you through official channels.

Ongoing monitoring, audits and stress testing

We run regular audits and stress tests to hold our security and regulatory standards.
section
How to recognize that's us

Narvi official channels

This is the list of channels Narvi uses to contact clients. If a website, email, or message you encounter isn't on it, this is not us, but a fraudster trying to abuse your trust.
Website: https://narvi.com and its subdomains (like api.narvi.com)
Client portal: https://my.narvi.com
Email: We use only @narvi.com domain in email communication. Our generic contact email is contact@narvi.com. The customer service email is support@narvi.com. Our email for filing complaints and fraud suspicions is complaints@narvi.com.
Social media handles: Narvi maintains official social media presence on LinkedIn, X, and Telegram.
section

What to do in suspicious cases

How it works: Someone calls, claiming to be Narvi support or a compliance officer, often with a spoofed caller ID, and pressures you to hand over codes, passwords, or hardware key approval.Red flags:
  • Urgency, panic, or a demand for secrecy.
  • A request for your password, login codes, PIN, or approval of a prompt.
  • Caller ID alone is offered as "proof" that it's really us. IDs can be faked.
What to do:
  • Narvi will never ask for your password, login codes, or PIN by phone, and will never ask you to approve a hardware key or biometric prompt over a call. If a call asks for any of that, hang up.
  • Don't read out a code or approve a prompt because a caller asked.
  • Contact us yourself at complaints@narvi.com.

How it works: A text with a link, or an authentication request you didn't start, pushes you to log in or approve something.Red flags:
  • A link in an SMS claiming to lead on Narvi website.
  • A 2FA or approval prompt you didn't trigger.
  • Pressure to act on a "suspicious transaction" by tapping a link.
What to do:
  • Don't tap links in texts. Check your account by typing narvi.com yourself.
  • Never approve a hardware-key or app prompt you didn't start.
  • Forward the message to complaints@narvi.com

How it works: An email that looks like Narvi tells you to verify your account, re-confirm KYC, or stop a payment, with a link to a fake login built to capture your details.Red flags:
  • The sender isn't an @narvi.com address, even if the display name says "Narvi."
  • Urgency or a threat: e.g., a threat that your account will be suspended, or a payment will go through unless you act now.
  • Links that don't go to narvi.com, or attachments you didn't expect.
What to do:
  • Don't click. Hover to check where a link really goes.
  • Don't open attachments.
  • Open a new tab, type narvi.com, and check your account directly.
  • Forward the email to complaints@narvi.com, then delete it.

How it works: Fraudsters clone the Narvi site or build a fake login on a lookalike domain (e.g. narvi-secure.com, narv1.com, or a shortened link) to harvest your credentials)Red flags:
  • The address isn't exactly narvi.com.
  • Misspellings, extra words, or a different ending (.net, .io, -secure, -login, etc.).
  • You arrived via a link rather than typing the address yourself.
  • The page asks for your hardware key or codes in an unusual flow.
What to do:
  • Type narvi.com yourself or use a saved bookmark. Don't log in from a link.
  • Check the full address before you enter anything.
  • Report the fake to complaints@narvi.com

How it works: Fraudsters put the Narvi name and logo on social media, ads or messaging apps to push fake investments, or to offer to "recover" money you've already lost, for a fee.Red flags:
  • Investment "opportunities," guaranteed returns, or crypto offers using Narvi's brand.
  • Anyone offering to recover lost funds for an upfront payment.
  • Contact through a direct message in social media rather than an official channel.
What to do:
  • Treat any investment or fund-recovery offer in Narvi's name as fake. Narvi doesn't cold-offer investments or fund recovery.
  • Check the account against our official social list before trusting it.
  • Report the profile or ad to complaints@narvi.com and to the platform you have seen it on.

How it works: Fraudsters get your login through malware, a reused password, a phishing page, or a SIM swap, then sign in as you.Red flags:
  • Login prompts, password resets or 2FA requests you didn't start.
  • Losing mobile signal unexpectedly (a possible SIM swap).
  • Devices or users you don't recognise on your account.
What to do:
  • Turn on the strongest authentication available: a hardware key plus biometrics.
  • Use a unique password for Narvi and store it in a password manager.
  • Review who has access to the account, and remove anyone who no longer needs it.
  • If something looks wrong, contact us through official channels above
section
Incident response

What to do if you have been targeted

If you suspect you are a victim of a fraudulent activity related to your Narvi account, follow the steps below with no delay Speed matters.
  1. Stop. Don't send any more payments or share any more information.
  2. Contact Narvi at complaints@narvi.com. The sooner we know, the better the chance to stop, or at least limit the fraud.
  3. Secure your access. Change your password, review authorised users, and check recent activity on your account.
  4. Report it to the police or your national fraud reporting body. Every report helps, whatever the amount, and can support fund recovery.
Narvi will act on its side wherever possible. Fund recovery is never guaranteed and depends on how fast the fraud is caught and the circumstances.Suspicious activity? Report it here
section

FAQ

Narvi only writes from an @narvi.com address and only operates from narvi.com domain (and subdomains like my.narvi.com). If the sender's address or the web address is different in any way, treat it as fake. When in doubt, don't click the link. Type narvi.com yourself and check your account directly.

No. Narvi will never ask for your password, login codes or PIN, by email, SMS or phone, and will never ask you to approve a hardware-key or biometric prompt you didn't start. Anyone who does is a fraudster.

Act fast. Change your Narvi password, turn on the strongest authentication available, and review recent activity and authorised users. Contact Narvi at complaints@narvi.com and report it to your local police or national fraud body.

Send it to complaints@narvi.com with a screenshot or the original email if you can. For a fake social profile or ad, also report it to the platform it appears on.

Narvi is an Electronic Money Institution regulated by the Finnish Financial Supervisory Authority (FIN-FSA). Client funds are safeguarded at regulated banks in the EU and kept separate from Narvi's own funds under segregation rules, and we run regular audits and stress tests.
section