Belgian authorities, including the Public Prosecutor’s Office and the Centre for Cybersecurity Belgium (CCB), warned that unknown actors have been impersonating His Majesty the King and other senior figures (including the King’s chief of cabinet and the head of Belgium’s military intelligence service) to fraudulently solicit money from targeted victims. Since early 2025, foreign dignitaries, Belgian families, and business leaders have been contacted via phone, WhatsApp, and email using spoofing-style techniques to make messages appear to originate from the Royal Palace or the King Baudouin Foundation; early lures included requests for funds tied to a fabricated story about “liberating” Belgian journalists allegedly held hostage in Syria, with at least one reported transfer.
Authorities reported a renewed wave of attempts in early January 2026 focused largely on Belgian business leaders, including invitations to video calls intended to increase credibility; the video imagery may have been AI-generated. Some targets also received fake invitations to sponsor a non-existent gala dinner purportedly organized by the King Baudouin Foundation (claimed to be scheduled for February and April 2026). The Federal Prosecutor’s Office is conducting a preliminary investigation with the Federal Computer Crime Unit (FCCU) and other federal police services, and CCB continues broader national efforts to strengthen cybersecurity across critical sectors, though no additional investigative details were released.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
The Federal Prosecutor’s Office, supported by the Federal Computer Crime Unit and other specialized federal police services, began a preliminary investigation into the scam campaign. On January 24, 2026, the Public Prosecutor’s Office and the Centre for Cybersecurity Belgium publicly warned about the fraud and said further details were being withheld to protect the case.
Some victims received invitations to a non-existent King Baudouin Foundation gala dinner supposedly scheduled for February and April 2026. The invitations were part of the broader impersonation scam exploiting royal and public-figure identities.
In early January 2026, authorities detected a renewed wave of scam attempts focused mainly on Belgian business leaders. The operation included invitations to video calls meant to convince victims they were speaking with the King, with authorities assessing the imagery may have been AI-generated.
As part of the scam campaign, the perpetrators asked targets for funds tied to a fabricated hostage situation involving Belgian journalists allegedly held in Syria. Most targets identified the approach as fraudulent, but at least one victim transferred money.
Since early 2025, unknown perpetrators have contacted foreign dignitaries, Belgian families, and business leaders by phone, WhatsApp, and email while posing as His Majesty the King and other senior Belgian figures. The messages used spoofing-style techniques to appear as though they came from the Royal Palace or the King Baudouin Foundation.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.