Report phishing in Belgium: where and how to report

Do you want to report a suspicious SMS, email, fake website or WhatsApp message in Belgium? The right channel depends on what happened: message only, data sent, payment made, account takeover or threat. Keep the report factual and do not publish personal data.

Information checked : 2026-09-10

Priority / Safe channel / Action

  1. Priority - Limit the risk now

    Where to report phishing in Belgium and how to report a suspicious SMS, fake email, scam site or fraud attempt after saving the evidence.

  2. Safe channel - Do not follow the channel you received

    5 useful official sources listed below.

  3. Action - Contact the right service

    Forward to Safeonweb

Transparency and Sources

Page checked
2026-09-10
Sources checked
2026-09-17
Content status
information published with visible sources and clear limits
Official sources cited
5
Editorial responsibility
StopArnaques

StopArnaques is an independent Belgian service. It is not a public authority and does not speak on behalf of the organisations cited.

Report a correction

Immediate summary

  • Do you want to report a suspicious SMS, email, fake website or WhatsApp message in Belgium? The right channel depends on what happened: message only, data sent, payment made, account takeover or threat. Keep the report factual and do not publish personal data.

What this action may have triggered

  • The original message may preserve information missing from a screenshot.
  • An active URL or unmasked image can expose others if published.

Do this now

  • For a phishing message without loss: keep the message and use the appropriate official reporting channel, such as Safeonweb when the message contains a suspicious link or attachment.
  • If you paid, shared card details, codes or login credentials, contact your bank or the affected service first through an official channel.
  • For loss, threats or account takeover, ask local police what evidence is required and keep a short timeline.

Emergency timeline

  • Now, 0-5 min: do not click further, keep the original message and avoid any new interaction with the sender.
  • Within 30 min: collect the channel, time, sender and neutralised link without sharing more data.
  • Today: write a short timeline with what you saw, what you did, which amounts or accounts are involved and which measures were already taken.
  • This week: monitor accounts, sessions, passwords and follow-up messages; stay alert for fake helpdesk or bank calls.

Do not do this

  • Do not republish an active fraudulent link.
  • Do not publicly share codes, identity documents or complete banking data.
  • Do not accuse a domain or person without sufficient validation.

What should be checked

  • Confirm that the reporting destination is an official service: Safeonweb, your bank, the impersonated organisation, police or ConsumerConnect depending on the situation.
  • Separate what you observed from what you infer: text, link, number, time, requested action and action already taken.

Useful evidence to keep

  • Keep the original email, headers if available, SMS, phone number, neutralised URL, screenshots and timestamps.
  • Provide banking references only through the official channel that requests them. Do not post them in comments, forums or social media.

Prepare the next steps without false promises

  • Keep the acknowledgement or report reference.
  • Reporting supports prevention but does not replace urgent account-security measures.

Which reporting channel should you use?

  • A suspicious message with no damage can be forwarded to Safeonweb. If money, bank data, itsme, an account or an identity document is involved, forwarding the message is not enough.
  • Choose the channel based on what happened: bank for payment means, the relevant service for accounts, police for loss or serious attempts, ConsumerConnect for consumer fraud situations.

What makes a report useful?

  • Include the channel, date, time, displayed sender, impersonated organisation, neutralised link and the action requested. Do not publish full card numbers, codes, identity documents or other people's data.
  • An original email often contains technical details missing from a screenshot. For SMS or chat, a clear copy with personal data masked is usually more useful than a long narrative.

Limits of reporting

  • A report helps detect patterns, but it does not automatically block a payment, recover an account or replace a police report when harm occurred.
  • If you already paid or gave a code, treat reporting as the second step. The first step is still limiting damage through the bank, Card Stop or the relevant official service.

Limits of this guidance

  • This page helps choose where to report phishing in Belgium. Reporting alone does not secure an account, stop a payment or block a card.
  • If you already clicked, paid or shared a code, treat reporting as the second step. First limit harm through the bank, Card Stop or the official service being impersonated.

What to do now

  • If you have not acted, do not click further and open the named service's official channel yourself.
  • If you clicked, close the page, enter nothing else and note what information was shown or requested.
  • If you shared a code, card, password or payment, contact your bank or the relevant official service immediately.
  • Keep the message, time, link used and any useful screenshots. Share them only with an official reporting channel or a trusted helper.

Limits of this page

  • This page does not prove that a message is safe and does not replace your bank, the police, Safeonweb, a platform or a public service.
  • A scam may be new, very well written or described with too little context. Use the result as decision support, not as absolute certainty.
  • Before taking a final action, checking through the official channel matters more than the appearance of the received message.

Check through an official channel

  • Type the service address yourself or open the official app. Do not use a phone number, link or QR code from the suspicious message to verify the situation.
  • When money, card details, a code or account access are involved, the safety action comes first. The analysis can then help organise the evidence.

How to read the result

  • A low number of signals does not mean that everything is safe. It only means that this page or analysis did not find decisive evidence with the information available.
  • Focus on the requested action: paying, sharing a code, installing an app, approving a bank action or leaving an official platform. That action matters more than a logo, sender name or polished wording.
  • If the situation feels urgent, step away from the received message first. Then check calmly through a channel you already trusted before the message arrived.

Belgian reading of this situation

  • For the phishing report, focus on the relevant Belgian next step: open the official channel yourself, contact the bank, use Safeonweb or preserve evidence.
  • The right decision for the phishing report depends on what has already happened. Reading a message is not the same as clicking, paying, sharing a code or granting remote access.

Frequently asked questions

Where can I report phishing in Belgium?

Use the official channel that fits the situation, such as Safeonweb for phishing messages. If a bank, card, account or payment is involved, also contact the affected service through its official channel.

Is a screenshot enough?

It shows the appearance, but the original often contains more information. Keep both without exposing personal data.

Should I click to obtain the full address?

No. Do not visit the site to complete the report.

Will reporting block the site immediately?

Not necessarily. Services must verify the information. Protect your accounts without waiting for that outcome.

Useful official sources

Check a similar message

Forward to Safeonweb

I already clicked

Prepare my next steps