Phishing, scams and itsme: how to spot fraud and report it
By Thomas Schuddinck on Aug 27, 2026
In short
Fraud involving itsme almost always takes one of three forms: a scam (a form of social engineering where you're talked into approving an action you didn't initiate yourself), a device takeover (malware compromises your device, so actions on it can no longer be trusted), or an account takeover (your phone is stolen or your account is moved to a fraudster's device, so you lose control over your account).
Good to know: itsme will never contact you by email, SMS or phone to reactivate your account, re-enter bank details or to update your personal data. Report suspicious messages to phising@itsme-id.com or to suspicious@safeonweb.be.
Smartphone Security Alert in Landscape Orientation
Fraudsters borrow the itsme name for one simple reason: you trust it. They move fast, they sound convincing, and they only need about ninety seconds of your attention to do real damage. Here's how their tactics actually work, what we're doing to disrupt them, and the three questions that will keep you out of reach.
You are the target
Online fraud is rising fast. In 2025, a grand total of 11,000 phishing cases were reported across Belgium – a 30% increase on the year before. Fraudsters walked away with roughly €93 million.
These days, attackers target individuals rather than organisations: it's cheaper. Breaching a company means getting past layers of technology and multiple people. Tricking one person is way easier.
itsme is a target for exactly the same reason it's useful: it opens the door to banking, government, insurance and hundreds of other services. Our security team receives reports of new fake emails, SMS messages and websites every single day. We can take a phishing site down fast, sometimes within a couple of hours. However, a replacement often appears already the next morning, or even within the hour. Also, it's not unusual to see 5 phishing campaigns running at once. The sheer scale and speed of it all is exactly why awareness on your side matters as much as controls on ours.
In 2025, more than 11,000 phishing cases were reported in Belgium, a 30% increase year on year, with roughly €93 million stolen. (source: Febelfin)
How fraudsters misuse itsme
- Scam (social engineering). This is by far the most common, and cheapest method. It usually starts with an email or SMS that pushes you to a convincing fake page. Once the fraudster has some information about you, they call posing as your bank, the police or someone from itsme. Then, they talk you through a series of actions in your own app: approving a payment, confirming a login, signing a document. Your account is untouched. Your phone is untouched. You did it yourself, because someone made it sound urgent and legitimate.
- Device takeover. Here the account details haven't changed, but the device has been compromised by malware (malicious software). The actions are genuine itsme actions, but the person triggering them isn't you.
- Account takeover. The most complex and intrusive of the three. This is not simply a matter of physical access — a stolen phone alone is not enough. An attacker would also need the device PIN and the itsme PIN to gain entry. The real threat is social engineering: fraudsters contact victims by phone, impersonate a trusted party, and walk them through enrolling itsme on a device the fraudster controls. From that point, the account is compromised without the victim ever losing possession of their own phone.
Generative AI has made fraud faster and cleaner. Messages no longer give themselves away with clumsy language, pretexts are more plausible, and it’s become a lot easier to create a huge amount of messages. We've already seen cases where a voice familiar to the victim was cloned to make a call more credible, and robotic voices that collect basic details before handing over to a human are now routine. But the mechanism itself hasn't changed: fraud still depends on persuading a person to perform an action they wouldn't otherwise perform or that isn't self-initiated.
What we’re doing about it
- In the app. Behind every triggered action, there is a validation screen before the actual action is approved. It clearly displays the name of the service, the requested action, and any amounts if applicable. If something seems suspicious, you can still refuse the action. When the app detects that an itsme action arrives while you're on a phone call — which in itself is a strong signal of a scam in progress — an extra verification screen appears. The goal is to give you a moment to think about what you're actually approving.
- On the device. We assess signals about the trustworthiness of the phone initiating an itsme action, including indications that software on the device is attempting to manipulate the app. These signals feed into our detection and follow-up. This area is developing quickly, and further improvements are in progress.
- Against the infrastructure. Our fraud and security team monitors continuously, investigates suspected operations, and takes down the digital infrastructure behind them.
- With our partners. Taking over an itsme account is often a means to reach a bank account or a service behind it. That's why we work closely with partners in both directions. Contextual signals about an action (for example, an ongoing call while using the itsme app) are shared with our partners, who use them to score transaction risk and delay or refuse the ones that don't add up. When a partner reports a fraud case to us, we inform only the partners actually impacted by that specific case.
- Across the sector. Fraud cases are often not seen end to end by one organisation. A campaign might begin with a text message crossing a telecom network, run through a fake page hosted abroad, and end in a transfer leaving a bank account. Each party has part of the story, but seldom gets the full picture. That's why itsme takes part in a series of cross-sector fora and working groups alongside the financial sector, telecom operators, public authorities and cybersecurity organisations. Sitting in those rooms allows us to see how the app is being misused as a whole rather than case by case, to recognise a new tactic while it's still small, and to move on it before it becomes a wave.
itsme will never ask you by email, SMS or phone to reactivate your account, update your details or re-enter your bank information.
itsme… or is it? A checklist
- Check the sender's address: Don't trust just the display name. Legitimate itsme mail comes from @itsme-id.com or @itsme.be. Be extra sceptical of any link sent by SMS.
- Would itsme ever contact me about this?
If you're an end user, the answer is almost always no. itsme will not send you an unsolicited email or SMS asking you to reactivate your account, update your details, or re-enter bank information. Messages claiming your account was blocked, used for fraud, or needs urgent verification are the standard pretexts used by fraudsters. If something genuinely needs your attention, you'll see it when you open the app.
If you're a partner or business contact, the picture is different. You may receive legitimate communication from itsme via support channels or directly from our security team — for example in response to a report you submitted. In those cases, verify the sender address before clicking anything, and when in doubt, reach out through the channel you originally used to contact us.
- Is this really an itsme website? Fake pages are near-perfect copies: same logo, same styling, same layout. The only reliable check is how you got there. Don't follow a link: type itsme-id.com yourself, or start from the app. Also: no legitimate caller will ever need you to approve an itsme action while they're on the line with you.
Report it, even if you weren't fooled
Spotting a phishing attempt is good. Reporting it is even better: it stops the next person from falling for it. Therefore:
- Forward suspicious emails and SMS messages to phishing@itsme-id.com and suspicious@safeonweb.be. For an SMS, a screenshot is fine as long as the link is visible. For an email, please forward the message itself rather than a screenshot, so the link is included. These reports are processed automatically and directly feed URL blocking in Belgium.
- If you shared bank details or lost money: call Card Stop on 078 170 170, contact your bank immediately, and file a report with the police via my.police.be.
Fraudsters move fast, but they rely on one thing that hasn't changed in years: convincing you to act before you think. A few seconds of doubt is still the most effective control there is.
You May Also Like
These Related Stories
Supernova - 2026032413,13,40 - Copyright Jules Juten
Why phishing is a shared responsibility problem: insights from Cybernova
go live press image
itsme launches in the Netherlands and is set to replace iDIN
1653565760-microsoft-adobe-new-2