€3.81 million lost to internet banking phishing in 2018
Losses from phishing in internet banking rose from €1.05 million in 2017 to €3.81 million in 2018. Nevertheless, total losses from payment fraud fell slightly in 2018, by 2 per cent.
The overall decline was mainly due to less fraud involving debit cards, direct debits and paper credit transfer forms. Once again, no mobile banking fraud was reported at all in 2018.
More debit card payments, lower fraud losses
Despite a 12.6 per cent increase in the number of debit card payments, losses from debit card fraud fell by 33 per cent last year compared with the previous year, to €4.91 million. There were still no incidents of contactless pickpocketing, mainly because it is not profitable and potential offenders can be traced easily.

Tighter procedures at banks also led to a sharp fall in fraud involving direct debits and paper credit transfer forms, from €1.28 million in 2017 to €337,000 in 2018.
More and more convincing phishing across more channels
The rise in losses from internet banking phishing appears to be the result of several factors:
- Fraudsters are using better tools that allow them to carry out phishing attacks more easily, more frequently and on a larger scale.
- Fake emails and websites are becoming more convincing, with fewer language errors and better design and formatting.
- Fraudsters are increasingly able to address their targets personally and convincingly, using the correct salutation and name, including by text message, messaging apps such as WhatsApp and social media such as Facebook.
- Fraudsters also use phishing to obtain security codes that allow them to install a mobile banking app on their own smartphone in the victim’s name. The app then gives them access to the victim’s bank account.
- The sharp rise in phishing also appears to be spreading outside the Netherlands. Earlier this month, Belgian banks reported that phishing losses among their customers had risen from €2.5 million in 2017 to €8 million in 2018.
Check the sender and web address
Bank customers can avoid phishing losses by paying close attention to the real sender address of messages that appear to come from banks. Do not simply click hyperlinks in messages, and carefully check the web address of any website that asks for internet or mobile banking security codes. Banks will never use links in emails, text messages or other messages, or a telephone call, to ask for internet or mobile banking security codes. Never enter the PIN for a debit card on a web page either. Forward a fake message to the bank that supposedly sent it. More advice and tips are available at VeiligBankieren.nl (in Dutch) .
Banks continually improve their internet and mobile banking systems to detect and block fraudulent transactions. They also take part in private- and public-sector initiatives to improve the technical security of messaging and to track down and prosecute fraudsters. Banks provide their customers with extensive information about secure banking on radio and television and online, including on the joint information website VeiligBankieren.nl (in Dutch) .
Victims of online banking fraud who have taken proper care of their devices and internet and mobile banking security codes are reimbursed in full or in part by their bank. In 2018, victims were reimbursed for 96 per cent of internet banking fraud.
Related articles
-
Checking In and Out on Public Transportation Is Now Even Smoother with Your Smartphone
-
News
-
Card payments
-
-
More travelers very satisfied about traveling with payment card
-
Press release
-
Card payments
-
-
Digital Resilience and AI
-
News
-
Digital identity
-
-
Workshop on agentic payments and the EUDI Wallet
-
News
-
Digital identity
-
-
Six out of ten retail business owners say they are prepared for card payments failures
-
News
-
Card payments
-
-
Make sure you have (digital) fallback options in case of a potential card payments failure!
-
News
-
Card payments
-