Phishing and internet fraud in the Netherlands: your rights

Protect Your Rights Against Internet Fraud

Phishing and internet fraud are criminal offences under Dutch law. A fraudster who tricks you into handing over login details or transferring money commits fraud (oplichting) under article 326 of the Dutch Criminal Code, and often unauthorised access to a computer system (computervredebreuk) under article 138ab as well. If money has left your account without your consent, your bank must in principle refund it under article 7:528 of the Dutch Civil Code. The main exception: the bank does not have to pay if it can show you acted fraudulently or with gross negligence. Speed matters, so report the incident to your bank and file a police report as soon as you notice it.

What counts as phishing under Dutch law?

Phishing is deception in which a criminal poses as an organisation you trust to obtain your credentials or money. Dutch law does not use the word phishing, but it punishes the conduct behind it.

The fraudster may pretend to be a bank, a payment provider, a delivery company or the Dutch tax authority (Belastingdienst). The aim is to obtain login credentials, payment card details, a verification code or a signature in a banking app. The medium varies: an email, an SMS message (smishing), a phone call from someone claiming to be from the bank’s fraud desk (vishing), a message on WhatsApp or LinkedIn, or a cloned website behind a sponsored search result.

Several provisions of the Dutch Criminal Code (Wetboek van Strafrecht) can apply at once:

  • Posing as a bank to move someone to hand over money or data is fraud under article 326.
  • Logging into an account with credentials obtained that way is unauthorised access under article 138ab.
  • Using another person’s identifying data to cause harm or gain an advantage is punishable under article 231b.
  • Forging documents or a digital record falls under article 225.
  • Misusing payment cards or the data behind them falls under article 232.
  • Where an attack ends in encrypted files and a ransom demand, article 350a (altering or destroying data) and article 317 (extortion) come into play.

What counts as internet fraud?

Internet fraud is the wider category: any deception carried out through an online channel. Legally, most forms run through the same provision, article 326 of the Criminal Code.

Internet fraud covers webshops that take payment and never ship, fake rental listings and investment scams built around cryptocurrency. It also covers invoice fraud, in which a supplier’s bank details are silently changed, and CEO fraud, in which a finance employee receives an urgent payment instruction that appears to come from a director. The core is always the same: a deceptive act that moves someone to part with money, goods or data.

The practical difference between phishing and the wider category is where the loss arises. In a phishing case the money usually leaves a payment account without your consent. That brings the payment services rules in Book 7 of the Civil Code into play. In a webshop or investment scam you transfer the money yourself. Recovery then becomes a civil matter against the fraudster and, sometimes, against the platform or the bank that received the funds.

How do you recognise a phishing message?

Look at what the message asks you to do, not at its spelling. Modern phishing messages are well written and often personalised, so the old advice about spelling mistakes is no longer enough.

Three signals remain reliable:

  • The message creates time pressure. It tells you an account has been blocked or a payment will be reversed unless you act now.
  • It steers you away from the channels you normally use. It asks you to click a link or call a number, rather than open your own banking app.
  • It asks for something a bank never asks for: a verification code, a signature in your banking app for a transaction you did not start, or permission to install remote access software on your device.

For organisations, the same logic applies to payment instructions. A supplier that changes its bank details by email, a director who asks for an urgent transfer outside the usual approval chain, or an invoice that arrives slightly earlier than expected all call for a check. Call back on a number you already had on file, not one supplied in the message.

Can you get your money back from the bank?

Usually, yes. If you did not consent to a payment, the bank must in principle refund it immediately, unless you acted fraudulently or with gross negligence.

A payment transaction to which the payer did not consent is an unauthorised transaction within the meaning of article 7:522 paragraph 2 of the Dutch Civil Code. Article 7:528 paragraph 1 then obliges the payment service provider to refund the amount immediately and restore the account to the state it would have been in. The starting point, in other words, is that the bank carries the loss.

The exception sits in article 7:529 paragraph 1. The bank does not have to refund if the account holder acted fraudulently, or intentionally or with gross negligence failed to meet the duties in article 7:524. Those duties require you to use the payment instrument in line with the applicable conditions and security measures. Gross negligence is a high bar. It is judged on all the circumstances, not on the fact of the loss alone. Article 7:529 paragraph 3 adds a further protection: where the bank did not apply strong customer authentication, you bear no loss at all.

What can you do if the bank refuses to pay?

As a consumer, you can take the dispute to the Financial Services Complaints Institute (Klachteninstituut Financiële Dienstverlening, Kifid) or to the civil court. Kifid will only deal with your complaint after you have completed the bank’s internal complaints procedure.

Business account holders are in a different position. They fall outside most of the consumer protections and depend largely on their contract with the bank and on general liability rules. That makes a company’s internal payment controls all the more important.

Can you claim damages from the fraudster or a negligent organisation?

Yes. Where the perpetrator is identified, you can recover the loss as an unlawful act (onrechtmatige daad) under article 6:162 of the Civil Code. A claim against an organisation whose poor security made the fraud possible runs through the same article.

Against the perpetrator, this most often happens inside the criminal case. Under article 51f of the Dutch Code of Criminal Procedure you can join the criminal proceedings as an injured party (benadeelde partij) and ask the criminal court to award compensation. That is usually cheaper and faster than a separate civil claim. The court will only deal with a claim that does not place a disproportionate burden on the criminal proceedings. Your loss must therefore be documented and straightforward to calculate.

A second route is a claim against an organisation whose security fell short. Think of the employer whose mailbox was compromised, the platform that allowed a seller to operate without any verification, or the processor that leaked a customer database. The standard applied is what a careful organisation should have done, given the state of the art and the sensitivity of the data. The rights of victims of cyberattacks sets out how notification duties, compensation and insurance interact in those cases. Proof is usually the hard part; our article on how to prove digital deception deals with the evidence that carries weight.

What does the GDPR require of organisations hit by phishing?

A successful phishing attack on a company almost always produces a personal data breach. The organisation must then report it to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) without undue delay and, where feasible, within 72 hours.

Article 32 of the GDPR requires controllers and processors to take appropriate technical and organisational security measures. Article 33 contains the duty to report a breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the people concerned. Where the risk to those people is high, article 34 adds a duty to inform them directly.

The supervisory authority looks less at the fact that an attack succeeded than at what preceded it. Was multi-factor authentication in place? Were access rights limited to what staff actually needed? Did logging allow the incident to be reconstructed? Had staff been trained? An organisation that can show a considered security approach and a documented response is in a far stronger position than one that only starts writing things down after the event. Who is responsible after a data breach works through how that liability is allocated.

Which reporting duties apply under the Cyberbeveiligingswet?

Since 15 August 2026 the Dutch Cybersecurity Act (Cyberbeveiligingswet), which implements the NIS2 Directive, applies alongside the GDPR. Organisations within its scope must report significant incidents in stages: an early warning within 24 hours, a notification within 72 hours and a final report within one month.

Organisations that fall within the Act must also register with the National Cyber Security Centre (NCSC). They must take measures under a duty of care covering risk management, supply chain security and incident handling. The board must approve those measures, oversee their implementation and follow training, so cybersecurity is a management responsibility and not only a matter for IT.

The two regimes overlap but are not the same. A phishing incident that compromises a mailbox may trigger a GDPR notification to the Autoriteit Persoonsgegevens and a separate incident report under the Cyberbeveiligingswet, on different deadlines and to different authorities. Work out in advance which regime applies to your organisation, and who makes the call at three in the morning. Our guide on cybersecurity incident reporting duties sets the deadlines side by side.

What if the fraudster or the money is abroad?

File a police report (aangifte) in the Netherlands anyway. An offence directed at a victim in the Netherlands is generally treated as committed here, so the Dutch police and prosecutor are the right starting point even when the perpetrator is abroad.

Phishing operations are rarely confined to one country. The sending infrastructure sits in one jurisdiction, the victim in another, the money in a third and the hosting of the cloned site in a fourth. Dutch criminal jurisdiction extends to offences committed on Dutch territory.

Evidence from another state is obtained through established channels. Within the European Union, the European Investigation Order allows a Dutch prosecutor or investigating judge to request data, account information or the freezing of funds from another member state. Beyond the EU, the Council of Europe Convention on Cybercrime, concluded in Budapest in 2001, provides for expedited preservation of stored computer data and mutual assistance between the states that have joined it. Europol and Interpol coordinate operations but do not prosecute themselves; the case remains with a national prosecuting authority.

For you as a victim, this has a practical consequence. Recovery of the funds usually depends on how quickly the receiving bank can be alerted, because money moved through a mule account is dispersed within hours. Reporting to your own bank immediately, so it can attempt a recall, is more likely to produce a result than any later legal step.

How do you prevent phishing and internet fraud in your organisation?

Remove single points of failure; buying more software is rarely the answer. A few basic measures stop most opportunistic attacks.

  • Use multi-factor authentication on every account that can reach company data.
  • Keep unique passwords in a password manager.
  • Patch devices and software promptly.
  • Verify every change to supplier bank details by telephone, on a number you already had.
  • Make sure no single person can both create and release a payment.

Training closes the remaining gap, provided it is repeated and realistic. Staff who have seen a convincing simulated phishing message recognise the real one; staff who have only read a policy generally do not. Finally, decide in advance what happens in the first hour after an incident: who isolates the account, who preserves the logs, who contacts the bank, and who assesses whether a notification duty has been triggered. That list is worth more on the day than any amount of analysis after the event.

What should you do if you have been targeted?

Contact your bank first, then secure your accounts, preserve the evidence and report to the police. Act in this order:

  1. Contact your bank through its official fraud number and ask for the transaction to be blocked or recalled.
  2. Change the credentials of the compromised account and of any other account using the same password.
  3. Preserve everything: the original message with its headers, screenshots, transaction references and the times at which you noticed each step.
  4. File a police report. Most insurers require one, and it is the basis for any later claim as an injured party.
  5. If personal data of others has been exposed, assess the notification duties under the GDPR and, where applicable, the Cyberbeveiligingswet before the deadlines run out.

We advise victims of phishing and internet fraud on recovering losses from banks, platforms and perpetrators. We also advise companies on security obligations, breach notifications and liability after an incident. Further reading is collected in our Dutch IT law guides.

In summary

  • Phishing and internet fraud are punishable in the Netherlands, mainly as fraud (article 326 Criminal Code) and unauthorised access (article 138ab).
  • For a payment you did not authorise, the bank must in principle refund you immediately (article 7:528 Civil Code), unless you acted fraudulently or with gross negligence (article 7:529).
  • If the bank refuses, consumers can go to Kifid after the bank’s internal complaints procedure, or to the civil court.
  • Organisations hit by phishing must assess a GDPR notification within 72 hours and, if within scope, report under the Cyberbeveiligingswet (24 hours, 72 hours, one month).
  • Call your bank immediately and file a police report: speed is often decisive for recovering the money.

Frequently asked questions

Does my bank have to refund me if I clicked a phishing link?

Not automatically, but often. The starting point is a refund for any payment you did not consent to. The bank must show that you acted with gross negligence, and that is judged on all the circumstances of the case.

Is a business account protected in the same way?

Largely not. Most consumer protections do not apply to business accounts, so the contract with the bank and general liability rules decide who bears the loss.

Can I claim compensation in the criminal case?

Yes. As an injured party (benadeelde partij) you can join the criminal proceedings and ask the court to award compensation, provided your claim is documented and straightforward to assess.

Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.

How Law & More can help you with this is explained on our criminal lawyer page.

Jade Vaneerdewegh
Jade Vaneerdewegh is an attorney-at-law at Law & More in Eindhoven and Amsterdam. She works on criminal and administrative law matters, building her advice on thorough analysis of the facts and the legislation.

Need Legal Assistance?

Have you received a letter, a writ of summons or a judgment? Send us the documents. We will check which deadlines apply and what your options are.

This article provides general information and is not a substitute for advice on your specific situation.

Related articles

Violence cases are among the most common criminal matters private individuals face in the Netherlands.

You cannot simply take back a statement you gave to the police in the Netherlands.

Learn what is criminal law, its importance, key concepts, and how it functions in the

A driving licence seized by the Dutch police is not automatically lost. Under article 164

A preliminary hearing in criminal cases, known in Dutch practice as a regiezitting, is a

Police interrogation rights in the Netherlands attach the moment the police treat you as a

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.