Stay safe

    Only press play when you know what's playing

    Small offices are popular with fraudsters: there is money, there is data and there is no IT department keeping watch. Here you learn, a few minutes per topic, how to stay one step ahead. With real stories, a few games and no jargon.

    Pick a topic

    Every topic with a game or a real story

    Spot the phish

    Fake e-mails, calendar invitations, calls from 'the bank' and video calls with your 'director'. Practise with the big round.

    Home office and Wi-Fi

    Your work, the kids' tablet and the smart TV on one Wi-Fi? How to separate them, and a game of "Who goes where?".

    Backups

    The day without a backup, in pictograms. Then survive a week full of disasters with the backup of your choice.

    Bookkeeping and tax

    Fake messages from 'the tax office', invoices with a new account number and keeping your bookkeeping software safe.

    True stories

    A fake IT colleague, a backup in the same building as the fire. Real stories in brief, with what they cost.

    Hacked? First aid

    What to do in the first hour if it goes wrong after all, step by step. Bookmark this page, just in case.

    On one page

    Ten rules that prevent most of the trouble

    • Unsure about a message? Call the sender on a number you look up yourself.
    • Turn on two-step verification for your e-mail, your bank and your bookkeeping.
    • Use a password manager: a different, long password everywhere.
    • Let updates install by themselves, on your phone and your router too.
    • Make backups the 3-2-1 way, with one copy that isn't plugged in. And test the restore.
    • Give guests and smart devices their own Wi-Fi network.
    • Never change a bank account number on the strength of an e-mail alone.
    • Never give anyone your login codes, not even 'the bank' or 'the helpdesk' on the phone.
    • Never install anything because someone on the phone asks you to.
    • Know who to turn to when it goes wrong. Our contact form is always open.

    It really happened

    They thought so too: that won't happen to us

    Real cases, summarised in our own words. Click for what happened, what it cost and the link to the full story.

    • 2026

      A fake IT colleague calls customer service

      Customer service staff at a large Dutch telecoms provider, and millions of customers

      Cost: Data from 6.2 million customer accounts, including IBANs and ID document numbers. The company refused to pay a ransom and the data was published.

      What happened

    • 2017

      The backup was on the same server

      A small Dutch bookkeeping office

      Cost: Three bitcoin in ransom (2,890.83 euros), one week without any work and another with hardly any. The total claim was over 42,000 euros; the court split the blame.

      What happened

    • 2022

      A media server on a home PC opened the company vault

      A senior engineer at a company that makes a password manager

      Cost: A backup of all customer vault data was copied. The UK privacy regulator imposed a fine of 1.2 million pounds.

      What happened

    • 2019

      'Our new payment route', from a hacked mailbox

      The accounts payable team of a large Dutch online shop, and a regular supplier

      Cost: 751,493 euros went to the fraudsters. The court ruled that the shop had to pay the supplier again.

      What happened

    • 2024

      The finance director on the video call was fake

      A finance employee at the Hong Kong office of an international engineering firm

      Cost: Some 200 million Hong Kong dollars, about 25.6 million US dollars.

      What happened

    • 2023

      158 years old, and gone after one attack

      A British family-run haulage firm with around 400 lorries

      Cost: Without financial records the bank wouldn't lend. The firm went into administration in September 2023 and around 700 people lost their jobs.

      What happened

    Press play

    Rather have someone take a look?

    Together we go through your devices, accounts, Wi-Fi and backups and make a short list of what needs doing now and what can wait.

    Real story - 2026

    A fake IT colleague calls customer service

    Customer service staff at a large Dutch telecoms provider, and millions of customers

    What happened
    In early February 2026 a man speaking good Dutch phoned customer service. He posed as a colleague from the IT department: a problem needed fixing, and for that the employee had to log in to an internal system. On a fake login page the employee entered a username, a password and a verification code. The data of millions of customers was then downloaded in a short time. Later, fraudsters called customers about 'compensation' for the breach and asked them for a text code.
    Why it worked
    A colleague from IT, a problem that needs fixing now, and English IT jargon sprinkled through the Dutch. The extra security step was bypassed because the employee handed over the code. According to NOS, access was also set up too broadly and no alarm went off during the large download. The company only learned of the theft when the criminals got in touch themselves.
    What it cost
    Data from 6.2 million customer accounts, including IBANs and ID document numbers. The company refused to pay a ransom and the data was published.
    What would have stopped it
    Real IT never asks you to log in through a link they give you on the phone, and never asks for your code. Hang up and call the service desk back on the internal number. As a customer: your provider doesn't call about compensation, and you never pass on a text code.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2017

    The backup was on the same server

    A small Dutch bookkeeping office

    What happened
    On 12 February 2017 hackers got into the network and encrypted every file on the server, including the backup files. They got in through a remote-working connection that was open to the internet, combined with a weak password. The office paid the ransom and got its files back. A court case with the IT supplier followed.
    Why it worked
    The only backup lived on the same machine as the data, so the ransomware simply took it too. A second disk to take home now and then had been suggested back in 2010. And at the office's request, the passwords had been made simpler.
    What it cost
    Three bitcoin in ransom (2,890.83 euros), one week without any work and another with hardly any. The total claim was over 42,000 euros; the court split the blame.
    What would have stopped it
    A backup on the same machine isn't a backup. Use two disks in rotation, one of them always unplugged and off site. And never leave remote access open to the internet without two-step verification.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2022

    A media server on a home PC opened the company vault

    A senior engineer at a company that makes a password manager

    What happened
    The engineer's personal computer at home ran a media server for films and series, for private use. The security update for a known flaw had been available since May 2020 but was never installed. Through that flaw an attacker put a keylogger on the computer. It captured the master password when the engineer logged in to the company vault, which let the attacker copy a backup containing customer data.
    Why it worked
    A hobby server on the same PC as the work, about 75 versions behind. The personal and work vaults were linked with the same master password.
    What it cost
    A backup of all customer vault data was copied. The UK privacy regulator imposed a fine of 1.2 million pounds.
    What would have stopped it
    Work on a work device. Hobby servers, gaming PCs and smart devices belong on a separate network, not on the computer you work on. Update everything that can be reached from the internet, and keep work and personal passwords apart.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2019

    'Our new payment route', from a hacked mailbox

    The accounts payable team of a large Dutch online shop, and a regular supplier

    What happened
    In late November 2019 an e-mail arrived from the real address of an employee at a regular supplier: 'Attached you will find our new payment route as instructed by management.' The neat letter gave a Spanish bank account. Two polite reminders asked whether the records had been updated yet. The account number was changed and from then on the payments went to the fraudsters. In mid-January the supplier asked where its money was.
    Why it worked
    The e-mail really came from the supplier's mailbox, with the real logo. Rules in that hacked mailbox hid every reply in a hidden folder, so the supplier never saw the confirmation. The judge said the shop should have shown 'healthy suspicion': a Dutch company suddenly using a Spanish account, clumsy wording and a well-known trick.
    What it cost
    751,493 euros went to the fraudsters. The court ruled that the shop had to pay the supplier again.
    What would have stopped it
    Never change an account number because of an e-mail. Call a contact you already know on a number you already had. And protect your own mailbox with two-step verification; check it for rules you didn't create.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    The finance director on the video call was fake

    A finance employee at the Hong Kong office of an international engineering firm

    What happened
    It started with a message that seemed to come from the chief financial officer in the UK, about a secret transaction. At first the employee suspected phishing. Then came a video call with the CFO and other colleagues, who looked and sounded just like the people the employee knew. According to the police, everyone on that call was fake except the employee. Fifteen transfers followed. It only came out when the employee checked with head office.
    Why it worked
    Authority (the CFO), secrecy and a group of familiar faces removed the doubt. Faces and voices were faked using public videos of the real people. One employee could make fifteen payments without a call-back check or a second approval.
    What it cost
    Some 200 million Hong Kong dollars, about 25.6 million US dollars.
    What would have stopped it
    Never act on a payment instruction from a call or chat until you've called the requester back yourself, on a number you already had. A 'secret' deal that skips the normal route is a stop sign, even when the faces look right.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2023

    158 years old, and gone after one attack

    A British family-run haulage firm with around 400 lorries

    What happened
    In June 2023 a ransomware gang encrypted the files of the firm and two sister companies. They got in by guessing an employee's password, with software that makes thousands of attempts. The owners refused to pay. A new transport system was running within days, but the financial records didn't come back: the criminals had also destroyed the backup that was supposed to be stored safely elsewhere.
    Why it worked
    A guessable password on an account that could be reached from outside, and an 'off-site' backup the attackers could still get to. A month earlier the firm had taken out a cyber insurance policy worth 1 million pounds.
    What it cost
    Without financial records the bank wouldn't lend. The firm went into administration in September 2023 and around 700 people lost their jobs.
    What would have stopped it
    Insurance doesn't replace a backup criminals can't reach. Keep an offline copy of your books and invoicing, and put two-step verification on everything that can be reached from outside.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.