< Back to all clusters
[TECHNOLOGY] · Netherlands · 5 sources

Netherlands faces surge in AI‑driven phishing attacks on banks and advisers

The Dutch Authority for Personal Data (Autoriteit Persoonsgegevens, AP) reports that AI‑assisted phishing is making attacks harder to detect, leading to a sharp rise in cyber incidents. Account takeovers jumped from 607 in 2024 to 1,742 in 2025, and total data‑breach notifications rose to 39,407, of which 2,428 were caused by cyber attacks.

Financial advisers handling sensitive client data are urged to adopt technical safeguards such as multi‑factor authentication and stronger email filtering, as awareness training alone is no longer sufficient. The AP advises limiting access privileges and encouraging staff to report suspicious messages.

Specific scams highlighted include fake payment requests purporting to come from Infomedics, the Dutch invoicing service for health‑care providers. The fraudulent emails cite amounts of €100‑€160 per invoice, use deceptive sender addresses and omit the legitimate 14‑digit payment reference ending in 071.

A parallel phishing campaign impersonates ABN AMRO, claiming a mandatory customer‑data synchronization deadline of 31 July and urging recipients to click a link to verify their account. The bank stresses it never asks customers to log in via email links or provide immediate payments.

Both incidents use urgent language, forged logos and counterfeit sender domains to pressure victims into clicking, highlighting the need for organizations and individuals to verify sender details, avoid unsolicited links, and employ robust security measures.

Entities: ABN AMRO · ABN AMRO Bank · Autoriteit Persoonsgegevens · Autoriteit Persoonsgegevens (AP) · Dutch financial advisory firms · Infomedics · Netherlands

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

  • [○ 1 SOURCE] 2,428 of the 2025 breaches were the result of cyber attacks. (Autoriteit Persoonsgegevens report)
  • [○ 1 SOURCE] Infomedics received many reports of phishing emails with fake payment requests, typically for amounts between €100 and €160. (Infomedics warning)
  • [○ 1 SOURCE] ABN AMRO warned that a phishing email claiming a mandatory data‑synchronisation deadline of 31 July is fraudulent and that the bank never asks users to log in via links. (ABN AMRO advisory)
  • [○ 1 SOURCE] ABN AMRO advises anyone who clicked the fraudulent email to contact the bank using the number on their card or in the app, run a virus scan, and enable two‑step verification. (ABN AMRO advisory)
  • [○ 1 SOURCE] A total of 39,407 data‑breach notifications were reported to the AP in 2025, up from 37,839 the previous year. (Autoriteit Persoonsgegevens report)
  • [○ 1 SOURCE] Legitimate Infomedics emails are sent from rekening@infomedics.nl, contain a 14‑digit payment reference ending in 071, and never include direct iDEAL links. (Infomedics guidance)
  • [○ 1 SOURCE] AI is being used by cybercriminals to create more convincing phishing emails, making them harder for employees to detect. (Autoriteit Persoonsgegevens analysis)
  • [○ 1 SOURCE] Account takeovers in the Netherlands rose from 607 in 2024 to 1,742 in 2025. (Autoriteit Persoonsgegevens report)
  • [○ 1 SOURCE] AI is being used by cybercriminals to generate larger numbers of credible phishing emails. (AP analysis)
  • [○ 1 SOURCE] AB AMRO states it never asks customers to log in via a link in an email or to provide immediate payments. (AB AMRO policy)
  • [○ 1 SOURCE] A phishing campaign impersonating AB AMRO claims a mandatory customer‑data synchronization deadline of 31 July 2026. (Phishing alert)
  • [○ 1 SOURCE] Legitimate Infomedics payment emails always come from the address rekening@infomedics.nl and include a 14‑digit payment reference ending in 071. (Infomedics guidance)