Skip to content
Beveiligingsnieuws

Anti Phishing Shield: 2M phishing attempts blocked

Anti Phishing Shield

Phishing remains one of the most common ways cybercriminals trick people online. In the Netherlands, scammers regularly use fake messages and websites to lure victims into clicking links or entering login and payment details. To tackle this at the moment a user lands on a malicious domain, public and private partners tested a technical approach in a pilot: the Anti Phishing Shield.

During the pilot, which started in July 2025, the system blocked more than two million attempts to visit phishing and other fraudulent websites for a group of over 200,000 users. The results show that this kind of targeted, DNS-based intervention can make a real difference.

Public-private collaboration behind the shield

The Anti Phishing Shield was developed and tested through cooperation between multiple organizations. The initiative involved the Dutch Ministry of Justice and Security, the National Cyber Security Centre (NCSC), KPN, the police, the Dutch Banking Association, and NLconnect, the industry association for telecom and broadband providers.

Over time, additional internet service providers joined the effort, strengthening the pilot. These included SNLLR, TriNed, and Kabelnoord. Because the pilot showed promising outcomes, the partnership decided to continue the approach under the NCSC.

Protection available through opt-in with providers

The technical concept is designed so participating internet providers can integrate the service into their network. However, users must give explicit permission before the protection is enabled. In practice, this is done through an opt-in process.

That opt-in requirement was also part of the pilot. Only customers who consented received the additional protection when attempting to reach malicious domains. This helps ensure the service is applied intentionally and transparently, rather than automatically for everyone.

Why phishing is still such a big problem

The need for effective defenses is clear. According to Dutch statistics, in 2025 about 17% of people in the Netherlands—roughly 2.5 million individuals—became victims of online crime. Research referenced in the report also indicates that 91% of cyberattacks begin with phishing.

Phishing typically unfolds in three connected steps:

  • Approach: victims receive an email, SMS, or message that appears to come from a trusted organization such as a bank, government body, or web shop, often with an urgent request.
  • Manipulation: the message pressures the recipient to click a link or enter information on a website controlled by criminals and designed to look legitimate.
  • Abuse: once login credentials or payment information is stolen, attackers can take over accounts, make purchases, or move money.

Crucially, the pilot focuses on a point where technical intervention can prevent harm: the moment a user tries to reach a malicious link.

How the Anti Phishing Shield works (step by step)

The mechanism behind the Anti Phishing Shield centers on continuously identifying malicious domains and blocking them before they can load in a user’s browser.

1) Building and maintaining a denial list

The NCSC collects up-to-date information about domains being misused by criminals from both public and commercial sources. These suspicious domains are analyzed and then added to a denial list.

2) Sharing the list via DNS service

The denial list is distributed using a DNS service to participating internet providers. In the pilot, the NCSC updated the list every quarter. Over time, the list grew to include more than 160,000 malicious domains.

Importantly, the list is not static. Domains that are taken offline or no longer deemed malicious are removed, keeping the protection aligned with current threats.

3) Blocking at the customer level

Participating providers incorporate the shared list into their own systems and make the service available to customers at no cost. For users who opted in, the system automatically blocks access when they attempt to visit a domain on the denial list. This reduces the chance that people fall victim to phishing or other forms of online fraud.

Results from the pilot—and what happens next

The pilot’s impact—over two million blocked attempts—demonstrated that the Anti Phishing Shield can reduce access to harmful destinations for real users, not just in test environments. That success led the Ministry of Justice and Security and the NCSC to decide to keep the joint approach running.

At the same time, the ambition now is to broaden both reach and effectiveness. The report highlights two key paths for further improvement:

  • Increase coverage within participating providers by reaching more customers who can opt in.
  • Enable additional providers to join, so the service can protect a larger portion of the Dutch user base.

In the coming period, the partners will explore how to scale the solution step by step.

What opt-in means for everyday internet users

If you are a customer of a participating internet provider, you may be able to enable the Anti Phishing Shield through an opt-in process. When enabled, the protective DNS filtering aims to block access to known malicious domains automatically.

It’s designed to intervene precisely when you try to open a suspicious website—one of the key moments in a phishing chain. While phishing messages may still reach you through email or SMS, the shield helps reduce the likelihood that the next step—loading a dangerous destination—ends with stolen credentials or payment details.

Conclusion: A practical defense against the phishing “click”

The Anti Phishing Shield pilot shows what is possible when threat intelligence, DNS filtering, and provider integration work together. By blocking more than two million attempts to reach phishing and fraudulent websites for over 200,000 opted-in users since July 2025, the approach has proven its value.

With the service moving forward under the NCSC and plans to expand reach and effectiveness, the next phase will focus on bringing more providers on board and enabling more customers to use the protection. For individuals and families trying to stay safe online, this kind of targeted, technical barrier at the right moment can be an important step in reducing phishing harm.

Source: https://www.ncsc.nl/nieuws/ruim-twee-miljoen-bezoeken-aan-kwaadaardige-websites-voorkomen-in-pilot