Lyce · Hybrid Watch

hw_de49f07f33db0f4e

Cyber-attack on Dutch police and NATO-linked networks by Russian-supported hackers.

According to a joint advisory by the Algemene Inlichtingen‑ en Veiligheidsdienst (AIVD) and the Militaire Inlichtingen‑ en Veiligheidsdienst (MIVD), a previously unknown Russian state-sponsored hacker group, referred to as Laundry Bear, accessed the work-related contact details of nearly all Dutch police employees and succeeded in infiltrating networks linked to NATO systems. The Dutch services stated that the group is strongly suspected of aiming to collect sensitive information about weapons procurement by Western governments and defence supply chains. Although the breach did not yet result in major kinetic damage, it marks a clear escalation: from espionage-style access to infrastructure and defence-related systems toward capabilities that may enable sabotage. The Netherlands is highlighted not just as a logistical hub but as a direct target of Russian hybrid operations, beyond simply being a host to forward infrastructure. The dynamics show how adversaries use low-visibility digital intrusions into defence and law-enforcement networks to set the stage for later disruption.

Occurrence
2024-09-23
Publication
2024-09-22T22:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
NL
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2024-09-22T22:00:00Z

    According to a joint advisory by the Algemene Inlichtingen‑ en Veiligheidsdienst (AIVD) and the Militaire Inlichtingen‑ en Veiligheidsdienst (MIVD), a previously unknown Russian state-sponsored hacker group, referred to as Laundry Bear, accessed the work-related contact details of nearly all Dutch police employees and succeeded in infiltrating networks linked to NATO systems. The Dutch services stated that the group is strongly suspected of aiming to collect sensitive information about weapons procurement by Western governments and defence supply chains. Although the breach did not yet result in major kinetic damage, it marks a clear escalation: from espionage-style access to infrastructure and defence-related systems toward capabilities that may enable sabotage. The Netherlands is highlighted not just as a logistical hub but as a direct target of Russian hybrid operations, beyond simply being a host to forward infrastructure. The dynamics show how adversaries use low-visibility digital intrusions into defence and law-enforcement networks to set the stage for later disruption.