Wait, what? I use Klarna quite regularily and I assumed they were redirecting to my bank's website (in an iframe) where I would enter my credentials. I mean, the web form is even branded with my bank's logo and color scheme.
If it's really the case that I was just giving my credentials to Klarna who then logged into my bank account on my behalf, I have been phished, there's no sugar coating this.