Phishing and internet fraud are criminal offences under Dutch law. A fraudster who tricks you into handing over login details or transferring money commits oplichting (fraud) under article 326 of the Dutch Criminal Code, and often computervredebreuk (unauthorised access to a computer system) under article 138ab as well. If money has left your account without your genuine consent, your bank must in principle refund it under article 7:528 of the Dutch Civil Code, unless it can show you acted fraudulently or with gross negligence. Speed matters: report the incident to your bank and file a police report as soon as you notice it.
What counts as phishing under Dutch law
Phishing is a form of deception in which a criminal poses as an organisation you trust – a bank, a payment provider, a delivery company, the Belastingdienst – in order to obtain login credentials, payment card details, a verification code or a signature in a banking app. The medium varies: an email, an SMS message (smishing), a phone call from someone claiming to be from the bank fraud desk (vishing), a message on WhatsApp or LinkedIn, or a cloned website behind a sponsored search result.
Dutch criminal law does not use the word phishing. What it punishes is the conduct behind it. Passing yourself off as a bank in order to move someone to hand over money or data is oplichting under article 326 of the Wetboek van Strafrecht. Logging into an account with credentials obtained that way is computervredebreuk under article 138ab. Using another person’s identifying data to cause harm or gain an advantage is punishable under article 231b, forging documents or a digital record falls under article 225, and misusing payment cards or the data behind them falls under article 232. Where an attack ends in encrypted files and a ransom demand, article 350a (altering or destroying data) and article 317 (extortion) come into play.
What counts as internet fraud
Internet fraud is the wider category: any deception carried out through an online channel. It covers webshops that take payment and never ship, fake rental listings, investment scams built around cryptocurrency, invoice fraud in which a supplier’s bank details are silently changed, and CEO fraud in which a finance employee receives an urgent payment instruction that appears to come from a director. Legally these all run through the same provision, article 326 of the Criminal Code, because the core is the same: a deceptive act that moves someone to part with money, goods or data.
The practical difference between phishing and the wider category is where the loss arises. In a phishing case the money usually leaves a payment account, which brings the payment services rules in Book 7 of the Civil Code into play. In a webshop or investment scam the victim transfers the money themselves, which makes recovery a civil matter against the fraudster and, sometimes, against the platform or the bank that received the funds.
How to recognise a phishing message
Modern phishing messages are well written and often personalised, so the old advice about spelling mistakes is no longer enough. Three signals remain reliable. The message manufactures time pressure, telling you an account has been blocked or a payment will be reversed unless you act now. It steers you away from the channels you normally use, asking you to click a link or call a number rather than open your own banking app. And it asks for something a bank never asks for: a verification code, a signature in your banking app for a transaction you did not start, or permission for remote access software on your device.
For organisations, the same logic applies to payment instructions. A supplier that changes its bank details by email, a director who asks for an urgent transfer outside the usual approval chain, or an invoice that arrives slightly earlier than expected all warrant a call back on a number you already had on file, not one supplied in the message.
Getting your money back from the bank
A payment transaction to which the consumer did not give consent is an unauthorised transaction within the meaning of article 7:522 paragraph 2 of the Dutch Civil Code. Article 7:528 paragraph 1 then obliges the payment service provider to refund the amount immediately and restore the account to the state it would have been in. The starting point, in other words, is that the bank carries the loss.
The exception sits in article 7:529 paragraph 1: the bank does not have to refund if the account holder acted fraudulently, or intentionally or with gross negligence failed to meet the duties in article 7:524, which require the payment instrument to be used in accordance with the applicable conditions and security measures. Gross negligence is a high bar and is judged on all the circumstances, not on the fact of the loss alone. Article 7:529 paragraph 3 adds a further protection: where the bank did not apply strong customer authentication, the payer bears no loss at all.
If the bank refuses, a consumer can put the dispute to the Klachteninstituut Financiele Dienstverlening (Kifid) after completing the bank’s internal complaints procedure, or bring the claim before the civil court. Business account holders sit outside most of the consumer protections and are largely dependent on the contract with the bank and on general liability rules, which makes the internal payment controls of a company all the more important.
Claiming damages from the fraudster or a negligent organisation
Where the perpetrator is identified, the loss can be recovered as an unlawful act under article 6:162 of the Civil Code. In practice this most often happens inside the criminal case: a victim can join the criminal proceedings as an injured party (benadeelde partij) under article 51f of the Code of Criminal Procedure and ask the criminal court to award compensation, which is cheaper and faster than a separate civil claim. The court will only deal with a claim that does not place a disproportionate burden on the criminal proceedings, so the loss must be documented and straightforward to calculate.
A second route is a claim against an organisation whose poor security made the fraud possible – the employer whose mailbox was compromised, the platform that allowed a seller to operate without any verification, the processor that leaked a customer database. That claim also runs through article 6:162, and the standard applied is what a careful organisation should have done given the state of the art and the sensitivity of the data. The rights of victims of cyberattacks sets out how notification duties, compensation and insurance interact in those cases. Proof is usually the hard part; our article on how to prove digital deception deals with the evidence that carries weight.
What the GDPR requires of organisations hit by phishing
A successful phishing attack on a company almost always produces a personal data breach. Article 32 of the GDPR requires controllers and processors to take appropriate technical and organisational security measures, and article 33 requires a breach to be reported to the Autoriteit Persoonsgegevens without undue delay and where feasible within seventy-two hours of becoming aware of it, unless it is unlikely to result in a risk to the people concerned. Where the risk to those people is high, article 34 adds a duty to inform them directly.
The supervisory authority looks less at the fact that an attack succeeded than at what preceded it: whether multi-factor authentication was in place, whether access rights were limited to what staff actually needed, whether logging allowed the incident to be reconstructed, and whether staff had been trained. An organisation that can show a considered security posture and a documented response is in a far stronger position than one that only starts writing things down after the event. Who is responsible after a data breach works through how that liability is allocated.
Reporting duties under the Cyberbeveiligingswet
Since 15 August 2026 the Cyberbeveiligingswet, which implements the NIS2 Directive in the Netherlands, applies alongside the GDPR. Organisations that fall within its scope must register with the Nationaal Cyber Security Centrum, take care-duty measures covering risk management, supply chain security and incident handling, and report significant incidents twice: an early warning within twenty-four hours and a fuller notification within seventy-two hours. Management can be held personally accountable for compliance with the care duty.
The two regimes overlap but are not the same. A phishing incident that compromises a mailbox may trigger a GDPR notification to the Autoriteit Persoonsgegevens and a separate incident report under the Cyberbeveiligingswet, on different deadlines and to different authorities. Working out in advance which regime applies to your organisation, and who makes the call at three in the morning, is part of the preparation. Our guide on cybersecurity incident reporting duties sets the deadlines side by side.
Cross-border cases and how evidence is obtained
Phishing operations are rarely confined to one country. The sending infrastructure sits in one jurisdiction, the victim in another, the money in a third and the hosting of the cloned site in a fourth. Dutch criminal jurisdiction extends to offences committed on Dutch territory, and an offence directed at a victim in the Netherlands is generally treated as committed here, so an aangifte with the Dutch police is the right starting point even when the perpetrator is abroad.
Obtaining evidence from another state runs through established channels. Within the European Union the European Investigation Order allows a Dutch prosecutor or investigating judge to request data, account information or the freezing of funds from another member state. Beyond the EU, the Council of Europe Convention on Cybercrime, concluded in Budapest in 2001, provides for expedited preservation of stored computer data and mutual assistance between the states that have signed it. Europol and Interpol coordinate operations but do not themselves prosecute; the case remains with a national prosecuting authority.
For the victim this has a practical consequence. Recovery of the funds usually depends on how quickly the receiving bank can be alerted, because money moved through a mule account is dispersed within hours. Reporting to your own bank immediately, so it can attempt a recall, is more likely to produce a result than any later legal step.
Preventing phishing and internet fraud in your organisation
Prevention is mostly a matter of removing single points of failure rather than of buying software. Multi-factor authentication on every account that can reach company data, unique passwords held in a password manager, and prompt patching of devices and software remove the majority of opportunistic attacks. Payment fraud needs a separate control: a fixed rule that changes to supplier bank details are verified by telephone on a previously known number, and that no single person can both create and release a payment.
Training closes the remaining gap, provided it is repeated and realistic. Staff who have seen a convincing simulated phishing message recognise the real one; staff who have only read a policy generally do not. Finally, decide in advance what happens in the first hour after an incident: who isolates the account, who preserves the logs, who contacts the bank, and who assesses whether a notification duty has been triggered. That decision list is worth more on the day than any amount of after-the-fact analysis.
What to do if you have been targeted
Act in this order. Contact your bank through its official fraud number and ask for the transaction to be blocked or recalled. Change the credentials of the account that was compromised and of any other account using the same password. Preserve everything: the original message with its headers, screenshots, transaction references and the times at which you noticed each step. File a police report, which is required for most insurance claims and is the basis for any later claim as an injured party. If personal data of others has been exposed, assess the notification duties under the GDPR and, where applicable, the Cyberbeveiligingswet before the deadlines start to bite.
Law & More advises victims of phishing and internet fraud on recovering losses from banks, platforms and perpetrators, and advises companies on security obligations, breach notifications and liability after an incident. We assess your position, deal with the bank or the supervisory authority on your behalf, and take proceedings where that is the sensible route. Get in touch with our lawyers to discuss your situation. Further reading is collected in our Dutch IT law guides.


