Executive Summary: A Small Country With a Doubling Problem

Belgium is not a fraud origin hub. It has no Hackerville, no compound economy, no diaspora call-centre industry. It is a wealthy, densely banked, highly digitised country of 11.7 million people — and it is losing money to fraud at a rate that nearly doubled in a single year.

The headline numbers from Febelfin, the Belgian banking federation: more than 11,000 phishing cases reported in 2025, a 30% increase on the previous year, with fraudsters obtaining approximately €93 million. In 2024 the figure was around €49 million. In 2022 it was €39.8 million; in 2021, €25 million.

That is a four-fold rise in four years in a country whose banking infrastructure is among the most modern in Europe. The interesting part of the Belgian story is not the loss curve — plenty of countries have one of those. It is the response, which breaks with the usual playbook in a way other European regulators are now studying.

Why Belgium Is Exposed

Three structural features make Belgium unusually attractive to phishing crews.

Instant payments are the default. Belgium sits inside the SEPA Instant ecosystem, and under the EU Instant Payments Regulation, euro instant transfers are now a standard offering across the bloc. A transfer initiated under pressure lands in seconds and is effectively irrevocable. The window in which a bank’s fraud team, or a victim’s second thoughts, can intervene has been compressed to almost nothing.

Card-reader and app-based authentication creates a scriptable ritual. Belgian retail banking runs on itsme and bank-issued card readers — genuinely strong authentication, which is exactly why the fraud has migrated to social engineering the customer into performing the authentication themselves. The criminal does not need to break the token. They need the victim to use it while on the phone.

Multilingualism cuts both ways. Dutch, French, and German are all official; English is widespread. Belgian consumers are accustomed to receiving official communication in a language that is not their first, which erodes one of the oldest phishing tells — awkward phrasing. A slightly stilted French-language “Belfius” message reads as normal administrative output.

Vishing: The Phone Call That Does the Work

Febelfin has flagged vishing — voice phishing — as the category on the sharpest upward curve, and it is the technique that best explains why Belgium’s strong authentication has not protected it.

The mature Belgian vishing script runs like this. The victim receives an SMS or email flagging a suspicious transaction. Shortly afterwards, a call arrives from a number that displays as the bank’s published fraud line. The caller knows the victim’s name, and often recent transaction details harvested from a prior phishing page or a data breach. They explain that the account is compromised and that funds must be moved to a “safe account” — or that the customer must confirm identity through their card reader or banking app.

Every subsequent step is performed by the victim, with their own credentials, on their own device. From the bank’s authentication logs, it is a legitimate session. Febelfin’s own figures show banks detect, block, or recover around 75% of fraudulent phishing transactions — an impressive rate that still leaves a quarter getting through, and the €93 million is what a quarter looks like.

There is also an awareness gap the industry is candid about: 8% of the Belgian population has never heard of phishing, with the weakest recognition concentrated in younger demographics who are otherwise the most confident digital users.

The National Anti-Phishing Plan: Engineering Delay

In July 2026, Consumer Protection Minister Rob Beenders and Febelfin announced a national action plan built on three pillars: additional security measures inside individual banks, closer cooperation between banks, and a broader approach pulling in telecoms operators, technology companies and government departments.

That third pillar is the strategically significant one. It is an explicit acknowledgement that fraud does not live inside the financial system — it arrives through a phone network, a search engine, a social platform, or a messaging app, and only ends at a bank.

The concrete measures are notable for what they optimise for: friction.

  • Default daily transfer limits cut to €5,000 by early 2027. Customers can request more, but the default position of every account becomes defensive rather than permissive.
  • A cooling-off period of at least four hours before a requested limit increase takes effect. This is aimed squarely at the vishing script, which depends on completing the whole sequence inside one phone call. A criminal who must keep a victim engaged and unsuspecting for four hours has a very different problem.
  • A guaranteed choice between instant and standard transfers, a deliberate move toward what the plan calls “slow banking” — instant rails should be an option, not an unavoidable default.
  • Complaint resolution within a maximum of 15 banking days by the end of the year.
  • A joint fraud-indicator platform for banks to share mule account and beneficiary signals sector-wide, so a mule account burned at one institution does not simply move to the next.

Belgian regulators are pairing this with a “name and shame” approach to anti-money-laundering enforcement, publicly identifying banks that repeatedly breach compliance rules — pressure aimed at the receiving end of the fraud chain, where mule accounts are opened and tolerated.

The Gap the Plan Leaves Open

The plan’s most conspicuous omission is reimbursement. It does not substantially address when victims get their money back — a gap Beenders himself has raised.

This is where Belgium diverges sharply from the United Kingdom, which since October 2024 has required banks to reimburse authorised push payment fraud victims up to £85,000 within five business days. The UK’s Payment Systems Regulator reported in July 2026 that mandatory reimbursement was associated with roughly £73 million a year less fraud and around 35,000 fewer scams — evidence that making banks pay changes how hard banks work to prevent.

Belgium has chosen prevention-by-design instead of liability-by-default. It is a defensible bet: friction stops the transfer before the argument about who pays ever begins. But for the Belgians who lost part of that €93 million in 2025, it settles nothing.

Protecting Yourself in Belgium

Your bank will never ask you to move money to a “safe account.” No Belgian bank operates such a thing. This single sentence defeats the dominant local script.

Treat caller ID as decoration. Spoofing the published fraud number is trivial. If a call concerns your money, hang up, wait a minute for the line to clear, and dial the number printed on your bank card yourself.

Never use itsme or your card reader while someone is on the phone with you. Legitimate bank staff will never talk you through an authentication step in real time. Anyone doing so is having you sign their transaction.

Lower your own transfer limit now, before it becomes the default. You do not need to wait for 2027. Most Belgian banking apps let you set a daily ceiling today — set it to what you actually use, and accept the four-hour wait when you genuinely need more.

Choose standard transfers for anything large or unfamiliar. Instant is a convenience, not an obligation. A payment that arrives tomorrow morning is a payment you can still stop tonight.

Report immediately to your bank and to CERT.be / safeonweb.be. Suspicious messages go to suspect@safeonweb.be. Speed is the entire variable in recovery: within minutes there is a chance, within a day there usually is not.

Talk to the younger people in your household. The Belgian awareness data is counterintuitive — recognition of phishing is weakest among the digitally fluent, who assume familiarity with technology is the same thing as familiarity with fraud. It is not.