phishing
Netherlands tops Europe's payment fraud league in 2025
2026-07-09

Dutch police have arrested two young men, aged 21 and 23, accused of running a credit card phishing operation out of Amsterdam and Zaandam. When officers raided their homes on 23 June 2026, they left with devices, luxury goods, and a car. The pair are said to have harvested card details through fake websites, used some themselves, and passed the rest on to other fraudsters.
The timing was almost cinematic. A day after the arrests became public, De Nederlandsche Bank published its 2025 payment fraud figures. Cases rose roughly 30% to about 658,000. Losses climbed 22% to €198 million. Card fraud accounted for the majority, with more than half a million dodgy transactions logged over the year.
How criminals are getting the card numbers
The central bank's explanation for where all these card details are coming from is short and, at this point, unsurprising: phishing. Analysis by BioCatch, drawing on European Banking Authority data, now ranks the Netherlands as the worst country in the European Economic Area for digital payment fraud.
The lures will be familiar to anyone who has owned a phone in the last two years:
- Fake PostNL and DHL redelivery texts asking for a small fee
- Spoofed bank login pages that harvest credentials the moment they are typed
- Malicious QR codes physically stuck over legitimate ones in car parks, on menus, at charging stations
None of this is exotic. It works because it looks ordinary, and because most people have been trained by years of legitimate messages to tap the link and get on with their day.
Phishing sold like software
The June arrests are not the Noord-Holland cybercrime unit's first this year. In May they picked up two 23-year-olds from Bergschenhoek, accused of selling phishing panels to fraudsters across Europe. Panels are essentially ready-to-run kits, complete with fake bank sites, admin dashboards, and support, marketed via social media.
This is what makes the fraud numbers hard to bend. The people building the tools are not necessarily the people using them. One arrest at the toolmaker level can supply dozens of downstream operators, and one arrest at the operator level does nothing to the toolmaker. Two suspects in Amsterdam is a good day for police. It is not a dent in the pipeline.
The victims' side of the ledger
The uncomfortable footnote sits in the 2024 numbers. Only around 1% of Dutch fraud victims got their money back. About half told their bank. A fifth told the police. The rest either absorbed the loss or gave up somewhere in the reporting process.
That is the arithmetic behind the headline. A 30% jump in cases, a 22% jump in losses, and a recovery rate that rounds to nothing. Arrests are welcome, and the raids in Amsterdam, Zaandam and Bergschenhoek clearly took skill and patience. But the volume of card fraud running through Dutch accounts suggests the majority of the people behind it are still very much in business, and the tooling to replace anyone who does get caught is available to anyone with a Telegram account and a bit of cash.
The Netherlands is the current European league leader, but nothing about the mechanics is uniquely Dutch. The same texts, the same fake bank pages, and the same QR overlays are turning up everywhere else too. The Dutch just happen to have the clearest numbers.