True stories

    It happened to them too. Read how, and what it cost.

    From a fake IT colleague to a backup in the same building as the fire. Every story really happened, summarised in our own words, with the link to the original source. We don't name names: it's about the lesson, not about who had the bad luck.

    Phishing and fraud

    One click, one call, one payment

    Fake e-mails, fake colleagues, a fake bank on the phone and even a fake director on a video call.

    • 2026

      A fake IT colleague calls customer service

      Customer service staff at a large Dutch telecoms provider, and millions of customers

      Cost: Data from 6.2 million customer accounts, including IBANs and ID document numbers. The company refused to pay a ransom and the data was published.

      What happened

    • 2024

      The finance director on the video call was fake

      A finance employee at the Hong Kong office of an international engineering firm

      Cost: Some 200 million Hong Kong dollars, about 25.6 million US dollars.

      What happened

    • 2025

      'This is your bank's fraud department'

      Thousands of Dutch bank customers

      Cost: In the Netherlands in 2025, 25.8 million euros from just under 5,900 victims. Just over 45 per cent was reimbursed as a goodwill gesture.

      What happened

    • 2019

      A phishing e-mail in October, a university down at Christmas

      A Dutch university

      Cost: A ransom of 30 bitcoin, almost 200,000 euros at the time. Dozens of staff worked through the Christmas holidays.

      What happened

    • 2024

      'Hi mum, this is my new number'

      Dutch people, often parents, who get a message from 'someone they know'

      Cost: Of the Dutch people who fell victim to phishing in 2024, 9 per cent were victims of this friend-in-need fraud. No total amount is known.

      What happened

    • 2022

      Prompt after prompt, until someone pressed Approve

      A contractor working for a large US ride-hailing company

      Cost: No amount published. But the attacker got into tools including Slack, G Suite and an internal invoice system, and posted a message in a company-wide Slack channel.

      What happened

    • 2024

      First hundreds of spam e-mails, then 'the helpdesk' calls

      Staff at various organisations (not named)

      Cost: Microsoft gives no amount. Once in, the attackers installed more tools and in several cases spread ransomware across the whole network.

      What happened

    • 2024

      A Teams invitation with a code, on the real Microsoft site

      Staff at governments, NGOs, IT firms and other organisations in Europe and beyond

      Cost: No amount published. The attackers searched mailboxes for words such as 'password' and 'admin', took e-mails and sent new phishing to colleagues from the hijacked account.

      What happened

    • 2024

      Fake invitations that turned up in your calendar by themselves

      Staff at around 300 organisations (not named)

      Cost: More than 4,000 of these e-mails in four weeks, at around 300 organisations. Criminals can use the details for credit card fraud; no damage figure has been published.

      What happened

    • 2023

      The hotel's account hijacked, the guests scammed

      Hotels that take bookings through a large booking platform, and their guests

      Cost: In Singapore at least 30 guests lost 41,000 dollars between them. Dutch travellers lost money and card details too.

      What happened

    • 2023

      A call to the helpdesk: 'I can't log in'

      The IT helpdesk of a large US casino and hotel group, and that of a cleaning-products maker

      Cost: The casino group reported a negative impact of about 100 million dollars on its results. The manufacturer is claiming 380 million dollars in damages in its lawsuit.

      What happened

    • 2020

      130,000 text messages in a few days

      Tens of thousands of recipients in the Netherlands

      Cost: According to the Dutch Public Prosecution Service, 60,000 victims of attempted fraud. The man was sentenced to 4.5 years in prison.

      What happened

    • 2018

      A fake MijnOverheid e-mail, and the text code with it

      203 Dutch DigiD users

      Cost: 203 DigiD accounts were deleted and personal data was probably collected. In the second wave, according to DutchNews, 361 people fell for it.

      What happened

    • 2019

      'Scan this QR code to receive your money'

      People selling things on an online marketplace

      Cost: Several hundred reports; in some cases fraudsters got away with thousands of euros. The bank refused at first, but later reimbursed all the damage after all.

      What happened

    • 2024

      Fake QR stickers on parking meters

      Drivers in Dutch and Belgian cities

      Cost: No total known. Anyone who paid handed card or bank details to fraudsters.

      What happened

    • 2025

      'Your SIM card is expiring', and your number belongs to someone else

      Customers of two large Dutch providers

      Cost: No numbers or amounts known. With the hijacked SIM cards, the criminals sent fake texts in bulk to new victims, from the victim's own number.

      What happened

    • 2024

      'The police' come to collect your jewellery

      A 77-year-old woman in Eindhoven

      Cost: By the end of October 2025 the Dutch police had registered more than 10,000 incidents with fake police officers, against 520 in the whole of 2023. The criminals mainly target people aged 70 and over.

      What happened

    • 2023

      Her grandson's voice, cloned with AI

      Grandparents aged 73 and 75 in Canada, and the parents of a man in Canada

      Cost: The grandparents were warned in time by a bank manager. The other family lost 21,000 Canadian dollars. In research for the Dutch government (2024) only 4 per cent could tell for sure that the cloned voice of a well-known radio presenter was fake.

      What happened

    • 2025

      The prime minister recommends an investment. Except it wasn't him.

      Facebook users in the Netherlands

      Cost: Victims can lose thousands of euros in a short time. In 2025 investment fraud caused the highest damage to private persons of all types of fraud reported to the Dutch Fraud Helpdesk, 34.1 million euros.

      What happened

    Money and books

    Paid to the wrong people

    A new account number, a secret takeover and an update to bookkeeping software.

    • 2019

      'Our new payment route', from a hacked mailbox

      The accounts payable team of a large Dutch online shop, and a regular supplier

      Cost: 751,493 euros went to the fraudsters. The court ruled that the shop had to pay the supplier again.

      What happened

    • 2018

      A secret takeover in Dubai, paid in six instalments

      The managing director and finance director of a Dutch cinema chain

      Cost: More than 19.2 million euros. Both directors lost their jobs.

      What happened

    • 2017

      An update to tax software takes down firms worldwide

      Users of a Ukrainian tax and accounting program, and through them large companies around the world

      Cost: According to the White House, more than 10 billion dollars of damage in total. The shipping company alone lost 250 to 300 million dollars.

      What happened

    Backups and ransomware

    There was a backup. Or so they thought.

    On the same server, in the same building, with the same password. And twice a happy ending.

    • 2017

      The backup was on the same server

      A small Dutch bookkeeping office

      Cost: Three bitcoin in ransom (2,890.83 euros), one week without any work and another with hardly any. The total claim was over 42,000 euros; the court split the blame.

      What happened

    • 2023

      158 years old, and gone after one attack

      A British family-run haulage firm with around 400 lorries

      Cost: Without financial records the bank wouldn't lend. The firm went into administration in September 2023 and around 700 people lost their jobs.

      What happened

    • 2020

      Two disks in rotation, and the criminals got nothing

      A small Dutch office that handles clients' post and paperwork

      Cost: No ransom. The business was at a standstill for one day while everything was put right.

      What happened

    • 1998

      90 per cent of an animated film deleted, and the backup didn't work

      A major animation studio, in the middle of making a feature film

      Cost: A week of work on an unreliable restore was wasted, and 10 to 12 people worked non-stop for a whole weekend to check everything.

      What happened

    • 2017

      A database wiped, and the backups turned out empty

      An online platform for software developers

      Cost: Down for about 18 hours. More than six hours of changes were lost, affecting roughly 5,000 projects, 5,000 comments and 700 new user accounts.

      What happened

    • 2021

      Fire at the data centre, and the backup was in the same building

      Customers of a large European hosting provider, including small French companies

      Cost: 14,046 servers destroyed. Neither company could get its backup back. The software company was awarded 153,837 euros by the court at first instance.

      What happened

    • 2020

      'Welkom2020', and every backup deleted

      A Dutch municipality

      Cost: Total costs of around 4.2 million euros, and almost two years of recovery work.

      What happened

    • 2019

      The backup drives encrypted too: the practice closes

      A small US medical practice

      Cost: The practice closed for good on 17 December 2019. 5,835 patients were affected.

      What happened

    • 2021

      Ransom paid, and absolutely nothing happened

      A Dutch fashion shop with a web shop and around twenty staff

      Cost: About 500 euros of ransom for nothing, weeks of recovery work and 30 to 40 per cent of the data never recovered.

      What happened

    Home office and network

    It started at home

    A media server, a gaming laptop, a browser profile and routers secretly working for someone else.

    • 2022

      A media server on a home PC opened the company vault

      A senior engineer at a company that makes a password manager

      Cost: A backup of all customer vault data was copied. The UK privacy regulator imposed a fine of 1.2 million pounds.

      What happened

    • 2023

      A Minecraft mod that steals passwords

      Players of a popular game, often children, and everyone who uses the same computer

      Cost: According to Kaspersky, more than 132,000 young gamers were targeted in one year by malware disguised as games, mods and cheats. No damage figure is known.

      What happened

    • 2024

      One laptop for work, games and pirated downloads

      About 165 organisations that stored data on one cloud platform

      Cost: About 165 organisations were warned. One of the attackers later admitted stealing, among other things, the call records of more than 100 million customers of a telecoms company; the group received over 2.5 million dollars in ransom.

      What happened

    • 2023

      A work password in a personal browser profile

      An employee of a company that handles logins for other businesses

      Cost: Files belonging to 134 customers were accessed, and active sessions of 5 customers were hijacked.

      What happened

    • 2016

      Routers and cameras with the factory password

      Owners of home routers, cameras and video recorders, and over 900,000 customers of a German provider

      Cost: Attacks of more than 1 terabit per second, and over 900,000 households offline.

      What happened

    • 2024

      Old routers secretly working for someone else

      Owners of ordinary home and small-office routers, in the Netherlands too

      Cost: The NCSC spotted about 150 routers in the Netherlands believed to be compromised, part of around 13,000 compromised systems worldwide. The owners' connections were used for attacks on others.

      What happened

    How we work

    How we pick the stories

    • Only with a source: a court, the government, the police, a regulator, news media or the company that was hit.
    • No guesswork: amounts and numbers are taken exactly as the source gives them. If there's no amount, we say so.
    • No names: our summary is about what happened, not who it happened to.
    • Stays put: if a source disappears, our summary stays, with the date we checked it.

    Press play

    Rather not have your own story on this page?

    A security check costs you a morning. We look at your e-mail, your backups, your network and how you check payments.

    Real story - 2026

    A fake IT colleague calls customer service

    Customer service staff at a large Dutch telecoms provider, and millions of customers

    What happened
    In early February 2026 a man speaking good Dutch phoned customer service. He posed as a colleague from the IT department: a problem needed fixing, and for that the employee had to log in to an internal system. On a fake login page the employee entered a username, a password and a verification code. The data of millions of customers was then downloaded in a short time. Later, fraudsters called customers about 'compensation' for the breach and asked them for a text code.
    Why it worked
    A colleague from IT, a problem that needs fixing now, and English IT jargon sprinkled through the Dutch. The extra security step was bypassed because the employee handed over the code. According to NOS, access was also set up too broadly and no alarm went off during the large download. The company only learned of the theft when the criminals got in touch themselves.
    What it cost
    Data from 6.2 million customer accounts, including IBANs and ID document numbers. The company refused to pay a ransom and the data was published.
    What would have stopped it
    Real IT never asks you to log in through a link they give you on the phone, and never asks for your code. Hang up and call the service desk back on the internal number. As a customer: your provider doesn't call about compensation, and you never pass on a text code.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    The finance director on the video call was fake

    A finance employee at the Hong Kong office of an international engineering firm

    What happened
    It started with a message that seemed to come from the chief financial officer in the UK, about a secret transaction. At first the employee suspected phishing. Then came a video call with the CFO and other colleagues, who looked and sounded just like the people the employee knew. According to the police, everyone on that call was fake except the employee. Fifteen transfers followed. It only came out when the employee checked with head office.
    Why it worked
    Authority (the CFO), secrecy and a group of familiar faces removed the doubt. Faces and voices were faked using public videos of the real people. One employee could make fifteen payments without a call-back check or a second approval.
    What it cost
    Some 200 million Hong Kong dollars, about 25.6 million US dollars.
    What would have stopped it
    Never act on a payment instruction from a call or chat until you've called the requester back yourself, on a number you already had. A 'secret' deal that skips the normal route is a stop sign, even when the faces look right.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2025

    'This is your bank's fraud department'

    Thousands of Dutch bank customers

    What happened
    A 'bank employee' calls, sometimes with the bank's real number on screen. Something odd is happening on your account and your money has to go to a 'safe account' for now. Or your card is no longer safe and a courier will collect it. Sometimes you're asked to install a program such as AnyDesk so they can 'help'. The callers often already know your name, your account number and sometimes even your latest payments.
    Why it worked
    Fear, urgency and authority, made believable with data from earlier phishing or leaks and a spoofed phone number. Sometimes it starts with a phishing e-mail, after which 'the bank' calls about a threat to your account.
    What it cost
    In the Netherlands in 2025, 25.8 million euros from just under 5,900 victims. Just over 45 per cent was reimbursed as a goodwill gesture.
    What would have stopped it
    Your bank never asks you to move money to a 'safe account', never collects your card and never asks for remote access. Hang up and call the number on the back of your card yourself.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2019

    A phishing e-mail in October, a university down at Christmas

    A Dutch university

    What happened
    In mid-October 2019 phishing e-mails were opened on two workstations. Several variants had been sent, and a report about one variant wasn't properly followed up. The attackers moved through the network for more than two months. On 23 December they encrypted 267 Windows servers, including e-mail servers, file servers and a number of backup servers.
    Why it worked
    About 20 per cent of users open phishing e-mails, the university wrote itself. An administrator account was also used for routine maintenance, a server was missing updates and the network was fairly open. The online backups could be encrypted too.
    What it cost
    A ransom of 30 bitcoin, almost 200,000 euros at the time. Dozens of staff worked through the Christmas holidays.
    What would have stopped it
    Report every phishing e-mail and make sure every report gets followed up: one missed variant was enough. Keep backups offline and admin accounts separate.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    'Hi mum, this is my new number'

    Dutch people, often parents, who get a message from 'someone they know'

    What happened
    A message from an unknown number: 'mum my phone is broken, this is my new number'. The old number can be deleted. Then comes a problem that needs solving fast, and it takes money. The profile photo comes from social media, and calling is 'not possible right now'. Sometimes fraudsters even use a cloned voice.
    Why it worked
    Emotion (your child in trouble), urgency and a story that explains the unknown number straight away.
    What it cost
    Of the Dutch people who fell victim to phishing in 2024, 9 per cent were victims of this friend-in-need fraud. No total amount is known.
    What would have stopped it
    Never pay after a message: first call the old number in your own contacts. Agree on a family code word for payment requests.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2022

    Prompt after prompt, until someone pressed Approve

    A contractor working for a large US ride-hailing company

    What happened
    The attacker had probably bought the contractor's password on the dark web, after a personal device of the contractor's was infected with malware. The attacker then tried to log in again and again. Each time, the contractor got a request to approve the sign-in, until eventually one was approved. According to the attacker, a WhatsApp message from 'IT' also arrived: approve one and they'll stop.
    Why it worked
    Fatigue and annoyance, plus a fake explanation from 'IT'. A simple Approve or Deny button, with no number to match.
    What it cost
    No amount published. But the attacker got into tools including Slack, G Suite and an internal invoice system, and posted a message in a company-wide Slack channel.
    What would have stopped it
    Never approve a sign-in request you didn't start. A string of requests means someone has your password: report it at once and change it. IT never asks you to approve anything.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    First hundreds of spam e-mails, then 'the helpdesk' calls

    Staff at various organisations (not named)

    What happened
    The attackers signed their target's e-mail address up to a whole series of newsletters, so the mailbox overflowed. Then they called, or sent a Teams message under names such as 'Help Desk' or 'IT Support', offering to sort out the spam. The victim was asked to open Quick Assist and type in a code the 'helpdesk' gave them. That handed the attackers the computer.
    Why it worked
    The attacker creates the problem first, then offers the fix at exactly the right moment. Quick Assist is a genuine Windows tool, and the Teams names look internal.
    What it cost
    Microsoft gives no amount. Once in, the attackers installed more tools and in several cases spread ransomware across the whole network.
    What would have stopped it
    Only let someone into your computer if you contacted your own IT partner yourself. A sudden spam flood followed by a helpful call is a warning sign in itself.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    A Teams invitation with a code, on the real Microsoft site

    Staff at governments, NGOs, IT firms and other organisations in Europe and beyond

    What happened
    The attackers first made contact via WhatsApp, Signal or Teams, posing as someone who mattered to the target. After some friendly contact came an invitation to a Teams meeting. To join, the target had to enter a code on a Microsoft sign-in page. The attacker had generated that code, and that gave the attacker access to the account.
    Why it worked
    Build trust first, then use a sign-in page that really is Microsoft's: there's no fake address to spot. The victim does the two-step verification themselves, on the attacker's behalf.
    What it cost
    No amount published. The attackers searched mailboxes for words such as 'password' and 'admin', took e-mails and sent new phishing to colleagues from the hijacked account.
    What would have stopped it
    Never enter a code on a sign-in page because a chat or invitation asks you to. Organisations: switch off this way of signing in (device code) wherever nobody needs it.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    Fake invitations that turned up in your calendar by themselves

    Staff at around 300 organisations (not named)

    What happened
    Criminals sent e-mails that looked like a Google Calendar invitation from someone the victim knew. The invitation held a link to a Google Form or Google Drawing, containing yet another button disguised as a reCAPTCHA or support button. That led to a fake page where people entered personal details and eventually payment details.
    Why it worked
    Trust in Google and in ordinary calendar notifications, and a sender who seemed familiar. When security tools started flagging the invitations, the criminals switched from forms to drawings.
    What it cost
    More than 4,000 of these e-mails in four weeks, at around 300 organisations. Criminals can use the details for credit card fraud; no damage figure has been published.
    What would have stopped it
    Don't click links in an unexpected invitation, even if it's already in your calendar. Open documents only where they belong. In Google Calendar you can make only invitations from known senders appear automatically.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2023

    The hotel's account hijacked, the guests scammed

    Hotels that take bookings through a large booking platform, and their guests

    What happened
    A hotel received an e-mail from a 'former guest' who had supposedly left a passport behind, with a link to photos of it. The link delivered malware that stole the hotel's login for the booking platform. With it the fraudsters read the real reservations and messaged guests: their payment or booking just needed 'verifying', via a link.
    Why it worked
    Hotel staff want to help guests, and the guests got messages with their real booking dates, sometimes even through the real platform.
    What it cost
    In Singapore at least 30 guests lost 41,000 dollars between them. Dutch travellers lost money and card details too.
    What would have stopped it
    Guests: never re-enter your card details via a link in a message; check in the app or call the hotel. Hotels: don't open 'passport photos' from strangers, and turn on two-step verification for your platform account.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2023

    A call to the helpdesk: 'I can't log in'

    The IT helpdesk of a large US casino and hotel group, and that of a cleaning-products maker

    What happened
    According to the attackers themselves, they looked up an employee on LinkedIn and called the helpdesk as that person to get into the account. At the second company, attackers called the outsourced service desk and asked for new passwords. According to that company's lawsuit, the service desk handed them over without the usual checks: 'Oh, ok. Ok. So let me provide the password to you ok?'
    Why it worked
    A helpdesk wants to help quickly, and the check on who was calling relied on facts an attacker can look up. Or it didn't happen at all.
    What it cost
    The casino group reported a negative impact of about 100 million dollars on its results. The manufacturer is claiming 380 million dollars in damages in its lawsuit.
    What would have stopped it
    Never reset a password or two-step verification on the strength of a phone call alone: call back on a number you already had, or check with the manager. Got a reset message you didn't ask for? Report it at once.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2020

    130,000 text messages in a few days

    Tens of thousands of recipients in the Netherlands

    What happened
    In September 2020 a 22-year-old man sent almost 130,000 text messages in a few days, in the name of the Dutch tax office, PostNL, UPS and DigiD, among others. The links led to fake payment pages, where he also captured people's bank login details.
    Why it worked
    Familiar names and a payment link you quickly tap on your phone.
    What it cost
    According to the Dutch Public Prosecution Service, 60,000 victims of attempted fraud. The man was sentenced to 4.5 years in prison.
    What would have stopped it
    Never pay or log in via a link in a text. The Dutch tax office doesn't send direct payment requests. Open the app yourself or type the address in yourself.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2018

    A fake MijnOverheid e-mail, and the text code with it

    203 Dutch DigiD users

    What happened
    In June 2018 people received an e-mail with a link to a fake version of MijnOverheid, the Dutch government's message box. Anyone who logged in there with DigiD also handed over the text code. A script used those details straight away to log in for real and search MijnOverheid. A second wave followed in December: an official letter was supposedly waiting.
    Why it worked
    Trust in the government, and a fake site that passed the text code straight on. Real e-mails from MijnOverheid never contain a link.
    What it cost
    203 DigiD accounts were deleted and personal data was probably collected. In the second wave, according to DutchNews, 361 people fell for it.
    What would have stopped it
    Never log in via a link or QR code in a message that seems to come from DigiD, MijnOverheid or the tax office. Open the app yourself or type the address in yourself.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2019

    'Scan this QR code to receive your money'

    People selling things on an online marketplace

    What happened
    The seller gets a WhatsApp message from a 'buyer', who says they're paying from a business account and sends a QR code to scan with the banking app to 'accept' the money. In reality the seller was linking a second device to their own bank account: the fraudster's.
    Why it worked
    A QR code doesn't show where it leads, and it was a genuine feature of the victim's own banking app. That made it feel safe.
    What it cost
    Several hundred reports; in some cases fraudsters got away with thousands of euros. The bank refused at first, but later reimbursed all the damage after all.
    What would have stopped it
    You never scan a QR code to receive money. Someone sending you money only needs your account number.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    Fake QR stickers on parking meters

    Drivers in Dutch and Belgian cities

    What happened
    Neat stickers saying 'Scan to pay' appeared on parking meters, over or next to the real information. Anyone who scanned ended up on a site that looked like a parking app and asked for bank details. Councils removed the stickers and issued warnings. In Brussels the police arrested a man carrying 160 of these stickers.
    Why it worked
    A sticker looks official and convenient, and a QR code hides where it leads.
    What it cost
    No total known. Anyone who paid handed card or bank details to fraudsters.
    What would have stopped it
    Pay for parking at the machine itself or through the app you already have. Check the address in your browser after every scan.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2025

    'Your SIM card is expiring', and your number belongs to someone else

    Customers of two large Dutch providers

    What happened
    In 2025 customers got texts and calls in the name of their provider: the SIM card was about to expire, had to be 'validated' or, 'due to new legislation', switched to an eSIM. Via a link they entered their details, sometimes even their citizen service number (BSN). Some were also asked to forward a genuine e-mail from the provider or to delete the provider's app. After that, criminals had the SIM card.
    Why it worked
    A technical-sounding problem, 'new legislation' as the reason, and small steps that each seem harmless on their own.
    What it cost
    No numbers or amounts known. With the hijacked SIM cards, the criminals sent fake texts in bulk to new victims, from the victim's own number.
    What would have stopped it
    Your provider never gets in touch because your SIM card is expiring or needs validating. Delete the message or hang up. Lost control of your SIM card? Call your provider at once.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    'The police' come to collect your jewellery

    A 77-year-old woman in Eindhoven

    What happened
    One evening in December 2024 'the police' called: criminals were after her home, two of them had been arrested and two had not. She had to stay on the line for over an hour and was not allowed to talk to anyone. Her valuables would be collected and kept safe, and they agreed on a code word: 'papegaai' (Dutch for parrot). At about half past seven a young man at the door said the code word. He took her bank card, her jewellery box and a necklace she had been given shortly before her husband died, and even asked for a bag to carry it all. That same day four more reports like this came in from her neighbourhood.
    Why it worked
    Authority, fear and isolation: someone who stays on the line for an hour and may not talk to anyone cannot be warned by anyone. The code word only made the fake officer more believable.
    What it cost
    By the end of October 2025 the Dutch police had registered more than 10,000 incidents with fake police officers, against 520 in the whole of 2023. The criminals mainly target people aged 70 and over.
    What would have stopped it
    The police never collect money, bank cards or jewellery from you and never ask you to keep anything secret. Hang up, call 112 yourself and talk to someone you trust.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 4 October 2026. The source is in charge of its own story.

    Real story - 2023

    Her grandson's voice, cloned with AI

    Grandparents aged 73 and 75 in Canada, and the parents of a man in Canada

    What happened
    In 2023 a grandmother in Canada got a call from 'her grandson': he was in jail, without his wallet or phone, and needed money for bail. It sounded exactly like him. With her husband she withdrew 3,000 Canadian dollars at their bank, the daily maximum, and they went to a second bank for more. There a bank manager took them aside: another customer had had a call just like it, and that voice had turned out to be fake. 'We were convinced that we were talking to him', she said later. Another family got a call from a 'lawyer': their son had caused a fatal accident and needed money for the court case. They briefly heard 'him' too, and sent 21,000 Canadian dollars through bitcoin.
    Why it worked
    A voice you trust, fear and urgency. A few recorded sentences are enough to clone a voice.
    What it cost
    The grandparents were warned in time by a bank manager. The other family lost 21,000 Canadian dollars. In research for the Dutch government (2024) only 4 per cent could tell for sure that the cloned voice of a well-known radio presenter was fake.
    What would have stopped it
    Hang up and call back yourself on the number you already have, not with the call-back button. Ask something only that person can know, or agree a code word in the family.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 4 October 2026. The source is in charge of its own story.

    Real story - 2025

    The prime minister recommends an investment. Except it wasn't him.

    Facebook users in the Netherlands

    What happened
    In 2025 a fake video of the Dutch prime minister appeared on Facebook, together with journalists of the Dutch public broadcaster. He recommended an investment platform: the Dutch central bank would guarantee it and your household would earn a steady income from it. Whoever clicked landed on a fake news site, left a phone number and had to put in 250 euros first. Then 'investment advisers' called and asked for more and more money. The video was shown almost 250,000 times.
    Why it worked
    A famous face, an institution you trust and a small first amount. Then comes the pressure, over the phone.
    What it cost
    Victims can lose thousands of euros in a short time. In 2025 investment fraud caused the highest damage to private persons of all types of fraud reported to the Dutch Fraud Helpdesk, 34.1 million euros.
    What would have stopped it
    Don't click ads in which famous people recommend an investment, and don't believe in guaranteed profit. Never leave your phone number, and report such an ad to the Fraud Helpdesk.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 4 October 2026. The source is in charge of its own story.

    Real story - 2019

    'Our new payment route', from a hacked mailbox

    The accounts payable team of a large Dutch online shop, and a regular supplier

    What happened
    In late November 2019 an e-mail arrived from the real address of an employee at a regular supplier: 'Attached you will find our new payment route as instructed by management.' The neat letter gave a Spanish bank account. Two polite reminders asked whether the records had been updated yet. The account number was changed and from then on the payments went to the fraudsters. In mid-January the supplier asked where its money was.
    Why it worked
    The e-mail really came from the supplier's mailbox, with the real logo. Rules in that hacked mailbox hid every reply in a hidden folder, so the supplier never saw the confirmation. The judge said the shop should have shown 'healthy suspicion': a Dutch company suddenly using a Spanish account, clumsy wording and a well-known trick.
    What it cost
    751,493 euros went to the fraudsters. The court ruled that the shop had to pay the supplier again.
    What would have stopped it
    Never change an account number because of an e-mail. Call a contact you already know on a number you already had. And protect your own mailbox with two-step verification; check it for rules you didn't create.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2018

    A secret takeover in Dubai, paid in six instalments

    The managing director and finance director of a Dutch cinema chain

    What happened
    In March 2018 the Dutch managing director received e-mails that seemed to come from the head of the French parent company. They were about a strictly confidential takeover of a company in Dubai; an adviser from a big accountancy firm would be in touch. Contact was only allowed through 'my personal e-mail', never by phone, and not even colleagues could know. Six payments to Dubai followed within three weeks. It only came out when the French head office asked questions about the money.
    Why it worked
    Authority, urgency and above all secrecy that blocked every normal check: no phone calls, not a word to colleagues. There were doubts ('A strange process. Never seen anything like it'), but a phone call was brushed off and nobody rang the real chief executive on a known number.
    What it cost
    More than 19.2 million euros. Both directors lost their jobs.
    What would have stopped it
    Secrecy plus urgency plus a new account means: stop. Call the requester back on a number you already had, never one from the e-mail. No payment instruction may forbid you to involve a colleague.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2017

    An update to tax software takes down firms worldwide

    Users of a Ukrainian tax and accounting program, and through them large companies around the world

    What happened
    In June 2017 attackers used the update of a widely used Ukrainian tax and accounting program to spread the NotPetya malware. It spread through networks by itself and made computers unusable; the ransom demand was only a cover. At a global shipping company, one computer with the program was enough. All its domain controllers were wiped except one in Ghana, which happened to be offline because of a power cut.
    Why it worked
    The update came from software everyone trusted. And the networks were flat, so one infected PC could reach everything.
    What it cost
    According to the White House, more than 10 billion dollars of damage in total. The shipping company alone lost 250 to 300 million dollars.
    What would have stopped it
    Keep the PC with your accounting or tax software updated and separated from the rest of the network, and keep a tested backup offline. Even a trusted update can bring an attack with it.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2017

    The backup was on the same server

    A small Dutch bookkeeping office

    What happened
    On 12 February 2017 hackers got into the network and encrypted every file on the server, including the backup files. They got in through a remote-working connection that was open to the internet, combined with a weak password. The office paid the ransom and got its files back. A court case with the IT supplier followed.
    Why it worked
    The only backup lived on the same machine as the data, so the ransomware simply took it too. A second disk to take home now and then had been suggested back in 2010. And at the office's request, the passwords had been made simpler.
    What it cost
    Three bitcoin in ransom (2,890.83 euros), one week without any work and another with hardly any. The total claim was over 42,000 euros; the court split the blame.
    What would have stopped it
    A backup on the same machine isn't a backup. Use two disks in rotation, one of them always unplugged and off site. And never leave remote access open to the internet without two-step verification.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2023

    158 years old, and gone after one attack

    A British family-run haulage firm with around 400 lorries

    What happened
    In June 2023 a ransomware gang encrypted the files of the firm and two sister companies. They got in by guessing an employee's password, with software that makes thousands of attempts. The owners refused to pay. A new transport system was running within days, but the financial records didn't come back: the criminals had also destroyed the backup that was supposed to be stored safely elsewhere.
    Why it worked
    A guessable password on an account that could be reached from outside, and an 'off-site' backup the attackers could still get to. A month earlier the firm had taken out a cyber insurance policy worth 1 million pounds.
    What it cost
    Without financial records the bank wouldn't lend. The firm went into administration in September 2023 and around 700 people lost their jobs.
    What would have stopped it
    Insurance doesn't replace a backup criminals can't reach. Keep an offline copy of your books and invoicing, and put two-step verification on everything that can be reached from outside.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2020

    Two disks in rotation, and the criminals got nothing

    A small Dutch office that handles clients' post and paperwork

    What happened
    On a Monday in February 2020 the office manager couldn't open any documents: everything was encrypted and a note asked for bitcoins. They cut every connection straight away, called their IT partner and checked whether the backup had been hit. It hadn't. Besides the daily backup at the office, a copy went to an external disk kept outside the office every month, with two disks used in turn.
    Why it worked
    The attack itself worked: the files at the office were encrypted. But the monthly copy was out of the criminals' reach.
    What it cost
    No ransom. The business was at a standstill for one day while everything was put right.
    What would have stopped it
    A simple rotation turns a disaster into a lost day. As they put it at that office: 'It seems like such a hassle, but that's nothing compared to the hassle you have when you're attacked.'

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 1998

    90 per cent of an animated film deleted, and the backup didn't work

    A major animation studio, in the middle of making a feature film

    What happened
    Someone ran a delete command at the top level of the film project, and 90 per cent of the film vanished. The tape backups turned out to have failed without anyone noticing: the files had grown too big and the error log sat on the same full disk. The rescue: a colleague who had been working from home after having a baby had a full copy on her home computer. It was wrapped in blankets, strapped in with seatbelts and driven to the studio.
    Why it worked
    The backups were never test-restored, and the failure raised no alarm at all. The copy that saved the film existed by accident.
    What it cost
    A week of work on an unreliable restore was wasted, and 10 to 12 people worked non-stop for a whole weekend to check everything.
    What would have stopped it
    A backup is only real once you've restored something from it. Make sure error alerts reach a person, and keep a copy somewhere else on purpose, not by luck.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2017

    A database wiped, and the backups turned out empty

    An online platform for software developers

    What happened
    Late in the evening an engineer tried to fix a problem with the standby database and wiped the database folder. Only it turned out to be the main database. The engineer stopped a second or two later, but by then about 300 GB was gone. Then the backup storage turned out to be empty: the backup job had been failing, and the failure e-mails never arrived. The rescue was a copy that happened to have been made for a test that afternoon.
    Why it worked
    Several backup methods, but none of them tested, and nobody owned them. The company wrote it down itself: there was no ownership, so nobody was responsible for testing.
    What it cost
    Down for about 18 hours. More than six hours of changes were lost, affecting roughly 5,000 projects, 5,000 comments and 700 new user accounts.
    What would have stopped it
    Give your backups one named owner, test restores on a fixed schedule and make sure a failed backup can't fail silently.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2021

    Fire at the data centre, and the backup was in the same building

    Customers of a large European hosting provider, including small French companies

    What happened
    On the night of 10 March 2021 fire broke out at a data centre in Strasbourg. One building burned down, another partly. A small software company had its production in one building and its backup in a second system, or so it thought. After the fire it turned out both had been in the same building. A French brokerage firm's contract said its backup was physically separate; that one was in the same building too.
    Why it worked
    The backup was in the same place as the original. Customers assumed 'backup option' meant somewhere else, without checking.
    What it cost
    14,046 servers destroyed. Neither company could get its backup back. The software company was awarded 153,837 euros by the court at first instance.
    What would have stopped it
    Off site means another building, ideally another region or another provider. Ask your provider in writing where your backup is, and keep a copy yourself as well.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2020

    'Welkom2020', and every backup deleted

    A Dutch municipality

    What happened
    An administrator account with the password 'Welkom2020' ('Welcome2020') and no two-step verification could be used from the internet. After millions of login attempts the attackers got in. On 30 November 2020 they encrypted the systems and deleted 89 virtual servers. There were three sets of data in different places, but with that same admin account the attackers could delete every backup too.
    Why it worked
    A guessable password, no two-step verification, and backups that could all be deleted with one account. An offline backup offered earlier that year had been turned down.
    What it cost
    Total costs of around 4.2 million euros, and almost two years of recovery work.
    What would have stopped it
    3-2-1 isn't enough if one account can wipe all three copies. Keep one copy offline or immutable, with separate credentials. And never 'Welcome' plus a year as a password.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2019

    The backup drives encrypted too: the practice closes

    A small US medical practice

    What happened
    On 10 August 2019 the practice's servers were encrypted with ransomware. The practice wrote to its patients: 'The attack encrypted our servers, containing your electronic health records as well as our backup hard drives'. Recovery proved impossible.
    Why it worked
    The backup drives could be reached from the same systems as the records, so they were encrypted along with them.
    What it cost
    The practice closed for good on 17 December 2019. 5,835 patients were affected.
    What would have stopped it
    One copy must be out of the network's reach: offline, off site or immutable. And test restoring, especially for records you're legally required to keep.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2021

    Ransom paid, and absolutely nothing happened

    A Dutch fashion shop with a web shop and around twenty staff

    What happened
    On a Monday in spring 2021 nobody could get to the files on the shop's NAS: product photos, content and business data. Hackers had got in through a vulnerability in the NAS and encrypted everything. The owner paid a ransom of about 500 euros. After that, absolutely nothing happened. A security firm spent weeks recovering 60 to 70 per cent, but many files were no longer in their folders.
    Why it worked
    The NAS had a vulnerability, and that NAS was both the storage and the 'backup'.
    What it cost
    About 500 euros of ransom for nothing, weeks of recovery work and 30 to 40 per cent of the data never recovered.
    What would have stopped it
    A NAS is storage, not a backup. Keep it updated and off the internet, and paying guarantees nothing. Today that shop keeps a storage device that isn't connected to anything.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2022

    A media server on a home PC opened the company vault

    A senior engineer at a company that makes a password manager

    What happened
    The engineer's personal computer at home ran a media server for films and series, for private use. The security update for a known flaw had been available since May 2020 but was never installed. Through that flaw an attacker put a keylogger on the computer. It captured the master password when the engineer logged in to the company vault, which let the attacker copy a backup containing customer data.
    Why it worked
    A hobby server on the same PC as the work, about 75 versions behind. The personal and work vaults were linked with the same master password.
    What it cost
    A backup of all customer vault data was copied. The UK privacy regulator imposed a fine of 1.2 million pounds.
    What would have stopped it
    Work on a work device. Hobby servers, gaming PCs and smart devices belong on a separate network, not on the computer you work on. Update everything that can be reached from the internet, and keep work and personal passwords apart.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2023

    A Minecraft mod that steals passwords

    Players of a popular game, often children, and everyone who uses the same computer

    What happened
    In June 2023 a series of popular Minecraft mods on well-known download sites turned out to be infected with malware. It tried to steal logins and cookies from browsers, take over Discord and Microsoft accounts and swap cryptocurrency addresses, and it spread to other files on the computer. Players were told: change all your passwords.
    Why it worked
    Mods and cheats often come from third-party sites, so malware can easily pose as a mod. If the game runs on the same PC as your work, your saved passwords are within reach too.
    What it cost
    According to Kaspersky, more than 132,000 young gamers were targeted in one year by malware disguised as games, mods and cheats. No damage figure is known.
    What would have stopped it
    The children's gaming PC is not the work PC. Separate devices or at least separate user accounts, gaming devices on the guest network, and two-step verification on your work accounts, so a stolen password alone isn't enough.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    One laptop for work, games and pirated downloads

    About 165 organisations that stored data on one cloud platform

    What happened
    Attackers logged in to companies' cloud environments with stolen passwords. Those had been taken by infostealers: malware that steals saved passwords. According to the investigators, in several cases it began on contractors' laptops that were also used for gaming and downloading pirated software. Some passwords had been stolen back in 2020 and still worked years later.
    Why it worked
    One device for work and play, saved passwords, no two-step verification on the accounts and passwords that were never changed.
    What it cost
    About 165 organisations were warned. One of the attackers later admitted stealing, among other things, the call records of more than 100 million customers of a telecoms company; the group received over 2.5 million dollars in ransom.
    What would have stopped it
    No games, cracks or 'free' software on a device you work on. Put two-step verification on every work account, and change passwords that were ever saved on a shared or infected device.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2023

    A work password in a personal browser profile

    An employee of a company that handles logins for other businesses

    What happened
    On the work laptop, the employee was signed in to Chrome with a personal Google profile. The username and password of an important service account were saved in it. The personal Google account or a personal device was probably compromised, and the password with it. That got the attacker into the company's customer support system.
    Why it worked
    Passwords sync neatly to all your personal devices, even when they're work passwords.
    What it cost
    Files belonging to 134 customers were accessed, and active sessions of 5 customers were hijacked.
    What would have stopped it
    Keep work and personal browser profiles apart. Use a company password manager instead of 'save password' in a personal profile.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2016

    Routers and cameras with the factory password

    Owners of home routers, cameras and video recorders, and over 900,000 customers of a German provider

    What happened
    The Mirai malware constantly scanned the internet for devices still using a default username and password, from a list of 62 combinations. Mostly home routers, network cameras and video recorders were taken over this way and used together for huge attacks on websites. At the end of November 2016 more than 900,000 customers of a German provider were knocked offline after their routers were attacked by a new variant.
    Why it worked
    Factory passwords, remote management left open to the internet, and no updates.
    What it cost
    Attacks of more than 1 terabit per second, and over 900,000 households offline.
    What would have stopped it
    Change every default password (router, camera, recorder, smart plug), update the firmware and switch off remote management and UPnP if you don't need them. Smart devices belong on a network of their own, away from your work laptop.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    Old routers secretly working for someone else

    Owners of ordinary home and small-office routers, in the Netherlands too

    What happened
    The Dutch NCSC investigated routers of businesses and consumers whose internet addresses stood out for mass login attempts on other people's servers. On one router the NCSC examined on site, two botnets were running at the same time. That router had the latest firmware and its own password, but was connected directly to the internet with an open port. The botnet was made up of routers that no longer got updates and routers with outdated firmware.
    Why it worked
    Routers the maker no longer updates, management reachable from the internet, and the idea that a router 'just works'. A new password and the latest firmware weren't enough here.
    What it cost
    The NCSC spotted about 150 routers in the Netherlands believed to be compromised, part of around 13,000 compromised systems worldwide. The owners' connections were used for attacks on others.
    What would have stopped it
    Replace routers the maker no longer supports, change the default password and switch off management over the internet. If in doubt, use your provider's router. As the Dutch NCSC puts it: keep all network devices updated and replace devices the manufacturer no longer supports.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.