The Lab

    Phish or not?

    Fake e-mails and texts look more real all the time: the right logo, your own name and a reason to hurry. Here you practise without any risk. A mistake costs you nothing.

    Would you fall for it?

    Three messages a round, copied from real attacks. Choose whether you trust them and see where the trick is. Want more practice? The big round is in Spot the phish.

    E-mail 1 of 3

    From: Safe Bank <[email protected]>

    Your account will be blocked

    We noticed unusual activity. Confirm your details within 2 hours using the button below, or we will block your account.

    Show the answer

    Phishing. A bank doesn't ask you to confirm your details through a button in an e-mail. In doubt? Open your banking app yourself.

    How you can tell:

    • A threat: or we block your account.
    • Hurry: within 2 hours.
    • Confirming your details through a button in an e-mail.

    Real story: 'This is your bank's fraud department'

    E-mail 2 of 3

    From: IT helpdesk <[email protected]>

    Your mailbox is 99% full

    Soon you will no longer receive e-mail. Log in on this page now to request extra space for free.

    Show the answer

    Phishing. Your login page never comes from an e-mail. You get more space in your own mail app or through your own IT partner.

    How you can tell:

    • A vague 'helpdesk' you don't know.
    • Logging in through a link in the e-mail.
    • A threat: no more e-mail.

    Real story: A phishing e-mail in October, a university down at Christmas

    Text message 3 of 3

    You've just set up your banking app on your new phone.

    From: Your bank

    Your banking app has just been activated on a new device. Wasn't you? Call us on the number on the back of your bank card.

    Show the answer

    Real. A good notification sends you to a number you already have, not to a link.

    Why it checks out:

    • It confirms something you just did yourself.
    • No link: you call yourself, on a number you already have.

    Every round deals new messages from 30. All made up, but every phish copies the trick of a real attack.

    More in the Lab

    You can spot a fake message now. What about a fake voice?

    With AI a fraudster can sound like your grandson, your director or the prime minister. How it works, and how to protect yourself.

    Real story - 2020

    130,000 text messages in a few days

    Tens of thousands of recipients in the Netherlands

    What happened
    In September 2020 a 22-year-old man sent almost 130,000 text messages in a few days, in the name of the Dutch tax office, PostNL, UPS and DigiD, among others. The links led to fake payment pages, where he also captured people's bank login details.
    Why it worked
    Familiar names and a payment link you quickly tap on your phone.
    What it cost
    According to the Dutch Public Prosecution Service, 60,000 victims of attempted fraud. The man was sentenced to 4.5 years in prison.
    What would have stopped it
    Never pay or log in via a link in a text. The Dutch tax office doesn't send direct payment requests. Open the app yourself or type the address in yourself.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2018

    A secret takeover in Dubai, paid in six instalments

    The managing director and finance director of a Dutch cinema chain

    What happened
    In March 2018 the Dutch managing director received e-mails that seemed to come from the head of the French parent company. They were about a strictly confidential takeover of a company in Dubai; an adviser from a big accountancy firm would be in touch. Contact was only allowed through 'my personal e-mail', never by phone, and not even colleagues could know. Six payments to Dubai followed within three weeks. It only came out when the French head office asked questions about the money.
    Why it worked
    Authority, urgency and above all secrecy that blocked every normal check: no phone calls, not a word to colleagues. There were doubts ('A strange process. Never seen anything like it'), but a phone call was brushed off and nobody rang the real chief executive on a known number.
    What it cost
    More than 19.2 million euros. Both directors lost their jobs.
    What would have stopped it
    Secrecy plus urgency plus a new account means: stop. Call the requester back on a number you already had, never one from the e-mail. No payment instruction may forbid you to involve a colleague.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2025

    'This is your bank's fraud department'

    Thousands of Dutch bank customers

    What happened
    A 'bank employee' calls, sometimes with the bank's real number on screen. Something odd is happening on your account and your money has to go to a 'safe account' for now. Or your card is no longer safe and a courier will collect it. Sometimes you're asked to install a program such as AnyDesk so they can 'help'. The callers often already know your name, your account number and sometimes even your latest payments.
    Why it worked
    Fear, urgency and authority, made believable with data from earlier phishing or leaks and a spoofed phone number. Sometimes it starts with a phishing e-mail, after which 'the bank' calls about a threat to your account.
    What it cost
    In the Netherlands in 2025, 25.8 million euros from just under 5,900 victims. Just over 45 per cent was reimbursed as a goodwill gesture.
    What would have stopped it
    Your bank never asks you to move money to a 'safe account', never collects your card and never asks for remote access. Hang up and call the number on the back of your card yourself.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    'Hi mum, this is my new number'

    Dutch people, often parents, who get a message from 'someone they know'

    What happened
    A message from an unknown number: 'mum my phone is broken, this is my new number'. The old number can be deleted. Then comes a problem that needs solving fast, and it takes money. The profile photo comes from social media, and calling is 'not possible right now'. Sometimes fraudsters even use a cloned voice.
    Why it worked
    Emotion (your child in trouble), urgency and a story that explains the unknown number straight away.
    What it cost
    Of the Dutch people who fell victim to phishing in 2024, 9 per cent were victims of this friend-in-need fraud. No total amount is known.
    What would have stopped it
    Never pay after a message: first call the old number in your own contacts. Agree on a family code word for payment requests.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2018

    A fake MijnOverheid e-mail, and the text code with it

    203 Dutch DigiD users

    What happened
    In June 2018 people received an e-mail with a link to a fake version of MijnOverheid, the Dutch government's message box. Anyone who logged in there with DigiD also handed over the text code. A script used those details straight away to log in for real and search MijnOverheid. A second wave followed in December: an official letter was supposedly waiting.
    Why it worked
    Trust in the government, and a fake site that passed the text code straight on. Real e-mails from MijnOverheid never contain a link.
    What it cost
    203 DigiD accounts were deleted and personal data was probably collected. In the second wave, according to DutchNews, 361 people fell for it.
    What would have stopped it
    Never log in via a link or QR code in a message that seems to come from DigiD, MijnOverheid or the tax office. Open the app yourself or type the address in yourself.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2019

    A phishing e-mail in October, a university down at Christmas

    A Dutch university

    What happened
    In mid-October 2019 phishing e-mails were opened on two workstations. Several variants had been sent, and a report about one variant wasn't properly followed up. The attackers moved through the network for more than two months. On 23 December they encrypted 267 Windows servers, including e-mail servers, file servers and a number of backup servers.
    Why it worked
    About 20 per cent of users open phishing e-mails, the university wrote itself. An administrator account was also used for routine maintenance, a server was missing updates and the network was fairly open. The online backups could be encrypted too.
    What it cost
    A ransom of 30 bitcoin, almost 200,000 euros at the time. Dozens of staff worked through the Christmas holidays.
    What would have stopped it
    Report every phishing e-mail and make sure every report gets followed up: one missed variant was enough. Keep backups offline and admin accounts separate.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    Fake invitations that turned up in your calendar by themselves

    Staff at around 300 organisations (not named)

    What happened
    Criminals sent e-mails that looked like a Google Calendar invitation from someone the victim knew. The invitation held a link to a Google Form or Google Drawing, containing yet another button disguised as a reCAPTCHA or support button. That led to a fake page where people entered personal details and eventually payment details.
    Why it worked
    Trust in Google and in ordinary calendar notifications, and a sender who seemed familiar. When security tools started flagging the invitations, the criminals switched from forms to drawings.
    What it cost
    More than 4,000 of these e-mails in four weeks, at around 300 organisations. Criminals can use the details for credit card fraud; no damage figure has been published.
    What would have stopped it
    Don't click links in an unexpected invitation, even if it's already in your calendar. Open documents only where they belong. In Google Calendar you can make only invitations from known senders appear automatically.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    First hundreds of spam e-mails, then 'the helpdesk' calls

    Staff at various organisations (not named)

    What happened
    The attackers signed their target's e-mail address up to a whole series of newsletters, so the mailbox overflowed. Then they called, or sent a Teams message under names such as 'Help Desk' or 'IT Support', offering to sort out the spam. The victim was asked to open Quick Assist and type in a code the 'helpdesk' gave them. That handed the attackers the computer.
    Why it worked
    The attacker creates the problem first, then offers the fix at exactly the right moment. Quick Assist is a genuine Windows tool, and the Teams names look internal.
    What it cost
    Microsoft gives no amount. Once in, the attackers installed more tools and in several cases spread ransomware across the whole network.
    What would have stopped it
    Only let someone into your computer if you contacted your own IT partner yourself. A sudden spam flood followed by a helpful call is a warning sign in itself.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2022

    Prompt after prompt, until someone pressed Approve

    A contractor working for a large US ride-hailing company

    What happened
    The attacker had probably bought the contractor's password on the dark web, after a personal device of the contractor's was infected with malware. The attacker then tried to log in again and again. Each time, the contractor got a request to approve the sign-in, until eventually one was approved. According to the attacker, a WhatsApp message from 'IT' also arrived: approve one and they'll stop.
    Why it worked
    Fatigue and annoyance, plus a fake explanation from 'IT'. A simple Approve or Deny button, with no number to match.
    What it cost
    No amount published. But the attacker got into tools including Slack, G Suite and an internal invoice system, and posted a message in a company-wide Slack channel.
    What would have stopped it
    Never approve a sign-in request you didn't start. A string of requests means someone has your password: report it at once and change it. IT never asks you to approve anything.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    The finance director on the video call was fake

    A finance employee at the Hong Kong office of an international engineering firm

    What happened
    It started with a message that seemed to come from the chief financial officer in the UK, about a secret transaction. At first the employee suspected phishing. Then came a video call with the CFO and other colleagues, who looked and sounded just like the people the employee knew. According to the police, everyone on that call was fake except the employee. Fifteen transfers followed. It only came out when the employee checked with head office.
    Why it worked
    Authority (the CFO), secrecy and a group of familiar faces removed the doubt. Faces and voices were faked using public videos of the real people. One employee could make fifteen payments without a call-back check or a second approval.
    What it cost
    Some 200 million Hong Kong dollars, about 25.6 million US dollars.
    What would have stopped it
    Never act on a payment instruction from a call or chat until you've called the requester back yourself, on a number you already had. A 'secret' deal that skips the normal route is a stop sign, even when the faces look right.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2019

    'Our new payment route', from a hacked mailbox

    The accounts payable team of a large Dutch online shop, and a regular supplier

    What happened
    In late November 2019 an e-mail arrived from the real address of an employee at a regular supplier: 'Attached you will find our new payment route as instructed by management.' The neat letter gave a Spanish bank account. Two polite reminders asked whether the records had been updated yet. The account number was changed and from then on the payments went to the fraudsters. In mid-January the supplier asked where its money was.
    Why it worked
    The e-mail really came from the supplier's mailbox, with the real logo. Rules in that hacked mailbox hid every reply in a hidden folder, so the supplier never saw the confirmation. The judge said the shop should have shown 'healthy suspicion': a Dutch company suddenly using a Spanish account, clumsy wording and a well-known trick.
    What it cost
    751,493 euros went to the fraudsters. The court ruled that the shop had to pay the supplier again.
    What would have stopped it
    Never change an account number because of an e-mail. Call a contact you already know on a number you already had. And protect your own mailbox with two-step verification; check it for rules you didn't create.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    Fake QR stickers on parking meters

    Drivers in Dutch and Belgian cities

    What happened
    Neat stickers saying 'Scan to pay' appeared on parking meters, over or next to the real information. Anyone who scanned ended up on a site that looked like a parking app and asked for bank details. Councils removed the stickers and issued warnings. In Brussels the police arrested a man carrying 160 of these stickers.
    Why it worked
    A sticker looks official and convenient, and a QR code hides where it leads.
    What it cost
    No total known. Anyone who paid handed card or bank details to fraudsters.
    What would have stopped it
    Pay for parking at the machine itself or through the app you already have. Check the address in your browser after every scan.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2026

    A fake IT colleague calls customer service

    Customer service staff at a large Dutch telecoms provider, and millions of customers

    What happened
    In early February 2026 a man speaking good Dutch phoned customer service. He posed as a colleague from the IT department: a problem needed fixing, and for that the employee had to log in to an internal system. On a fake login page the employee entered a username, a password and a verification code. The data of millions of customers was then downloaded in a short time. Later, fraudsters called customers about 'compensation' for the breach and asked them for a text code.
    Why it worked
    A colleague from IT, a problem that needs fixing now, and English IT jargon sprinkled through the Dutch. The extra security step was bypassed because the employee handed over the code. According to NOS, access was also set up too broadly and no alarm went off during the large download. The company only learned of the theft when the criminals got in touch themselves.
    What it cost
    Data from 6.2 million customer accounts, including IBANs and ID document numbers. The company refused to pay a ransom and the data was published.
    What would have stopped it
    Real IT never asks you to log in through a link they give you on the phone, and never asks for your code. Hang up and call the service desk back on the internal number. As a customer: your provider doesn't call about compensation, and you never pass on a text code.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2025

    'Your SIM card is expiring', and your number belongs to someone else

    Customers of two large Dutch providers

    What happened
    In 2025 customers got texts and calls in the name of their provider: the SIM card was about to expire, had to be 'validated' or, 'due to new legislation', switched to an eSIM. Via a link they entered their details, sometimes even their citizen service number (BSN). Some were also asked to forward a genuine e-mail from the provider or to delete the provider's app. After that, criminals had the SIM card.
    Why it worked
    A technical-sounding problem, 'new legislation' as the reason, and small steps that each seem harmless on their own.
    What it cost
    No numbers or amounts known. With the hijacked SIM cards, the criminals sent fake texts in bulk to new victims, from the victim's own number.
    What would have stopped it
    Your provider never gets in touch because your SIM card is expiring or needs validating. Delete the message or hang up. Lost control of your SIM card? Call your provider at once.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    A Teams invitation with a code, on the real Microsoft site

    Staff at governments, NGOs, IT firms and other organisations in Europe and beyond

    What happened
    The attackers first made contact via WhatsApp, Signal or Teams, posing as someone who mattered to the target. After some friendly contact came an invitation to a Teams meeting. To join, the target had to enter a code on a Microsoft sign-in page. The attacker had generated that code, and that gave the attacker access to the account.
    Why it worked
    Build trust first, then use a sign-in page that really is Microsoft's: there's no fake address to spot. The victim does the two-step verification themselves, on the attacker's behalf.
    What it cost
    No amount published. The attackers searched mailboxes for words such as 'password' and 'admin', took e-mails and sent new phishing to colleagues from the hijacked account.
    What would have stopped it
    Never enter a code on a sign-in page because a chat or invitation asks you to. Organisations: switch off this way of signing in (device code) wherever nobody needs it.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2023

    The hotel's account hijacked, the guests scammed

    Hotels that take bookings through a large booking platform, and their guests

    What happened
    A hotel received an e-mail from a 'former guest' who had supposedly left a passport behind, with a link to photos of it. The link delivered malware that stole the hotel's login for the booking platform. With it the fraudsters read the real reservations and messaged guests: their payment or booking just needed 'verifying', via a link.
    Why it worked
    Hotel staff want to help guests, and the guests got messages with their real booking dates, sometimes even through the real platform.
    What it cost
    In Singapore at least 30 guests lost 41,000 dollars between them. Dutch travellers lost money and card details too.
    What would have stopped it
    Guests: never re-enter your card details via a link in a message; check in the app or call the hotel. Hotels: don't open 'passport photos' from strangers, and turn on two-step verification for your platform account.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2019

    'Scan this QR code to receive your money'

    People selling things on an online marketplace

    What happened
    The seller gets a WhatsApp message from a 'buyer', who says they're paying from a business account and sends a QR code to scan with the banking app to 'accept' the money. In reality the seller was linking a second device to their own bank account: the fraudster's.
    Why it worked
    A QR code doesn't show where it leads, and it was a genuine feature of the victim's own banking app. That made it feel safe.
    What it cost
    Several hundred reports; in some cases fraudsters got away with thousands of euros. The bank refused at first, but later reimbursed all the damage after all.
    What would have stopped it
    You never scan a QR code to receive money. Someone sending you money only needs your account number.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2023

    A call to the helpdesk: 'I can't log in'

    The IT helpdesk of a large US casino and hotel group, and that of a cleaning-products maker

    What happened
    According to the attackers themselves, they looked up an employee on LinkedIn and called the helpdesk as that person to get into the account. At the second company, attackers called the outsourced service desk and asked for new passwords. According to that company's lawsuit, the service desk handed them over without the usual checks: 'Oh, ok. Ok. So let me provide the password to you ok?'
    Why it worked
    A helpdesk wants to help quickly, and the check on who was calling relied on facts an attacker can look up. Or it didn't happen at all.
    What it cost
    The casino group reported a negative impact of about 100 million dollars on its results. The manufacturer is claiming 380 million dollars in damages in its lawsuit.
    What would have stopped it
    Never reset a password or two-step verification on the strength of a phone call alone: call back on a number you already had, or check with the manager. Got a reset message you didn't ask for? Report it at once.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.