The Dutch Data Protection Authority has issued a critical alert regarding the escalating sophistication of cybercrime, driven by the rapid advancements in artificial intelligence. The authority emphasizes the urgency for organizations to bolster their cybersecurity defenses immediately, as criminals are leveraging AI to craft highly convincing phishing scams. By utilizing information from previous data breaches, these AI-generated phishing emails are increasingly personalized and effective.
Phishing attacks pose a significant threat as they can result in account takeovers, which, in turn, provide cybercriminals with access to launch more extensive attacks on organizations. The Dutch regulator has observed a substantial increase in such incidents, with account takeover cases rising dramatically from 607 in 2024 to 1,742 in 2025. This alarming trend underscores the need for heightened vigilance and stronger security measures across all sectors.
In addition to the surge in account takeovers, the authority recorded a staggering 39,407 data breach notifications in 2025 alone. This figure highlights the expanding cybersecurity challenges that both businesses and public institutions are facing. The increasing frequency and complexity of these breaches necessitate a proactive approach to cybersecurity management to protect sensitive information and maintain public trust.
To combat these evolving threats, the Dutch Data Protection Authority advises organizations to adopt comprehensive cybersecurity strategies. Key recommendations include enhancing data protection practices and avoiding the storage of sensitive data in centralized systems. By decentralizing sensitive information, organizations can mitigate the risk of large-scale cyberattacks and better safeguard their assets against potential breaches.