Why 95,000 Spaniards Called the 017 Cyber Helpline in Six Months

Spain’s national cybersecurity hotline, 017, handled 95,064 consultations in the first half of 2026 – almost double the 49,599 received in the same period a year earlier and nearly matching the total for all of 2024. The sharp rise was presented on Monday by Digital Transformation Minister Óscar López, who attributed the increase to growing public awareness of the free service, better digital literacy, and a widening variety of fraud tied to the expanding digital society.

Impersonation scams using phone calls (vishing), text messages (smishing) and email (phishing) were the single largest driver: they accounted for 40% of incidents reported by individuals and 30.6% of those from businesses. Among ordinary users, fraudulent online purchases made up 13% of queries, while plain identity theft represented 9.5%.

The report also highlights a sharp jump in financial and investment scams. Nearly 3,000 consultations about fake investments and cryptocurrencies were recorded in the six‑month period, a seven‑fold increase on the whole of 2022. Bank fraud cases quadrupled versus 2022 levels, and reports sparked by fake news and hoaxes climbed 175% compared with 2023.

On the corporate side, impersonation of brands and the creation of unauthorised social‑media profiles drove 20% of business consultations. The so‑called CEO fraud – where attackers pose as a senior executive to request money transfers or sensitive data – accounted for 9.8%. For minors, privacy and digital reputation queries represented 17.5% of contacts, now matched by sextortion cases at 17% for the first time since 2022, with identity theft at 10.7% and cyberbullying at 5%.

Advertisement

What the Fraud Surge Reveals About Spain’s Digital Landscape

The 017 Helpline as a Real‑Time Barometer

The doubling of calls is not necessarily a sign that cybercrime has doubled overnight; the minister’s argument that greater knowledge of the channel and higher awareness explain part of the spike is plausible. Nevertheless, the composition of complaints shows which fraud vectors are hitting hardest. Phone‑, SMS‑ and email‑based impersonation remains the most common weapon, reflecting how easily attackers exploit cheap, widely available spoofing tools and the sheer volume of communications that consumers struggle to verify.

A Surge in Investment and Bank Scams

The near‑3,000 investment‑ and crypto‑fraud consultations in six months – seven times the 2022 full‑year tally – signals that scammers are aggressively exploiting economic anxiety and the appeal of quick‑riches narratives. The simultaneous quadrupling of bank fraud cases points to a growing ability to bypass customer authentication, often using information gathered from phishing campaigns. Together they suggest a coordinated trend where criminals steal credentials, then target the victim’s savings or push them into fake investment platforms.

Minors Caught in Sextortion and Identity Theft

For the first time in several years, sextortion has become as prevalent as privacy‑reputation concerns among under‑18s, while identity theft and cyberbullying remain significant. This shift indicates that predators are now routinely using manipulated images or threats to extort money or more material from teenagers, a development that demands both parental education and specialist support within helplines like 017.

Government’s Multi‑Layer Regulatory Response

Spain’s response is not limited to the helpline. Telecoms operators have blocked more than 300 million fraudulent calls and 26.6 million SMS since the anti‑scam plan came into force on 7 March 2025. Two further technical measures are on the clock. On 15 September 2026, operators will start automatically blocking SMS that use an alias not registered with the national markets and competition authority (CNMC), so only messages from pre‑vetted, legitimate entities will reach phones. Then, from 17 October 2026, all commercial phone calls must use a nine‑digit number beginning with the prefix 400; any marketing call that lacks that prefix will be blocked at the network level. These steps will create a cleaner communication environment, but they also shift the obligation onto businesses to register in time and onto telecoms to implement the blocks without disrupting lawful traffic.

Advertisement

What Spanish Households and Businesses Should Do Ahead of September’s Tech Crackdown

For households
• Treat every unsolicited call, SMS or email that asks for personal or banking details as suspect. Even if the message appears to come from your bank or a delivery firm, go directly to the official website or app instead of clicking links.
• After 15 September 2026, any SMS that claims to be from a known company but is blocked or not received will likely be an invalid, spoofed message. If a legitimate alert goes missing, check your account directly.
• From 17 October 2026, all marketing calls must show the 400 prefix. If you receive a commercial call from any other number, you can assume it is fraudulent or unlawful; hang up and report it to 017.

For business owners and managers
• Verify that your company’s SMS sender alias is registered with the CNMC’s official database before the 15 September deadline, so customers continue to receive your transactional and marketing messages.
• Reinforce anti‑CEO‑fraud training: mandate a separate, out‑of‑band verification (e.g., a phone call to a known number) for any payment request that arrives by email or text, especially if it invokes urgency or a senior directive.
• Monitor the 400‑prefix rollout. If your business makes outbound sales calls, confirm with your telephony provider that the correct prefix will be applied from 17 October; otherwise your calls will be blocked and customer contact severed.

For investors and savers
• The seven‑fold jump in fake crypto and investment‑related queries is a clear warning: be extremely sceptical of “guaranteed” high returns, celebrity‑endorsed schemes or unsolicited investment offers received through social media or messaging apps. Check the CNMV’s warning lists before committing any money.

Risk & Opportunity Assessment

Commercial RiskHighTelecoms operators must implement network‑level blocking of unregistered SMS aliases and enforce the 400‑prefix rule by autumn 2026; technical failures or over‑blocking could disrupt legitimate business communications and lead to customer complaints or compensation claims.
Competitive RiskLowNo single competitor gains or loses material advantage from the regulatory changes, although banks and fintechs that adopt stronger anti‑fraud measures early may build trust.
Regulatory RiskCriticalMandatory blocking of unregistered SMS senders and the commercial‑call prefix create hard compliance deadlines; failure to register aliases or apply the prefix will result in blocked messages and calls, effectively cutting businesses off from customers and exposing them to non‑compliance action.
Reputation RiskHighBrand impersonation via SMS and unauthorised social‑media profiles now drives 20% of corporate consultations; companies whose brands are spoofed face direct consumer fraud losses and longer‑term erosion of customer confidence if they cannot quickly prove legitimacy.
Technology DisruptionLowThe mandated changes rely on proven network filtering and number‑range management; potential disruption arises from implementation glitches rather than new, untested technology.
Commercial OpportunityHighThe surge in fraud queries – especially investment, bank and impersonation scams – together with new compliance obligations open significant demand for cybersecurity awareness training, verification‑of‑identity services, and fraud‑detection tools for both consumers and corporate clients.