Authored By: Valerie Iqlima Raihaana
Universitas Indonesia
Case Citation
Criminal judgment of the District Court of North Netherlands, ECLI:NL:RBNNE:2026:1116, decided on 9 April 2026.
Introduction
On April 9, 2026, the District Court of North[1] Netherlands delivered a major criminal judgment in case ECLI:NL:RBNNE:2026:1116. Operating at the intersection of criminal law, financial fraud, and cybercrime, this ruling addresses a sophisticated multi-year criminal enterprise involving bank helpdesk fraud, unauthorized system access, and massive cryptocurrency laundering. The case is particularly noteworthy due to the sheer scale of the operation and the perpetrator’s persistence. Remarkably, the defendant even directed third parties to drain crypto wallets from inside a penitentiary institution post-arrest. The judgment is particularly notable for prioritizing victim compensation over state seizure.
III. Facts of the Case
Between late 2021 and early 2025, the defendant engaged in a prolonged, multi-faceted cyber-fraud and money laundering operation targeting bank account holders across the Netherlands. Operating in concert with unidentified co-conspirators, the defendant systematically obtained victim lead lists containing personal identification data and purchased specialized software, including remote access tools (AnyDesk) and communication scripts designed to execute bank helpdesk fraud (bankhelpdeskfraude).
The scheme operated through a distinct operational pattern. The defendant or his co-conspirators contacted victims while impersonating bank security personnel, falsely convincing them that their bank accounts were at risk of cyber threats. Victims were instructed to install remote access software, allowing the perpetrators to gain unauthorized entry to their online banking environments. Using stolen credentials and false security keys, they transferred funds to intermediary accounts before converting them into cryptocurrency, such as Bitcoin.
Over the course of the operation, the scheme defrauded numerous victims of approximately €890,000 in direct bank transfers. To conceal the origin and movement of these illicit proceeds, the defendant established an extensive network of digital wallets. Between September 2022 and January 2025, he received, moved, and converted over €6.5 million in digital assets and nearly €400,000 in fiat currency, executing thousands of layered transactions across multiple cryptocurrency platforms.
Following an extensive law enforcement investigation into the financial trail, authorities arrested the defendant. However, while detained in a penitentiary institution, the defendant maintained contact with external parties to secure his assets. On January 11 and 12, 2025, using illicitly accessed communication channels from within prison, he directed third parties outside the facility to transfer and drain remaining cryptocurrency balances from targeted wallets to prevent their seizure by law enforcement. On January 13, 2025, judicial authorities formally executed orders seizing the involved digital wallets and associated luxury assets.[2]
Legal Issues
Issue 1 (Procedural Nullity / Ne Bis In Idem) Whether Count 3 of the indictment is partially void or inadmissible under the principle of double jeopardy (ne bis in idem), given that Count 1 already charges the defendant with habit-based money laundering of cryptocurrency across an overlapping time period.[3]
Issue 2 (Criminal Liability for Cyber-Fraud and Money Laundering) Whether the defendant’s actions, specifically acquiring remote access tools and lead lists, impersonating bank officials, unlawfully accessing banking systems, and converting stolen funds into digital assets, satisfy the statutory elements of computer intrusion (computervredebreuk), grand theft via false key (diefstal met valse sleutel), fraud (oplichting), and habitual money laundering (gewoonte-witwassen) under Articles 138ab, 311, 326, and 420ter of the Dutch Criminal Code.[4]
Issue 3 (Prioritization of Victim Compensation over State Forfeiture) Whether, upon ordering the forfeiture of seized criminal assets, the court can legally instruct the executing authority to prioritize satisfying victim compensation orders (schadevergoedingsmaatregelen) prior to remitting any residual funds to the State Treasury.[5]
Argument Presented
5.1 Public Prosecutor’s Arguments (Prosecution)
The Public Prosecution Service (Openbaar Ministerie) argued for a full conviction across all charged counts, emphasizing the structured and continuous nature of the defendant’s criminal operation:
Criminal Enterprise and Cyber-Fraud: The prosecution argued that the evidence established every element of computer intrusion, theft, fraud, and habitual money laundering. They established that stolen funds from victims were routed through intermediary accounts (such as Bunq and Modulr Finance) directly into digital asset wallets linked to the defendant, satisfying the legal elements of computer intrusion (computervredebreuk under Article 138ab Sr), grand theft via false keys (diefstal met valse sleutel under Article 311 Sr), and fraud (politicking under Article 326 Sr).[6]
Habitual Money Laundering: The prosecution argued that converting stolen fiat currency into crypto assets totaling over €6.5 million constituted habitual money laundering (gewoonte-witwassen under Article 420ter Sr).[7]
Distinct Post-Arrest Acts: Regarding Count 3, the prosecution maintained that the unauthorized transfers executed on January 11 and 12, 2025 wherein the defendant instructed third parties from inside a penitentiary institution to drain savings wallets were distinct acts not encompassed by Count 1. They submitted that Count 1 covered outgoing Bitcoin transactions up to December 25, 2024, and general possession prior to official asset seizures on January 13, 2025.[8]
5.2 Defense’s Arguments
The defense raised specific procedural and evidentiary challenges to mitigate liability and invalidate parts of the indictment:
Procedural Challenge (Ne Bis In Idem): The defense counsel argued that Count 3 of the summons should be declared partially void or inadmissible. They contended that the alleged draining of crypto wallets under Count 3 constituted the exact same factual complex and offense, laundering digital currencies already charged under Count 1. Punishing or prosecuting both counts would violate the double jeopardy principle (ne bis in idem).
Evidentiary Objections: The defense challenged the direct attribution of certain fraud incidents and wallet transactions to the defendant, asserting a lack of definitive technical proof connecting him to every specific transaction or intermediary account identified in the financial trail.
Court’s Reasoning and Analysis
The District Court of North Netherlands structured its analysis around three core areas: the procedural integrity of the indictment under double jeopardy rules, the statutory attribution of cyber-fraud and laundering offenses, and the equitable execution of asset forfeiture.
Regarding the procedural challenge (ne bis in idem under Article 68 of the Dutch Criminal Code), the court rejected the defense’s motion to declare Count 3 partially void. The defense argued that directing third parties from prison on January 11 and 12, 2025, to drain crypto wallets constituted the same continuous money laundering complex as Count 1. However, the court distinguished these acts chronologically and conceptually. Count 1 addressed systematic outgoing transfers up to December 25, 2024, and general possession leading to official asset seizures on January 13, 2025. The court held that the post-arrest instructions given from inside the penitentiary were separate, intentional acts aimed at actively frustrating impending law enforcement seizures. Because these transactions constituted distinct operational conduct rather than a single continuous offense, prosecution under both counts did not violate double jeopardy principles.
On the substantive criminal charges, the court held that the evidence established each statutory element of computer intrusion, theft, fraud, and habitual money laundering. The subsequent unauthorized entry into victim accounts and generation of transaction keys fulfilled the legal requirements for theft via false keys and computer intrusion. Furthermore, the court determined that converting stolen fiat into digital currencies across thousands of layered transactions satisfied the threshold for gewoonte-witwassen (habitual money laundering). The sheer volume over €6.5 million in crypto and the systematic concealment of illicit origins demonstrated an ongoing criminal practice rather than isolated instances of laundering.[9]
For the exact purpose of determining penalties and asset disposal, the court carefully balanced public deterrence against victim restitution. Recognizing the profound financial and psychological harm inflicted on victims of bank helpdesk fraud, the court exercised its discretionary sentencing power to align criminal forfeiture with civil restitution.[10] While ordering the forfeiture of seized digital and physical assets to the State under Article 33a of the Dutch Criminal Code, the court explicitly instructed the executing authority (Centraal Justitieel Incassobureau) to prioritize satisfying individual victim compensation orders (schadevergoedingsmaatregelen) before any remaining funds revert to the State Treasury. This logical progression ensured that state asset recovery did not displace or undermine the primary right of victims to be made whole.[11]
VII. Judgment and Ratio Decidendi
The District Court of North Netherlands (Rechtbank Noord-Nederland) found the defendant guilty on all counts, including computer intrusion (computervredebreuk), grand theft via false key (diefstal met valse sleutel), fraude (oplichting), and habitual money laundering (gewoontewitwassen). On the procedural issue, the court rejected the defense’s plea of double jeopardy (ne bis in idem), holding Count 3 fully admissible alongside Count 1.
As a remedy, the court sentenced the defendant to seven years’ imprisonment (84 months) with credit for pre-trial detention. Furthermore, the court granted full victim compensation orders (schadevergoedingsmaatregelen) for all injured civil parties, accompanied by default custody (gijzeling) in case of non-payment. The court further ordered that forfeited assets be used first to satisfy victim compensation before any remainder passed to the State.[12]
The court held that post-arrest transfers constituted separate laundering acts and that victim compensation must take priority over seizure assets. Additionally, in asset forfeiture proceedings under Article 33a of the Dutch Criminal Code involving multi-victim cyber-fraud, the execution of forfeiture orders must prioritize satisfying victim compensation orders before reverting residual proceeds to the State.[13]
Distinction from Obiter Dicta: The court’s remarks concerning the growing social disruption caused by bank helpdesk fraud and the systemic vulnerabilities in third-party digital payment platforms serve as contextual commentary (obiter dicta) on sentencing severity and public policy, rather than binding legal principles necessary to resolve the charges.[14]
VIII. Critical Analysis
8.1 Significance of the Decision
This judgment makes a landmark contribution to Dutch criminal jurisprudence by clarifying the operational boundaries of ne bis in idem in the context of cyber-enabled financial crimes and cryptocurrency dissipation. The judgment clarifies the scope of ne bis in idem in cybercrime prosecutions.
8.2 Implications and Impact
Law enforcement and prosecutors validate charging strategies that treat separate transaction sequences as distinct offenses, enhancing prosecutorial leverage against multi-layered crypto operations. For prison administration, the case exposes severe security vulnerabilities regarding inmate access to communication channels used to execute high-value financial crimes from behind bars, likely prompting stricter surveillance of penitentiary communications. Crucially for victims of bank helpdesk fraud, the mandatory prioritizing of forfeited crypto assets for victim restitution sets a progressive administrative precedent for the Central Judicial Collection Agency (CJIB), ensuring state recovery does not frustrate civil redress.
8.3 Critical Evaluation
The primary strength of the court’s reasoning lies in its pragmatic approach to digital financial reality. By tracing blockchain transactions alongside real-world custodial events, the court refused to let technical complexity obscure criminal intent. However, the decision exhibits potential analytical friction regarding the line between a single continuous act and separate offenses under Dutch money laundering statutes. Defense advocates could argue that treating every discrete crypto transfer as a standalone offense risks over-prosecution where transactions form part of a single, overarching intent to retain control. Nevertheless, the court’s pragmatic balancing, punishing persistent criminal behavior while safeguarding victim remedies offers a robust, logically coherent framework for handling complex cyber-fraud cases in contemporary legal practice.
Conclusion
This judgment by the District Court of North Netherlands (ECLI:NL:RBNNE:2026:1116) penalizes a multi-million-euro bank helpdesk fraud operation involving systematic computer intrusion and extensive cryptocurrency laundering. The central takeaway is that cross-border, decentralized digital asset networks do not shield perpetrators from domestic judicial reach or procedural accountability. The decision establishes an important precedent by prioritizing victim compensation in cyber-fraud asset seizure . Looking forward, the judgment leaves critical questions regarding international jurisdictional enforcement. Specifically, how domestic courts can effectively compel the cross-border recovery and extradition of offshore-hosted digital wallets without broader multilateral treaties.
Bibliography & Table of Authorities
1. Table of Cases
Netherlands
Rechtbank Noord-Nederland 9 April 2026, ECLI:NL:RBNNE:2026:1116 (Case No 18.137839.24)
2. Table of Legislation
Netherlands Codes & Acts
Wetboek van Strafrecht (Dutch Criminal Code)
art 33a (Forfeiture of criminal assets).
art 57 (Concurrence of criminal acts).
art 63 (Sentencing upon multiple convictions).
art 68 (Ne bis in idem / Double jeopardy).
art 138ab (Computer intrusion / Computervredebreuk).
art 234 (Possession of cybercrime tools).
art 311 (Grand theft via false key / Diefstal met valse sleutel).
art 326 (Fraud / Oplichting).
art 420bis (Money laundering / Witwassen).
art 420ter (Habitual money laundering / Gewoonte-witwassen).
Wetboek van Strafvordering (Dutch Code of Criminal Procedure)
art 36f (Victim compensation measure / Schadevergoedingsmaatregel).
3. Secondary Sources & Official Databases
De Rechtspraak, ‘Uitspraak ECLI:NL:RBNNE:2026:1116’ (Rechtbank Noord-Nederland, 9 April 2026) https://uitspraken.rechtspraak.nl/details?id=ECLI:NL:RBNNE:2026:1116 accessed 30 July 2026.
[1]Rechtbank Noord-Nederland 9 April 2026, ECLI:NL:RBNNE:2026:1116.
[2]Rechtbank Noord-Nederland 9 April 2026, ECLI:NL:RBNNE:2026:1116.
[3]Wetboek van Strafrecht (Dutch Criminal Code), art 68; Wetboek van Strafrecht, art 420ter.
[4]Wetboek van Strafrecht, arts 138ab, 311, 326, 420ter.
[5]Wetboek van Strafrecht, art 33a; Wetboek van Strafvordering (Dutch Code of Criminal Procedure), art 36f.
[6]Rechtbank Noord-Nederland 9 April 2026, ECLI:NL:RBNNE:2026:1116, para 4.1; Wetboek van Strafrecht, arts 138ab, 311, 326.
[7]Wetboek van Strafrecht, art 420ter.
[8]Rechtbank Noord-Nederland 9 April 2026, ECLI:NL:RBNNE:2026:1116, para 3.
[9]Wetboek van Strafrecht, art 68; Rechtbank Noord-Nederland 9 April 2026, ECLI:NL:RBNNE:2026:1116, para 3.
[10]Rechtbank Noord-Nederland 9 April 2026, ECLI:NL:RBNNE:2026:1116, para 4.2; Wetboek van Strafrecht, arts 138ab, 311, 326, 420ter.
[11]Wetboek van Strafrecht, art 33a; Rechtbank Noord-Nederland 9 April 2026, ECLI:NL:RBNNE:2026:1116, para 2.
[12]ibid para 2; Wetboek van Strafrecht, arts 57, 63, 138ab, 234, 311, 326, 420bis, 420ter.
[13]Rechtbank Noord-Nederland 9 April 2026, ECLI:NL:RBNNE:2026:1116, paras 2–3.
[14]Wetboek van Strafrecht, art 33a.

