What you need to know
After an online scam in the Netherlands, the first priority is not to explain why the approach looked convincing. It is to prevent the next loss. Criminals may impersonate a bank, DigiD, the Belastingdienst, CJIB, a parcel company, a Marktplaats buyer, a relative or a customer-service agent. They use calls, text messages, WhatsApp, email, QR codes and copied payment pages to create urgency.
This Hokimi emergency guide is for newcomers, international students, working expats, families, older residents, online shoppers and anyone who uses DigiD. It cannot guarantee recovery. It gives you a practical sequence: stop → contact the bank → secure accounts and devices → preserve evidence → report through the correct route.
1. Run a 60-second scam check
You do not need to prove that the other person is definitely a criminal before you pause. A genuine bank, public authority, platform or relative should allow you to end the call, reopen the official app or verify the request through another channel.
- ✓ The contact was unexpected, but the sender already knows personal, banking or family details.
- ✓ You are told that an account will be blocked, a fine will rise, a parcel will be returned or a relative needs money immediately.
- ✓ You are instructed to keep the situation secret.
- ✓ The person resists a callback, video call or independent check.
- ✓ You must click a message link, scan a QR code or move away from the original platform.
- ✓ The IBAN, beneficiary, URL or telephone number changes without a convincing explanation.
- ✓ You are asked for a PIN, security code, DigiD details, full card data or approval of an unfamiliar login.
- ✓ You must raise a limit, use a “safe account”, share your screen, install remote-access software, or hand over a card, cash or jewellery.
Zero signs does not prove that a request is safe; verify it independently. With one or two signs, pause and do not pay or click. Three or more signs means the approach is highly suspicious. Any request involving a PIN, security code, safe account, remote access or card collection is a hard stop.
2. The first fifteen minutes
- ✓ Stop the interaction: do not click again, scan another code, raise a limit, approve a login or make a second payment.
- ✓ Contact your bank independently: use the official app, the number on your card or an address you type yourself.
- ✓ Preserve evidence: capture the full chat, number, URL, payment page, transaction and time.
- ✓ Secure cards and accounts: follow the bank’s instructions and ask whether access or devices need blocking.
- ✓ Use a trusted device: do not manage banking and passwords on a device that may still be remotely controlled.
Call 112 only when there is immediate danger or a crime is in progress. For non-emergency police guidance, use 0900-8844 or the reporting route that matches the fraud type.
3. If money has already been sent
Do not wait for a promise that the money will return tomorrow, and never pay another fee, tax, deposit or release charge to recover the first amount. Call your own bank immediately. Give the amount, time, beneficiary IBAN, transaction reference, payment method and a short description, and clearly say that this is suspected fraud.
Ask whether cards, online banking, the account or registered devices must be blocked, and whether the bank can attempt a recall, interception or contact with the receiving bank. Recovery or compensation depends on the payment method, whether the funds have moved, whether the transaction was authorised, the bank’s rules and the evidence. Prompt reporting helps, but does not guarantee reimbursement.
4. Fake bank calls and spoofing
Caller ID can be spoofed, so a familiar displayed number is not proof that the call is genuine. A bank will not ask you to move money to a “safe account”, disclose a PIN, password or security code, give a card to a courier, or install AnyDesk, TeamViewer or similar software.
End the call. After a short pause, find the number in the official bank app, on your bank card or on a website you typed yourself, and call back. Do not accept a transfer to a supposed security department, and do not treat knowledge of some personal details as proof.
5. After a phishing link, text message or QR code
Opening an ordinary webpage without submitting data, downloading a file or approving a login is different from entering credentials. Close the page and remain alert. If bank data was entered, contact the bank. If DigiD data was entered, type the official DigiD address yourself, change the password and review Gebruiksgeschiedenis in Mijn DigiD.
Official DigiD emails, text messages and letters do not contain login links or QR codes, and DigiD staff will not ask for login credentials. If you find an unfamiliar DigiD login, contact the DigiD helpdesk and the public organisation that was accessed. Deactivate the DigiD app on a stolen phone.
If you installed an app, opened a dangerous attachment, shared your screen or allowed remote access, stop the connection and have the device checked. Use another trusted device to secure the primary email account first, followed by banking, DigiD, Apple or Google accounts and the password manager. Check forwarding rules, recovery details and signed-in devices.
6. WhatsApp “new number” fraud
Help-request fraud often begins with “this is my new number”, “my phone is broken” or “this invoice must be paid today”. A profile photo, familiar wording or short voice clip is not sufficient proof. Call the person using the old number saved in your contacts, or verify the request through another relative.
If you paid, contact the bank, report the case to Fraudehelpdesk and follow police reporting guidance. Save the complete chat and screenshots before reporting or blocking the WhatsApp number, because the conversation may no longer be visible afterwards.
7. Marktplaats, resale platforms and fake shops
A scammer may move the conversation off-platform and send a fake link to “verify your receiving account”, arrange delivery, pay one cent or release a payment. A seller does not need to enter online-banking credentials on a buyer’s webpage to receive money. Treat a very low price, same-day pressure, bank-transfer-only demand, missing company information or refusal to use platform protections as warning signs.
Keep the advertisement, product photos, order confirmation, chat, email address, phone number, username, IBAN, payment receipt and full URL. Dutch Police provides online reporting routes for purchases not received, sellers not paid and counterfeit goods.
8. DigiD or identity documents may be compromised
Review unfamiliar organisations, dates and times in DigiD usage history. Contact DigiD and the organisation that was accessed, because a criminal may have changed a benefit application, bank account or personal detail. If the phone containing the DigiD app was stolen, deactivate the app on that device.
If a passport, identity card, driving licence or BSN copy reached a suspicious person, record who received it, when and for what stated purpose. Contact the Centraal Meldpunt Identiteitsfraude (CMI) for suspected identity misuse and report actual fraud to police. For future copies, the government’s KopieID app can hide unnecessary details and add a recipient, purpose and date watermark.
9. Build an evidence package first
- ✓ Complete chats, emails and messages, including sender and time
- ✓ Telephone and WhatsApp numbers, usernames and social profiles
- ✓ The full fake URL, QR-code source and payment page
- ✓ Beneficiary IBAN, displayed name, amount, time and transaction reference
- ✓ Advertisement, product images, order, invoice and delivery details
- ✓ Case numbers from the bank, platform, DigiD and police
- ✓ A short chronological account of what happened
Keep originals where possible. A tightly cropped screenshot may remove the account, number or time. Save evidence before reporting a profile, deleting an app, resetting a phone or closing an account.
10. Which organisation handles what?
- ✓ Your bank: cards, account access, banking credentials, suspicious transactions and transfers.
- ✓ Dutch Police: criminal reports and investigation; 112 is for immediate danger only.
- ✓ Fraudehelpdesk: fraud-type guidance, reports and next-step advice.
- ✓ DigiD and the affected public organisation: leaked DigiD credentials, unfamiliar login or changed public records.
- ✓ CMI: identity theft, identity misuse and certain registration problems.
- ✓ The trading or service platform: fake profiles and advertisements, after evidence is preserved.
11. Common misunderstandings and prevention
“The displayed number belonged to the bank, so the call was genuine.”
Caller ID can be spoofed. End the call and dial the official number yourself.
“The bank opened a case, so I will definitely be refunded.”
Recovery and compensation depend on the facts and the bank’s assessment.
“The amount was small, so reporting is pointless.”
Multiple reports may reveal repeated use of the same account, email address or profile.
“I should report WhatsApp first and collect evidence later.”
The chat may disappear after reporting; preserve it first.
After urgent containment, enable strong two-step login for banking and DigiD, set sensible limits and transaction alerts, use different passwords for important accounts and agree a separate emergency-payment code word with family members. Being deceived does not mean that you were foolish. Fraud is designed around fear, trust, language barriers and time pressure.
12. Hokimi field note
Remember the order: stop → contact the bank → secure accounts and devices → preserve evidence → report through the correct route. This content was reviewed on 27 July 2026. It provides general information and is not legal, financial, banking or cybersecurity advice. Follow the latest instructions from your bank, Dutch Police, Fraudehelpdesk, DigiD, CMI and the relevant platform.
Why it may be useful
Hokimi prioritises updates, deals and local tips with practical value for people living in the Netherlands.
For users who want less searching and clearer information in English, Dutch or Chinese. Essentials.








No comments yet — be the first!