Bookkeeping and tax

    Your books are worth gold. To fraudsters too.

    Invoices, account numbers, your DigiD and your bookkeeping software: everything money flows through attracts fraudsters. No tax advice here, but the tricks we see most often and how to stay ahead of them.

    The tricks

    Three tricks that cost money

    'The tax office' wants something from you

    A refund, an unpaid assessment or your DigiD about to expire, with a link to sort it quickly. Don't click. Log in yourself via the site you type in, or call a number you look up yourself.

    The invoice with a new account number

    "Please note, our bank account has changed." Often from your supplier's real e-mail address, which has been taken over. Always call back on a known number before you change anything.

    The director who wants to pay 'quickly'

    Secret, urgent, 'I'm in a meeting'. Sometimes even with a faked voice or video. Agree on a fixed check for every unusual payment.

    Your bookkeeping software

    How to keep your books safe

    • Updates installed right away, and software downloaded only from the maker itself.
    • Logging in with a strong password of its own and two-step verification.
    • Access only for those who really need it. Anyone who leaves loses their account the same day.
    • Backups of your books, separate from your computer and restorable. You have to be able to show your records for years.
    • Know where it lives: locally, on your own server or in the cloud, and who else can get to it.
    • Payments with four eyes: the person who changes an account number isn't the one who pays.

    How long you must keep your records is explained by the Belastingdienst (in Dutch). We make sure your backup lasts just as long.

    It really happened

    Money gone, books gone

    Real cases in brief, with the link to the full story.

    • 2017

      The backup was on the same server

      A small Dutch bookkeeping office

      Cost: Three bitcoin in ransom (2,890.83 euros), one week without any work and another with hardly any. The total claim was over 42,000 euros; the court split the blame.

      What happened

    • 2019

      'Our new payment route', from a hacked mailbox

      The accounts payable team of a large Dutch online shop, and a regular supplier

      Cost: 751,493 euros went to the fraudsters. The court ruled that the shop had to pay the supplier again.

      What happened

    • 2024

      The finance director on the video call was fake

      A finance employee at the Hong Kong office of an international engineering firm

      Cost: Some 200 million Hong Kong dollars, about 25.6 million US dollars.

      What happened

    • 2018

      A secret takeover in Dubai, paid in six instalments

      The managing director and finance director of a Dutch cinema chain

      Cost: More than 19.2 million euros. Both directors lost their jobs.

      What happened

    • 2020

      130,000 text messages in a few days

      Tens of thousands of recipients in the Netherlands

      Cost: According to the Dutch Public Prosecution Service, 60,000 victims of attempted fraud. The man was sentenced to 4.5 years in prison.

      What happened

    • 2018

      A fake MijnOverheid e-mail, and the text code with it

      203 Dutch DigiD users

      Cost: 203 DigiD accounts were deleted and personal data was probably collected. In the second wave, according to DutchNews, 361 people fell for it.

      What happened

    From us

    Kantoor: your books on your own computer

    We built Kantoor, bookkeeping software for freelancers that runs on your own PC or server. You decide where your figures live and how they are backed up.

    Questions

    Questions about money and data

    How do I know a message really comes from the tax office?

    Don't click the link in the message. Log in yourself via Mijn Belastingdienst, or call the tax office on a number you look up yourself. The Belastingdienst explains how to recognise fake messages (in Dutch); forward a fake e-mail to [email protected].

    My supplier e-mails a new account number. Now what?

    Call the supplier on the number you already had, not the one in the e-mail. Only change it once they confirm.

    Do you give tax advice?

    No, for that you go to your accountant or the tax office. We make sure your books are safe and recoverable.

    Press play

    Payments and books under lock

    Together we go through your accounts, your bookkeeping software and your backups, and agree on a fixed check for payments.

    Real story - 2017

    The backup was on the same server

    A small Dutch bookkeeping office

    What happened
    On 12 February 2017 hackers got into the network and encrypted every file on the server, including the backup files. They got in through a remote-working connection that was open to the internet, combined with a weak password. The office paid the ransom and got its files back. A court case with the IT supplier followed.
    Why it worked
    The only backup lived on the same machine as the data, so the ransomware simply took it too. A second disk to take home now and then had been suggested back in 2010. And at the office's request, the passwords had been made simpler.
    What it cost
    Three bitcoin in ransom (2,890.83 euros), one week without any work and another with hardly any. The total claim was over 42,000 euros; the court split the blame.
    What would have stopped it
    A backup on the same machine isn't a backup. Use two disks in rotation, one of them always unplugged and off site. And never leave remote access open to the internet without two-step verification.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2019

    'Our new payment route', from a hacked mailbox

    The accounts payable team of a large Dutch online shop, and a regular supplier

    What happened
    In late November 2019 an e-mail arrived from the real address of an employee at a regular supplier: 'Attached you will find our new payment route as instructed by management.' The neat letter gave a Spanish bank account. Two polite reminders asked whether the records had been updated yet. The account number was changed and from then on the payments went to the fraudsters. In mid-January the supplier asked where its money was.
    Why it worked
    The e-mail really came from the supplier's mailbox, with the real logo. Rules in that hacked mailbox hid every reply in a hidden folder, so the supplier never saw the confirmation. The judge said the shop should have shown 'healthy suspicion': a Dutch company suddenly using a Spanish account, clumsy wording and a well-known trick.
    What it cost
    751,493 euros went to the fraudsters. The court ruled that the shop had to pay the supplier again.
    What would have stopped it
    Never change an account number because of an e-mail. Call a contact you already know on a number you already had. And protect your own mailbox with two-step verification; check it for rules you didn't create.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    The finance director on the video call was fake

    A finance employee at the Hong Kong office of an international engineering firm

    What happened
    It started with a message that seemed to come from the chief financial officer in the UK, about a secret transaction. At first the employee suspected phishing. Then came a video call with the CFO and other colleagues, who looked and sounded just like the people the employee knew. According to the police, everyone on that call was fake except the employee. Fifteen transfers followed. It only came out when the employee checked with head office.
    Why it worked
    Authority (the CFO), secrecy and a group of familiar faces removed the doubt. Faces and voices were faked using public videos of the real people. One employee could make fifteen payments without a call-back check or a second approval.
    What it cost
    Some 200 million Hong Kong dollars, about 25.6 million US dollars.
    What would have stopped it
    Never act on a payment instruction from a call or chat until you've called the requester back yourself, on a number you already had. A 'secret' deal that skips the normal route is a stop sign, even when the faces look right.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2018

    A secret takeover in Dubai, paid in six instalments

    The managing director and finance director of a Dutch cinema chain

    What happened
    In March 2018 the Dutch managing director received e-mails that seemed to come from the head of the French parent company. They were about a strictly confidential takeover of a company in Dubai; an adviser from a big accountancy firm would be in touch. Contact was only allowed through 'my personal e-mail', never by phone, and not even colleagues could know. Six payments to Dubai followed within three weeks. It only came out when the French head office asked questions about the money.
    Why it worked
    Authority, urgency and above all secrecy that blocked every normal check: no phone calls, not a word to colleagues. There were doubts ('A strange process. Never seen anything like it'), but a phone call was brushed off and nobody rang the real chief executive on a known number.
    What it cost
    More than 19.2 million euros. Both directors lost their jobs.
    What would have stopped it
    Secrecy plus urgency plus a new account means: stop. Call the requester back on a number you already had, never one from the e-mail. No payment instruction may forbid you to involve a colleague.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2020

    130,000 text messages in a few days

    Tens of thousands of recipients in the Netherlands

    What happened
    In September 2020 a 22-year-old man sent almost 130,000 text messages in a few days, in the name of the Dutch tax office, PostNL, UPS and DigiD, among others. The links led to fake payment pages, where he also captured people's bank login details.
    Why it worked
    Familiar names and a payment link you quickly tap on your phone.
    What it cost
    According to the Dutch Public Prosecution Service, 60,000 victims of attempted fraud. The man was sentenced to 4.5 years in prison.
    What would have stopped it
    Never pay or log in via a link in a text. The Dutch tax office doesn't send direct payment requests. Open the app yourself or type the address in yourself.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2018

    A fake MijnOverheid e-mail, and the text code with it

    203 Dutch DigiD users

    What happened
    In June 2018 people received an e-mail with a link to a fake version of MijnOverheid, the Dutch government's message box. Anyone who logged in there with DigiD also handed over the text code. A script used those details straight away to log in for real and search MijnOverheid. A second wave followed in December: an official letter was supposedly waiting.
    Why it worked
    Trust in the government, and a fake site that passed the text code straight on. Real e-mails from MijnOverheid never contain a link.
    What it cost
    203 DigiD accounts were deleted and personal data was probably collected. In the second wave, according to DutchNews, 361 people fell for it.
    What would have stopped it
    Never log in via a link or QR code in a message that seems to come from DigiD, MijnOverheid or the tax office. Open the app yourself or type the address in yourself.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.