Dutch Police Arrest Two in Credit Card Phishing

Two men arrested in Zaandam and Amsterdam for phishing scams as Netherlands tops European payment fraud rankings.

By Central
Dutch police arrest two for credit card phishing as payment fraud rises 30% to 658,000 cases in 2025.
Highlights
  • Dutch police arrested two men aged 23 and 21 from Zaandam and Amsterdam on June 23, 2026.
  • Payment fraud in the Netherlands rose

Dutch police have arrested two young men in connection with a phishing operation that systematically harvested credit card details from victims, marking another enforcement action in a country now ranked highest in the European Economic Area for digital payment fraud. The arrests, announced on June 29, 2026, follow a police investigation that targeted suspects aged 23 and 21 from Zaandam and Amsterdam respectively.

On June 23, 2026, officers detained the two individuals and searched their homes, seizing electronic devices believed to have been used for fraudulent transactions, along with luxury goods and a car. The suspects, who have not been publicly named, are alleged to have operated bogus phishing websites designed to trick victims into entering their payment card details. According to a police press release, the stolen data was not only misused directly by the suspects but also passed on to other fraudsters, a common pattern in which stolen credentials are sold, shared, and reused multiple times across criminal networks.

How the Phishing Scams Operate in the Netherlands

Although the police statement did not detail the specific phishing sites or lures used in this case, the broader threat landscape in the Netherlands provides a clear picture. Current credit card phishing scams in the country typically involve fake text messages impersonating PostNL or DHL, requesting redelivery fees, spoofed bank webpages, or increasingly, malicious QR codes that redirect victims to fraudulent login pages. These tactics exploit the trust users place in familiar brands and urgent messaging, making them highly effective at harvesting sensitive financial information.

Payment Fraud Reaches New Heights

Just one day after the arrests were made public, the Dutch central bank (DNB) released figures showing that payment fraud in the Netherlands rose by approximately 30% in 2025, reaching around 658,000 cases. Total losses climbed 22% to €198 million. Card payment fraud was the single most common category, with over half a million fraudulent transactions recorded, an increase of more than a quarter compared to the previous year. The central bank explicitly identified phishing as the primary method used by criminals to obtain these card details.

According to fraud-prevention firm BioCatch, which analyzed data from the European Banking Authority, the Netherlands now ranks highest of all countries in the European Economic Area for digital payment fraud. This ranking underscores the scale of the challenge facing Dutch authorities and financial institutions.

Phishing-as-a-Service and the Wider Criminal Ecosystem

This arrest is not an isolated event. On May 19, the same police unit detained two 23-year-old men from Bergschenhoek on suspicion of selling “phishing panels”—ready-made kits of fake websites that mimic genuine bank pages—to other criminals as a form of phishing-as-a-service. Police alleged that the pair sold their panels via social media to fraudsters in several countries, targeting banks across Europe. These cases together illustrate a thriving underground economy in which both the tools and the stolen data are commoditized.

The Reporting Gap: A Persistent Problem

Despite the scale of the problem, very few victims come forward to the authorities. In 2024, only 1% of Dutch fraud victims recovered their money. While approximately half reported the crime to their bank, just a fifth went to the police. This reporting gap means that enforcement actions, while necessary, represent only the tip of a very large iceberg. The cybercrime unit of the Dutch police’s Noord-Holland division has stated that further arrests are not ruled out, and the investigation continues.

What Affected Users Should Do Now

If you believe you may have entered your payment card details on a suspicious website, act immediately. Contact your bank or card issuer to report the potential compromise and request a replacement card. Enable transaction alerts and carefully review your statements for any unauthorized charges. Change the passwords on any accounts where you may have reused the compromised credentials, and enable two-factor authentication wherever possible. Use a reputable, no-log VPN service when accessing financial accounts over public Wi-Fi to reduce the risk of interception. Consider monitoring your credit report for signs of identity theft. Taking these steps quickly can limit the damage and help prevent further misuse of your data.

Share This Article