Pilot with internet providers prevents over two million visits to malicious websites
Every day, Dutch people are misled by fake messages and fraudulent websites. Phishing remains one of the largest forms of online crime. To better protect internet users against this, public and private parties have jointly tested a new approach in a pilot. The so-called Anti Phishing Shield demonstrates that the approach works: since the start of the pilot in July 2025, over two million attempts to visit phishing and fraudulent websites have been blocked among a group of over 200,000 users. Due to the success of the pilot, the Anti Phishing Shield is being placed under the management of the National Cyber Security Centre (NCSC). In the coming period, research will be conducted into how the reach and effectiveness of the Anti Phishing Shield can be further increased.
The initiative is a collaboration between the Ministry of Justice and Security, the NCSC, KPN, the police, the Dutch Banking Association, and NLconnect, the trade association for the telecom and broadband industry. During the pilot phase, several additional internet providers (SNLLR, TriNed, and Kabelnoord) joined the initiative, thereby strengthening it.
A technical solution has been developed within this public-private partnership. Internet providers can easily connect to this and use it to protect their customers against phishing and other forms of online crime. To use the Anti Phishing Shield, users must give explicit consent via a so-called 'opt-in'. This also happened during the pilot.
Need
The need for this approach is great. Figures from Statistics Netherlands (CBS) show that in 2025, 17% of the Dutch population (approximately 2.5 million people) became victims of online crime. According to research by Deloitte, 91% of cyberattacks begin with phishing.
Eefje Zents, Director of Digital Resilience Cooperation at the NCSC, also underscores the necessity of the initiative: “The Anti Phishing Shield is a necessary step in the fight against online crime. The success of this pilot shows that by working together, we can protect consumers against the dangers of phishing.”
How does the Anti Phishing Shield work?
The NCSC continuously collects updated information via public and commercial sources regarding domains being misused by criminals. These malicious domains are analyzed by the NCSC and placed on a 'denial list,' which is shared with participating internet providers via a DNS service . This list is updated by the NCSC every fifteen minutes and currently contains over 160,000 malicious domains. Domains that have been taken offline or are no longer malicious are removed from the list. The internet providers incorporate the list into their own systems and make the service available to their customers free of charge. For customers of internet providers who subscribe to this service via an opt-in, the page is automatically blocked when visiting a malicious domain.
This reduces the risk of the internet user becoming a victim of phishing or other forms of online fraud.
Jeffrey Leusink, CISO KPN: “At KPN, security is the standard. Every single day, we work to protect consumers and entrepreneurs against digital threats. Through public-private partnerships, such as in this pilot, we combine knowledge and technology to make the Netherlands demonstrably more digitally resilient. We are happy to share the insights we have gained with other parties so that we can continue working together towards a safer digital Netherlands.”
Further development of the Anti Phishing Shield
The success of the pilot has led the Ministry of Justice and Security and the NCSC to decide to continue the joint approach. The parties involved express the ambition to further increase the reach and effectiveness of the Anti Phishing Shield. This can be achieved by reaching more customers within participating internet providers and by offering other providers the opportunity to join. In the coming period, it will be explored how this scaling up can take shape step by step.