Dutch authorities reported two separate but related forms of financial cyber-enabled fraud. In one case, three Dutch men in their twenties were sentenced to prison terms of three to seven years for running a large-scale phishing and bank helpdesk fraud operation that stole hundreds of thousands of euros. Prosecutors said the group used stolen victim data, phishing emails, fake banking sites, follow-up phone calls, cash-out teams at ATMs, mule accounts, and card collection teams to drain accounts, with the lead suspect allegedly coordinating around 100 callers and operating from luxury apartments in Rotterdam.
In a separate Dutch court case, a 34-year-old Amsterdam man was prosecuted for allegedly helping open dozens of ABN AMRO bank accounts in other peoples’ names by bypassing facial verification during remote onboarding. According to the court and prosecutors, the scheme involved replacing ID document photos with the suspect’s image and altering selfies so they matched the victim documents closely enough to defeat the bank’s face-scan checks. The activity was detected by the bank in spring 2025, and investigators reportedly found victim IDs and linked email accounts on the suspect’s phone, indicating a deliberate effort to abuse digital identity verification for account creation and likely downstream fraud.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
A Dutch court sentenced three men in their twenties to prison terms of three to seven years for running a large-scale phishing and fake bank helpdesk fraud operation. The court said the organized scheme laundered about €2 million and likely converted much of the stolen money into cryptocurrency.
A 34-year-old Amsterdam man appeared in court accused of helping open dozens of ABN AMRO bank accounts in other people's names by bypassing facial verification. Prosecutors requested a 2.5-year prison sentence, including six months suspended.
During the suspect's arrest in December 2025, border police found a large number of bank cards tied to accounts connected to him. Investigators also linked materials on his phone to victim IDs, related email accounts, and other evidence.
In spring 2025, ABN AMRO discovered that dozens of accounts had allegedly been opened in other people's names by manipulating ID photos and selfies to defeat facial checks in the bank's mobile app. Another fraudulent account was reportedly opened in May using a woman's identity document.
Prosecutors said one of the fraudulent ABN AMRO accounts was opened on 2025-04-08 using the identity of a Canadian man. The account was allegedly created by bypassing the bank's facial verification process with manipulated identity materials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.