Online banking via Wi-Fi hotspots: stay secure
Information security consultancy SecureLabs and investigative journalist Brenno de Winter have demonstrated a hypothetical attack on online banking using a programmable mobile Wi-Fi router.

A skilled cybercriminal could programme a Wi-Fi hotspot to intercept, redirect and manipulate internet traffic between any website and an unsuspecting user’s browser. This could give the criminal covert access to users’ accounts and confidential data on secure websites such as Facebook, Amazon or PayPal. The reconstruction shows how this could also be possible with online banking.
No successful attack using this method against online banking is known in the Netherlands. The attack attempts to deceive inattentive users and can be effectively prevented if both banks and users remain alert.
What do banks do?
Banks continually invest in new measures to keep banking secure. An SSL security certificate on an online banking website already provides good basic protection if users pay close attention. When users see a green padlock in their browser’s address bar, they can verify that they have a secure connection to their bank. Clicking the padlock allows them to confirm that they are connected to their own bank and that all data, including access codes, is encrypted before being exchanged with the website.
The demonstrated attack concerns online banking through a standard web browser. Many banks offer smartphone and tablet apps for mobile banking. In the scenario demonstrated, banking through such an app offers greater security than using a standard browser.
Banks can also identify and prevent suspicious transactions. Transfers to familiar accounts, such as those of a landlord, sports club or municipality, are processed normally. If a transaction deviates from the account holder’s usual payment pattern, for example by going to an account never used before, the bank may carry out additional checks.
What can users do?
Users can also take several precautions. To begin with, they should avoid online banking through unknown and unsecured Wi-Fi hotspots whose owner is unknown and which do not require a secure password. Users should be particularly cautious with publicly accessible hotspots.
When using a standard browser for online banking, it is advisable to connect only through a trusted and secured Wi-Fi hotspot. Mobile banking through the bank’s app offers better protection against the attack described.
Users should also check the green padlock on their bank’s website. During an attack, a padlock may appear on the webpage itself rather than in the browser’s address bar. Depending on the browser, a fake padlock may also appear near the top of the browser where the bank’s logo is normally shown. This is a warning sign: the genuine padlock must appear in the browser’s address bar, in green, together with the bank’s full name. Clicking it should open a pop-up showing the bank’s name without any warnings.
Account holders can further improve online banking security by following the banks’ uniform security rules (in Dutch)(opens in new window) . Bank websites and VeiligBankieren.nl (in Dutch)(opens in new window) provide detailed information.
Related articles
-
Digital Resilience and AI
-
News
-
Digital identity
-
-
New bank account numbers Dutch Tax Administration
-
News
-
Account-to-Account payments
-
-
Workshop on agentic payments and the EUDI Wallet
-
News
-
Digital identity
-
-
Payment orders with unstructured address data will be rejected starting November 14 or 15, 2026
-
News
-
European legislation
-
-
DNB payment figures available for 2025
-
News
-
Account-to-Account payments
-
-
Stakeholder Forum looks (far) ahead
-
News
-
European legislation
-