See more of Dutch Brief in your Google search results
An estimated 2.5 million people in the Netherlands fell victim to cybercrime, or to an online form of fraud, deception or intimidation, last year, according to a new report by prosecutors and police that warns the threat is becoming harder to contain.
The scale of it
The figure comes from the Cybercrimebeeld Nederland, a report published every two years by the public prosecution service (OM) and the Dutch police. It equates to around 17 percent of everyone in the country aged 15 or over, up from about 16 percent the year before, a steady rise as more of daily life moves online.
According to the national statistics office CBS, whose Veiligheidsmonitor survey underpins the numbers, online fraud and deception is the most common form: about 10 percent of people aged 15 and over experienced it, most often “purchase fraud”, where something is paid for online but never delivered. Around 6 percent had an account or device hacked, and 3 percent faced online threats or intimidation. Many cases go unreported, so the true scale is almost certainly larger; only about half of victims report what happened to the police or another body.
The human cost is not only financial. Of those affected, around a fifth said the incident led to emotional, psychological or financial problems, with emotional harm reported most often, and financial damage most common among victims of phishing.
Crime you can buy off the shelf
The report’s central warning is about how the criminal landscape is changing. Offenders increasingly work across borders and simply pay for whatever expertise they do not have themselves. Technical skill, the report says, is now widely for sale: ready-made tools, stolen data and hacking services mean that even novices can mount complex attacks, a model often described as cybercrime-as-a-service.
The data itself has become a weapon. “Criminals combine data from earlier hacks with newly stolen data,” said Christa de Pagter, the national public prosecutor for cybercrime. That lets them build a fuller picture of a target and launch more convincing, tailored attacks, often posing as a bank or a crypto platform to pressure people into acting quickly. It is exactly the pattern seen in the wave of Dutch data breaches over the past year: each leak becomes raw material for the next scam.
One recent example cited in the report is this year’s hack of the telecoms company Odido, which police believe was carried out by a Dutch gang using the name ShinyHunters, exposing the data of 6.2 million customers and leading to a one-million-euro ransom demand that the company refused.
SPONSORED
You’re overpaying your accountant. And they still don’t call you back.
Neno gives you a dedicated bookkeeper, automated admin, real-time financial insights and a free business bank account. Everything your business needs, in one place.
No chasing. No surprises. No unnecessary costs.
AI as an accelerant
Artificial intelligence features in the report as a “catalyst”. The assessment is measured rather than alarmist: AI does not fundamentally change what cybercrime is, but it increases its speed and scale, and, crucially for ordinary users, makes scam emails and messages harder to spot by removing the clumsy language and obvious errors that once gave phishing away.
State actors and a young new generation
Two other trends stand out. The first is the growing entanglement of state actors with criminal groups, through what the report calls hybrid warfare, which is eroding the line between ordinary cybercrime and national security. States can use criminals as proxies, directing them or supplying money and infrastructure. In May, Dutch investigators arrested two men over servers used for Russian-linked cyberattacks, and the report also refers to two 17-year-olds detained last year for mapping wifi networks around government buildings in The Hague.
The second is the emergence of a new generation of young, Western cybercriminals, driven by money and status rather than ideology, who meet in loose online networks and specialise in stealing data and cryptocurrency. They range in age from 11 to 25, according to the police cybercrime lead, Stan Duijf. Children, he said, are often lured in through online games such as Roblox, Fortnite and Minecraft, where they can be groomed in chat rooms. “It’s just like the schoolyard: they start with mischief,” Duijf said, but some go on to become cybercriminals.
How to protect yourself
For readers, the practical defences are largely familiar, but they matter more than ever now that scams are better targeted and better written. Be sceptical of any unexpected message, by email, text, call or chat, that urges you to act quickly or pay, even if it appears to come from your bank, a delivery company or a well-known shop, and even if it quotes real details about you. Do not click links or call numbers in such messages; instead, go to the organisation’s official app or website directly. Use a strong, unique password for each important account, and turn on two-factor authentication, which stops a stolen password alone from unlocking your accounts. Be cautious when buying from unfamiliar sellers or social-media adverts, a guard against the purchase fraud that tops the list. And for parents, the report is a prompt to pay attention to what children are doing in gaming chat rooms.
Anyone who has been targeted can report it to the police and to the Fraudehelpdesk, the national fraud reporting centre. The authorities stress there is no shame in being caught out, criminal gangs are sophisticated, and it can happen to anyone. Reporting helps build the picture needed to catch them.




