The Dutch Data Protection Authority has raised alarms over the increasingly sophisticated nature of phishing attacks and cybercrime, driven by the rapid advancement of artificial intelligence technology. As cybercriminals harness AI to craft highly convincing and personalized phishing attempts, organizations face mounting pressure to bolster their cybersecurity defenses immediately.
Leveraging AI, criminals can fuse information from prior data breaches to produce emails that are not only believable but also tailored to the individual recipient. This sophistication in phishing tactics significantly heightens the risk of account takeovers, a gateway that can enable attackers to orchestrate more extensive and damaging cyberattacks against businesses and institutions.
Recent statistics underscore the urgency of the situation. The authority has noted a significant increase in account takeover incidents, with reported cases climbing from 607 in 2024 to a troubling 1,742 in 2025. Furthermore, the number of data breach notifications received by the regulator surged to 39,407 in 2025, emphasizing the pressing cybersecurity challenges that entities must confront.
To mitigate these growing threats, the Dutch regulator is advising organizations to adopt robust cybersecurity strategies. This includes implementing comprehensive policies, enhancing data protection practices, and refraining from storing sensitive information in centralized systems. Such measures are vital to diminishing the potential for large-scale cyberattacks and safeguarding sensitive data from malicious actors.