Watchdogs warn of growing damage from data breaches
Public reports confirm more ransomware attacks and cybercrime, but not how consumers respond.
Dutch regulators and investigative agencies report a growing digital threat to businesses and citizens. The precise claim that consumers have become indifferent to data breaches could not be independently confirmed in public sources.
The Autoriteit Persoonsgegevens registered 136 ransomware attacks involving personal data in 2025. That was more than in 2024, when the regulator reported 127 attacks. According to the AP, data are increasingly being stolen in ransomware attacks, increasing the risk of fraud and identity theft.
The broader picture of cybercrime is also substantial. In their Cybercrimebeeld Nederland 2026, the police and the Public Prosecution Service estimate that around 2.5 million people in the Netherlands fell victim to cybercrime or online scams, fraud, threats or intimidation in 2025.
The investigative agencies also see new online networks in which young cybercriminals exchange knowledge, services and stolen data. According to the police and the Public Prosecution Service, artificial intelligence is not fundamentally changing cybercrime, but it can make attacks faster, larger in scale and more convincing.
In 2025, the AP received more than 13,500 complaints and tips about possible breaches of privacy legislation. That was 75 per cent more than in 2024. According to the regulator, more than half of the complaints about healthcare concerned the major data breach at Clinical Diagnostics.
These figures do not automatically mean that companies are being hacked on a mass scale or that consumers are ignoring data breaches. They do show that the scale of incidents, reports and potential consequences is sufficient to make preparation and clear communication necessary.
For now, therefore, the headline about data-breach fatigue is mainly a journalistic interpretation. Public sources confirm the growth in attacks and complaints, but contain no verifiable research showing that consumers care much less about them.
One story, several perspectives
What is established
- The number of ransomware attacks and privacy complaints increased, according to the AP.
- The police and the Public Prosecution Service estimate the number of victims of cybercrime and online fraud in 2025 at 2.5 million.
- According to the police and the Public Prosecution Service, AI can increase the speed and scale of attacks.
Left
Arguments Companies often collect more personal data than necessary and should not pass the costs of poor security on to citizens.
Values Privacy, public protection and responsible business conduct.
Consequences Stricter supervision and higher fines could encourage companies to improve security, but would increase their compliance costs.
Centre
Arguments Digital security is a shared responsibility of companies, government and citizens. Reporting, standards and cooperation should limit the damage.
Values Pragmatism, proportionality and resilience.
Consequences Targeted standards and information-sharing could reduce risks without imposing the same obligations on every organisation.
Right
Arguments Organisations must remain responsible for their own digital security and not wait for new rules.
Values Individual responsibility, innovation and limited government intervention.
Consequences More room for private security solutions could accelerate innovation, but vulnerable organisations could be left behind.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved with corrections · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The available figures on ransomware, privacy complaints and cybercrime have been confirmed. The unsubstantiated claim about consumer indifference has been toned down in the text.
- confirmed The number of reported ransomware attacks rose from 127 to 136. — Figures from the AP’s ransomware report. source
- confirmed Around 2.5 million people in the Netherlands fell victim to cybercrime or online scams in 2025. — Estimate in Cybercrimebeeld Nederland 2026. source
- confirmed The AP received more than 13,500 privacy complaints and tips in 2025. — Figure from the 2025 complaints report. source
- uncertain Consumers are tired of or indifferent to data breaches. — Not independently confirmed by a public source. source
1 correction(s) applied
- Was: Consumers do not care much: we are tired of data breaches.Now: Public sources confirm more cyberattacks and complaints, but not how consumers respond. (The specific claim about consumer behaviour could not be verified.)
Editor's note
The increase in ransomware, privacy complaints and cybercrime is substantiated. There is no public source for the specific claim about consumer behaviour.Sources
- Rapportage ransomware 2025 — Autoriteit Persoonsgegevens
- AP: grote toename van privacyklachten — Autoriteit Persoonsgegevens
- Politie en OM: cybercrime is grenzeloos — Openbaar Ministerie