1,742 account takeovers: a regulator's 2025 data on AI phishing
The Dutch data protection authority's 2025 breach report shows account takeovers up 187% in a year, almost all traced to phishing. What the numbers mean for GDPR-regulated organisations.
Most annual breach reports make for dull reading: totals up a bit, a chart of sectors. The Netherlands’ data protection authority, Autoriteit Persoonsgegevens (AP), published one in July 2026 with a genuinely striking number in it. Account takeovers, where a criminal gets into someone’s email or work account, went from 607 in 2024 to 1,742 in 2025. A 187% rise in a single year, from an authority with no reason to talk its own numbers up.
The AP’s explanation matches what we’ve argued in earlier pieces on this site: generative AI has made phishing cheaper, more convincing, and easier to run at scale. What’s useful here is that it’s a regulator saying so, backed by breach notifications rather than a vendor survey, and worth a closer look if your organisation processes personal data under GDPR anywhere in the EU.
Key takeaways
- Total breach notifications rose only 4% year on year, but breaches caused by cyber attacks rose 58%, and account takeovers specifically rose 187%.
- Account takeovers were, in the AP’s words, “virtually always the result of phishing.” Ransomware grew only modestly (127 to 136 attacks), which suggests AI is supercharging phishing specifically, not cyber attacks generally.
- The AP identifies three ways AI is changing phishing: better reconnaissance on targets, more convincing and personalised messages, and easier delivery at scale.
- A cosmetics retailer’s customers received birthday-themed phishing emails built from data likely assembled across several unrelated breaches, not a hack of the retailer itself. Reconnaissance, in practice.
- The standard defences haven’t stopped working. MFA, network segmentation, and staff reporting routes still block these attacks. The gap is coverage and habit, not obsolescence.
The headline numbers
The AP received 39,407 data breach notifications in 2025, against 37,839 in 2024. On its own, an unremarkable 4% increase, the kind of drift you’d expect from a growing economy generating more paperwork.
Look inside the total and the picture changes. Breaches caused by cyber attacks rose from 1,537 to 2,428, a 58% jump (the AP strips out a one-off 2024 spike of 5,407 notifications tied to a single incident at IT supplier AddComm, to keep the comparison fair). Within that category, account takeovers rose from 607 to 1,742, resulting in at least 1,780 breach notifications once you account for one attack hitting several organisations through a shared supplier. Ransomware, the more headline-grabbing attack type, moved from 127 to 136. Barely a ripple by comparison.
Why account takeover is the number to watch
Account takeover isn’t the end of an attack, it’s the beginning of one. Once a criminal is inside a mailbox, usually via stolen login details or a fraudulent login approval, they can read invoices, monitor conversations, and send convincing follow-up messages from a genuine internal address. It’s the standard entry point for business email compromise and a common precursor to ransomware. A near-tripling in successful account takeovers is a near-tripling in footholds handed to attackers for whatever comes next.
How AI is doing the heavy lifting
The AP sets out three specific ways it sees AI changing phishing, and each maps to a step in a standard attack.
Better research on targets. Language models make it easy to combine data from an earlier breach with information scraped from social media, producing a detailed target profile in minutes rather than hours. The report cites a case where a cosmetics retailer’s customers received phishing emails timed to their birthdays and referencing real personal details, despite the retailer’s own systems never being breached. The data had likely been assembled from other leaks and public sources: reconnaissance, with no hack of the target required.
More convincing messages. AI mimics writing style well and produces fluent, largely error-free text, including in languages the attacker doesn’t speak. “Look for bad grammar and awkward phrasing” is no longer reliable advice; that signal has mostly disappeared.
Delivery at scale. Off-the-shelf phishing kits, some sold as a subscription, now bundle AI features that personalise messages and adjust a campaign in real time based on what’s working. The skill needed to run a large, targeted campaign has dropped sharply, the same shift covered in our piece on AI and the collapsed cost of cybercrime and the ClickFix technique, which trades on the same combination: a convincing pretext and a low-friction ask.
AI cuts both ways
The AP doesn’t present this as one-sided. It notes AI is also being applied to defence, citing Anthropic’s Mythos model, which the Dutch NCSC flagged in 2026 as capable of finding and fixing software vulnerabilities faster than a human team. The same capability helps whichever side gets there first: the organisation that patches faster, or the attacker who finds the hole first. Hence the AP’s advice to treat patch management and monitoring as more urgent, not less.
What this means if you’re GDPR-regulated
For any organisation processing personal data in the EU, three things follow.
Breach notification hasn’t changed, but your exposure has. GDPR’s 72-hour clock starts the moment you become aware of a personal data breach. If account takeover is a more common route in, your incident response process needs to treat phishing-led compromise as a live scenario, not an edge case.
Risk registers should reflect the current threat, not the 2023 one. If the likelihood rating on phishing or business email compromise in your ISMS hasn’t moved in two years, this report is a reasonable trigger to revisit it.
Awareness training needs a rewrite, not a refresh. Training that tells staff to look for spelling mistakes is now actively unhelpful. Teach verification habits instead: confirm unusual payment or credential requests through a different channel than the one they arrived on, and treat urgency as a red flag, not a reason to move fast. Updated phishing simulations with current, AI-quality lures, rather than the dated ones many platforms still ship with, are a cheap way to test whether it’s landed.
Practical questions to ask now
- Does your incident response plan assume phishing-led account takeover as a likely entry point?
- Is multi-factor authentication enforced on every email and business system account, no exceptions?
- Does your awareness training still tell staff to look for bad grammar or spelling errors?
- Do payment changes or password resets require verification through a separate channel?
Closing
The headline figure in most breach reports is the total. This one reads better from the inside out: overall volume barely moved, but the category tied most directly to phishing very nearly tripled, a regulator pointing at the same shift we’ve flagged in earlier pieces on this site.
None of the fixes are exotic. MFA, verified channels for high-trust requests, and training that reflects how phishing actually looks now cover most of the gap. The organisations that get caught out are usually the ones that assumed last year’s training and risk register were still good enough.
If you’d like help reviewing your risk register, awareness programme, or incident response plan against current phishing tactics, get in touch. Our GDPR & Privacy, Risk & Governance, and AI Governance services all cover this ground.
