Belgian bank fraud

Fake advisers, fake portals, sponsored ads and requests for codes or readers.

Information checked : 2026-09-10

Transparency and Sources

Page checked
2026-09-10
Sources checked
2026-09-17
Content status
information published with visible sources and clear limits
Official sources cited
5
Editorial responsibility
StopArnaques

StopArnaques is an independent Belgian service. It is not a public authority and does not speak on behalf of the organisations cited.

Report a correction

What you need to understand

  • Fake advisers, fake portals, sponsored ads and requests for codes or readers.

The scam, step by step

  • Bank fraud brings together several paths: fake login sites, phishing by message, fake support, transfer to a supposedly secure account, or physical card collection.
  • The visual identity and the number shown can be copied. What they all have in common is an unusual request for secrecy, approval or moving money.
  • The risk should be assessed based on the action requested and the channel used, not just the logo or the bank name.

What the fraudster is trying to get

  • Access to online banking, codes and confirmations.
  • A payment, a transfer or the bank card.

Common variants

  • Banking phishing and fake sponsored results.
  • Fake adviser or fake fraud service.
  • Fake secure account, fake collector and invoice fraud.

Warning signs in your case

  • Request for code, reader, digipass or OTP
  • Portal or domain that is not official
  • Pressure around a transfer, a suspension or a securing step

What a legitimate service would do

  • A bank does not ask for a PIN or a full reader code by phone or message.
  • A warning can be checked by stopping the exchange and then using the official app and official number.

Belgian context and fraud chain

  • Belgian banks use different authentication methods: app, card reader, SMS code or itsme depending on the service. The fraudster adapts their wording to the bank being targeted, but always tries to make you approve an action they control.
  • The number shown during a call and the sender name of an SMS are not reliable proof of identity. The decisive check is to stop the incoming channel and then go back to the app or the official number.

Decision points to check

  • Distinguish information from authorisation. A bank may tell you about an operation; it does not need you to share a secret to cancel it.
  • Refuse any instruction to move money to a so-called secure account. A new IBAN belongs to a different beneficiary, even if the caller gives it a reassuring name.
  • Do not approve anything as long as the amount, the beneficiary and the action shown do not match an operation you prepared yourself.

How to check without taking risks

  • Do not reply to the message and do not use the link, QR code or number it contains.
  • Open the official app or website yourself, then check whether the same request appears in your personal space.
  • If in doubt, contact the organisation using a number found on its official website, a reliable invoice or your bank card.

What to do immediately

  • Call your bank using the official number.
  • Open the app or the official website that you typed in yourself.

If you already clicked, paid or replied

  • Stop the exchange and do not try to negotiate with the sender of the message.
  • Change the access details you shared through the official service. Contact the bank immediately if a payment, card, IBAN or confirmation is involved.
  • Keep the exchanges, payment references and observed addresses for reporting, without posting personal data publicly.

What to do after an incident

  • Call the bank’s fraud service from an official number and describe precisely the codes shared, confirmations made, transfers signed and apps installed.
  • Block the card via Card Stop if its data or possession is compromised. Blocking the card does not replace securing online banking when a digital access has also been shared.
  • Ask the bank for the transaction references and keep the evidence. In case of loss or identity theft, also follow the reporting steps indicated by the authorities.

Limits and level of proof

  • An unusual call is not by itself proof of fraud; however, no decision should rely on the identity shown by the incoming call.
  • StopArnaques does not see the account or the bank transactions. The bank remains the only source to confirm their status and the possible measures.

Analysis grid for the Belgian account security case

  • To review a the Belgian account security case case, separate four questions: who made contact, through which channel, what action is requested, and which independent element can confirm it. One reassuring answer does not make up for the other inconsistencies.
  • The priority signs in this file are: request for code, reader, digipass or otp; portal or domain that is not official; pressure around a transfer, a suspension or a securing step. Their combination matters more than an isolated word, logo or typo.
  • Always compare the message with the real status of the service. For the Belgian account security case, a request that is missing from the app, the account or the official contact should remain unexecuted until confirmed.

When to ask for immediate help

  • In a the Belgian account security case case, contact the relevant service without delay if a code, confirmation, payment, card, identity document or remote access has already been shared. Describe the exact action instead of only saying that you were hacked.
  • If no sensitive action was taken, keep the useful elements, block the contact and use the detector to document the signs. This difference avoids confusing prevention, a confirmed incident and a simple unsolicited message.

What to do now

  • If you have not acted, do not click further and open the named service's official channel yourself.
  • If you clicked, close the page, enter nothing else and note what information was shown or requested.
  • If you shared a code, card, password or payment, contact your bank or the relevant official service immediately.
  • Keep the message, time, link used and any useful screenshots. Share them only with an official reporting channel or a trusted helper.

Limits of this page

  • This page does not prove that a message is safe and does not replace your bank, the police, Safeonweb, a platform or a public service.
  • A scam may be new, very well written or described with too little context. Use the result as decision support, not as absolute certainty.
  • Before taking a final action, checking through the official channel matters more than the appearance of the received message.

Check through an official channel

  • Type the service address yourself or open the official app. Do not use a phone number, link or QR code from the suspicious message to verify the situation.
  • When money, card details, a code or account access are involved, the safety action comes first. The analysis can then help organise the evidence.

How to read the result

  • A low number of signals does not mean that everything is safe. It only means that this page or analysis did not find decisive evidence with the information available.
  • Focus on the requested action: paying, sharing a code, installing an app, approving a bank action or leaving an official platform. That action matters more than a logo, sender name or polished wording.
  • If the situation feels urgent, step away from the received message first. Then check calmly through a channel you already trusted before the message arrived.

Belgian reading of this situation

  • For the Belgian account security case, focus on the relevant Belgian next step: open the official channel yourself, contact the bank, use Safeonweb or preserve evidence.
  • The right decision for the Belgian account security case depends on what has already happened. Reading a message is not the same as clicking, paying, sharing a code or granting remote access.

Frequently asked questions

How can I check a request linked to the Belgian account security case without clicking?

Call your bank using the official number. Then compare the request with your official space and test the text or the link in the StopArnaques detector.

Which signs should make me stop?

Stop the interaction if you notice in particular: request for code, reader, digipass or otp, portal or domain that is not official, pressure around a transfer, a suspension or a securing step. A known visual identity never makes up for an unusual request.

Does the detector replace the official check?

No. The detector helps you understand the risk and the signs observed. For a banking, administrative or account-related operation, always confirm with the official service through an independent channel.

Useful official sources

Test another suspicious message

I already took action

Prepare my next steps