Computer Crime and Cyber Crime in the Netherlands: Which Laws Apply?

Dutch office workers collaborating on cybersecurity with 'Computer Crime' text on monitor

Dutch office workers collaborating on cybersecurity with 'Computer Crime' text on monitor

Dutch criminal law distinguishes between offences in which a computer is the target and offences in which it is only the means. Hacking, a DDoS attack or ransomware fall under specific computer offences in the Criminal Code, while online fraud, identity fraud and phishing are usually prosecuted under the ordinary offences, sometimes combined with a computer offence.

That distinction determines which provision applies, which maximum penalty applies and what the prosecutor has to prove. Below you will find the main offences, the most common forms of cyber crime, the penalties, what an organisation must do in the first days after an incident, how to recover your loss and how to prevent an attack.

Where the system itself is the target, the Dutch Criminal Code (Wetboek van Strafrecht, Sr) contains specific offences. Gaining access to a computer system without authorisation is computer trespass (computervredebreuk) under Article 138ab, and that is an offence even if nothing is taken and no damage is done. Deliberately making a system inaccessible by sending it data, as in a denial of service attack, is punishable under Article 138b. Intercepting communications is an offence under Article 139c, and Article 139d covers placing recording equipment and distributing tools for these offences. Altering, deleting or rendering data unusable falls under Articles 350a and 350b, which are the provisions that catch ransomware.

Where the computer is only the means, the ordinary offences apply. Online fraud is fraud (oplichting) under Article 326, identity fraud falls under Article 231b, and phishing is generally charged as a combination of fraud, computer trespass and forgery. That matters in practice, because these offences have their own limitation periods and their own evidential requirements.

For an organisation that has been attacked, reporting to the police is only one of several obligations. A personal data breach must be notified to the Dutch Data Protection Authority within 72 hours where it is likely to result in a risk to individuals. Organisations covered by the Cybersecurity Act (Cyberbeveiligingswet), in force since 15 August 2026, have their own reporting deadlines, starting with an early warning within 24 hours.

Table of Contents

What is the difference between computer crime and cyber crime?

Infographic comparing computer crime vs. cyber crime differences

In computer crime, the computer system or the data in it is the target of the offence. In cyber crime in the broader sense, the computer or the internet is the tool used to commit an offence that also exists offline, such as fraud or extortion.

The two terms are often used interchangeably, and Dutch law does not define them. The distinction is still useful, because it helps you see which provisions apply and what has to be proven.

When is the computer the target?

The computer is the target when the offence is directed at the system itself: getting in without permission, disrupting it or damaging the data. Specific provisions in the Criminal Code apply to this, such as computer trespass, disruption of a system and damaging data.

Typical examples are hacking into a company network, a DDoS attack that makes a website unreachable, installing malware and encrypting files with ransomware. For these offences it does not matter whether the perpetrator also gained money: the intrusion or disruption itself is punishable.

When is the computer only the means?

The computer is only the means when the offence also exists without a computer, but the internet is used to commit it. Examples are online purchase fraud, fake invoices sent by email, phishing messages, extortion by email and threats on social media.

In these cases the ordinary offences apply, such as fraud (Article 326 Sr), extortion (Article 317 Sr), forgery (Article 225 Sr) and identity fraud (Article 231b Sr). The digital method does not change the offence, but it can affect how the offence is investigated and proven.

The distinction determines which provision is charged, what the maximum penalty is and what the prosecutor has to prove. It also affects the investigation.

For computer offences, the prosecutor must prove, for example, that the intrusion was intentional and unlawful. For fraud, the prosecutor must prove deception by a false name, a false capacity, cunning tricks or a web of lies, and that the victim was induced to hand over money or goods. In practice, one incident often leads to several charges at once, for example computer trespass combined with fraud.

Investigations into computer crime require digital forensic research: analysis of logs, network traffic and devices. In fraud cases the police also trace payments and communication. Because perpetrators often operate from abroad, international cooperation is regularly needed.

The table below compares the two categories on their target, methods and legal basis.

AspectComputer crimeCyber crime (computer as the means)
TargetThe computer system or the data in itA person or organisation, usually their money or goods
ExamplesHacking, DDoS attack, malware, ransomwareOnline fraud, phishing, identity fraud, extortion by email
Main provisionsArticles 138ab, 138b, 139c, 139d, 350a and 350b SrArticles 225, 231b, 317 and 326 Sr
What must be provenIntentional and unlawful intrusion, disruption or damageThe elements of the ordinary offence, such as deception in fraud
InvestigationDigital forensic research into systems and logsDigital research plus tracing of payments and communication

Which forms of cyber crime are common in the Netherlands?

Dutch IT staff responding to cyber threat with 'Major Types' text on noticeboard

Three forms affect businesses and individuals most often in practice: ransomware, the theft of data and login details, and phishing combined with social engineering. They often occur together: a phishing email provides login details, which are then used to install ransomware.

Ransomware and digital extortion

In a ransomware attack, the attacker encrypts an organisation’s data and demands payment for the key. Increasingly, the attacker also copies the data first and threatens to publish it if the victim does not pay.

Ransomware affects multinationals, small and medium-sized businesses and public bodies alike. Attackers often gain access through a phishing email, stolen login details or a vulnerability in software that has not been updated.

Legally, ransomware usually involves several offences at once: computer trespass (Article 138ab Sr), damaging data by encrypting it (Article 350a Sr) and extortion (Article 317 Sr). If personal data have been copied or made inaccessible, it is also a data breach, with the notification obligations discussed below.

Whether to pay is a business decision with legal aspects. Paying does not guarantee that the data will be returned or deleted, and payment to a sanctioned party can itself be prohibited. Discuss this with your lawyer and the police before you decide.

Data theft and stolen login details

Criminals target databases and login details because they can resell them or use them for fraud. Stolen login details are traded online and used to log in to email accounts, company systems or bank accounts.

Once criminals have login details, they can send fake payment requests from a genuine email account, change the bank details on invoices or take over customer accounts. For the victim organisation, this is often both a security incident and a data breach.

Buying or holding stolen data knowing that it was obtained through a crime is also punishable. Since the Computer Crime Act III (Wet computercriminaliteit III), the Criminal Code contains a separate offence for handling stolen data (heling van gegevens).

Phishing and social engineering

Phishing is the attempt to obtain login details, payment details or access by pretending to be a trusted party. Messages increasingly come not only by email, but also by text message, WhatsApp, telephone and social media.

Criminals imitate banks, parcel services, government bodies and platforms such as LinkedIn. In so-called CEO fraud, an employee receives an urgent request, apparently from a director, to make a payment. In bank helpdesk fraud, a caller pretends to be from the bank and persuades the victim to transfer money to a “safe account”.

Social engineering exploits trust, time pressure and authority. That is why training and clear internal procedures are just as important as technical measures.

The table below summarises the main threats, their typical targets and methods.

ThreatTypical targetsTypical methods
RansomwareBusinesses of all sizes, public bodies, healthcare and educationEncrypting and copying data, extortion, access via phishing or unpatched software
Data theft and stolen login detailsDatabases, email accounts, company systems, bank accountsCredential theft, resale of data, account takeover, invoice fraud
Phishing and social engineeringEmployees, professionals and consumersFake messages by email, text, telephone or social media; CEO fraud; bank helpdesk fraud

The Criminal Code contains specific computer offences and the ordinary offences that also apply online. The maximum penalty depends on the offence and on aggravating circumstances, such as copying data or causing serious damage.

Which provisions of the Criminal Code apply?

The main provisions are the specific computer offences in Articles 138ab to 139d and 350a to 350b Sr, and the ordinary offences such as fraud, extortion, forgery and identity fraud. The legislator has amended these rules several times, most recently through the Computer Crime Act III.

An overview of the main provisions:

  • Article 138ab Sr: computer trespass, intentionally and unlawfully gaining access to a computer system or part of it.
  • Article 138b Sr: intentionally and unlawfully obstructing access to or the use of a computer system by sending it data, as in a DDoS attack.
  • Articles 139c and 139d Sr: intercepting or recording data and communications, and placing equipment or distributing tools for that purpose.
  • Articles 350a and 350b Sr: intentionally (350a) or culpably (350b) altering, deleting, rendering unusable or making inaccessible data, and distributing malware.
  • Article 231b Sr: identity fraud, the intentional and unlawful use of someone else’s identifying personal data where this may cause harm.
  • Article 326 Sr: fraud, inducing someone to hand over money or goods by deception.
  • Article 317 Sr: extortion, for example the ransom demand in a ransomware attack.

Computer trespass does not require that the perpetrator bypassed a security measure. Getting in without permission is enough, for example by using someone else’s password.

Which penalties apply?

The maximum penalties differ per offence. Basic computer trespass carries a maximum of two years’ imprisonment or a fourth-category fine; if the perpetrator then copies or records data, the maximum is four years.

Other maximum penalties are set out in the provision itself. A few examples:

  • DDoS attacks and damaging data (Articles 138b and 350a Sr) carry a maximum of two years in the basic form, with higher maximums where serious damage is caused or vital infrastructure is hit.
  • Distributing malware carries a higher maximum than the basic data offence.
  • Fraud (Article 326 Sr) carries a maximum of four years’ imprisonment.
  • Identity fraud (Article 231b Sr) carries a maximum of five years’ imprisonment.

The actual sentence imposed is usually well below the maximum. The court takes into account the scale of the attack, the damage caused, the method used, whether vital infrastructure was hit, the perpetrator’s role and his personal circumstances. For young first offenders, alternative sanctions are sometimes imposed.

Besides a prison sentence, fine or community service, the court can order the confiscation of criminal proceeds, such as cryptocurrency obtained through extortion. Victims can join the criminal case as an injured party (benadeelde partij) to claim compensation.

What if the attacker is abroad?

Dutch criminal law applies to an attack on a system in the Netherlands, even if the attacker is abroad. Prosecution is then possible, but requires international cooperation, which can take time.

The Netherlands is a party to the Council of Europe Convention on Cybercrime (the Budapest Convention), which provides for cooperation in investigations and the exchange of evidence. Within the EU, the police cooperate through Europol and the prosecutors through Eurojust. The Dutch police have specialised cybercrime teams for complex investigations.

In practice, the chance of tracing and prosecuting an attacker abroad varies greatly. For victims, it is therefore important not to rely solely on the criminal case, but also to take their own steps to limit and recover the damage.

What should you do after a cyber incident?

Limit the damage first, secure the evidence and check your notification obligations. Then report to the police and consider how to recover your loss.

Report to the police

You can report computer crime and online fraud to the police. For some forms of online fraud, such as fraud when buying or selling online, you can report online; for more serious incidents it is better to make an appointment.

Bring as much information as possible: dates and times, screenshots, email headers, log files, transaction details and the amount of the damage. Do not delete anything and do not reset systems before the evidence has been secured, if possible with the help of an IT forensic specialist.

Check your notification obligations

If personal data are involved, you may have to notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of the breach, under Article 33 of the General Data Protection Regulation (GDPR). If the breach is likely to result in a high risk to the people involved, you must also inform them without undue delay.

Organisations that fall under the Cybersecurity Act must report significant incidents in stages through the National Cyber Security Centre’s reporting point: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. The one report reaches both the relevant CSIRT and the supervisor. Other sectors, such as financial institutions, may have their own rules.

Recover your loss

There are several civil routes. You can claim damages from the perpetrator on the basis of tort (Article 6:162 of the Dutch Civil Code), either in the criminal case as an injured party or in separate civil proceedings.

If money was taken from your account without your permission, the bank must in principle refund an unauthorised payment transaction under Article 7:528 of the Dutch Civil Code, unless you acted fraudulently or with intent or gross negligence. If you transferred the money yourself, for example in bank helpdesk fraud, the rules are different and the outcome depends on the circumstances. Complaints about a bank can be submitted to the Financial Services Complaints Institute (Kifid).

Also check your insurance. Some businesses have a cyber insurance policy that covers costs of recovery and forensic research, and sometimes loss of income. Insurers usually impose strict notification periods.

If a supplier, such as an IT service provider, failed to comply with the security agreements in the contract, you may be able to hold that supplier liable for breach of contract. Much depends on the contract and on any limitation of liability.

How can individuals and businesses prevent cyber crime?

Combine technical measures with training and a clear incident response plan. Most successful attacks exploit a known weakness or a human mistake.

Prevention is not only sensible; for some organisations it is also a legal obligation. Under the GDPR, every organisation that processes personal data must take appropriate technical and organisational security measures. Organisations covered by the Cybersecurity Act have a duty of care to manage their cyber risks, and their directors are responsible for this.

Technical measures

Build several layers of defence. The basic measures are:

  • install software updates and security patches quickly;
  • use multi-factor authentication for email, remote access and financial systems;
  • use up-to-date security software on laptops, phones and servers, and a properly configured firewall;
  • make regular backups and keep at least one copy offline, so ransomware cannot reach it;
  • restrict access rights to what employees actually need;
  • monitor your network for unusual activity.

Larger organisations should also consider a system that detects and isolates suspicious activity automatically, and periodic testing of their security by an external party.

The human factor and training

Many attacks start with a human action: clicking a link, opening an attachment or making a payment on a fake instruction. Training helps employees recognise these situations.

Good training is practical. Think of simulated phishing emails, short sessions on recent forms of fraud and clear examples from your own sector. Make it easy and safe for employees to report a mistake quickly, because the first minutes after a click often determine the damage.

Also agree on fixed procedures. For example: a change of bank details or an urgent payment request is always verified by telephone using a known number, never using the number in the email.

Risk management and an incident response plan

Prepare for an incident before it happens. An incident response plan sets out who does what, whom you call and which deadlines apply.

A good plan covers at least:

  • how incidents are detected, contained and recovered from;
  • who decides, including on communication with customers and the media;
  • contact details of your IT supplier, forensic specialist, insurer and lawyer;
  • the notification obligations under the GDPR and, where applicable, the Cybersecurity Act;
  • how evidence is secured for a police report and any claims.

Carry out regular risk assessments and keep an up-to-date overview of your systems and data. Test the plan at least once a year with a short exercise.

Individuals can protect themselves in a similar way: keep software up to date, use strong and unique passwords with a password manager, switch on two-step verification and be cautious about sharing personal information online. Check your bank statements and accounts regularly, so that you notice unauthorised activity early.

In summary

  • Dutch law distinguishes between computer offences, where the system is the target, and ordinary offences committed online, such as fraud and identity fraud.
  • Basic computer trespass carries a maximum of two years’ imprisonment, rising to four years if data are copied; fraud carries four years and identity fraud five years.
  • After an incident: secure the evidence, report to the police and check the 72-hour GDPR notification obligation and, where applicable, the Cybersecurity Act deadlines.
  • Loss can be recovered from the perpetrator, in some cases from the bank, through insurance or from a supplier that failed to meet its obligations.
  • Prevention combines technical measures, training and a tested incident response plan.

Frequently asked questions

What is the difference between computer crime and cyber crime in the Netherlands?

In computer crime, the computer system or its data is the target, for example hacking, a DDoS attack or ransomware. These fall under specific provisions such as Articles 138ab, 138b and 350a of the Criminal Code. In cyber crime in the broader sense, the computer is only the means to commit an ordinary offence such as fraud, extortion or identity fraud.

What are the major types of cyber crime affecting individuals and businesses in the Netherlands?

The most common forms are ransomware, the theft of data and login details, and phishing combined with social engineering, such as CEO fraud and bank helpdesk fraud. They often occur together: a phishing message provides login details that are then used for fraud or ransomware.

What are the potential legal consequences of committing cyber crime in the Netherlands?

The maximum penalty depends on the offence. Basic computer trespass carries up to two years’ imprisonment, rising to four years if data are copied. Fraud carries up to four years and identity fraud up to five years. The court can also order confiscation of criminal proceeds and compensation for victims.

How can individuals and businesses protect themselves from cyber crime?

Install updates quickly, use multi-factor authentication, make offline backups and restrict access rights. Train employees to recognise phishing and verify payment requests by telephone. Businesses should also have a tested incident response plan that includes the notification obligations under the GDPR and, where applicable, the Cybersecurity Act.

Law & More assists businesses and individuals in the Netherlands with the criminal law aspects of cyber incidents, reporting to the police, notification obligations and claims to recover loss, in English and Dutch. Want to know more about our firm? Visit Law & More. If you are a suspect in a cyber crime investigation, Law & More can also assist with your defence. Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.

Need Legal Assistance?

Have you received a letter, a writ of summons or a judgment? Send us the documents. We will check which deadlines apply and what your options are.

This article provides general information and is not a substitute for advice on your specific situation.

Related articles

A business that accepts, holds or pays in crypto-assets takes on obligations that have little

If you or a family member has been arrested in the Netherlands, the cost of

Almost every commercial software product contains open source components, usually hundreds, chosen by developers rather

If someone damages your reputation online, Dutch law gives you two routes: a criminal complaint

An IT services agreement is the contract under which a provider delivers technology services to

An AI policy is the set of internal rules that determines how, why and under

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.