Dutch authorities have arrested two teenagers in the Netherlands who were reportedly recruited by pro-Russian hackers via Telegram to assist with cyber espionage operations. The teenagers were allegedly tasked with collecting Wi-Fi data along a route in The Hague that passed by sensitive locations, including Europol, Eurojust, and the Canadian embassy. This marks a new tactic by Russian intelligence agencies, which have previously relied on remote cyber operations or dispatched their own operatives for on-site activities. The recruitment of local proxies for cyber espionage is a recent development, although Russian intelligence has a history of using locals for other activities such as sabotage, surveillance, and even graffiti. The use of domestic proxies is seen as a cost-effective and lower-risk method for certain tasks, though it may not match the technical proficiency of trained Russian operatives. In 2018, Dutch authorities arrested four members of Russia’s GRU Unit 26165 for attempting to hack the Wi-Fi of the Organisation for the Prohibition of Chemical Weapons (OPCW) in The Hague, highlighting a precedent for on-site operations when remote compromise fails. The OPCW was at the time investigating the chemical weapons attack on Sergei Skripal and his daughter, making it a high-value target for Russian intelligence. Russian operatives have also conducted similar on-site operations targeting US and international anti-doping and sporting organizations in locations such as Rio de Janeiro and Lausanne. The typical goal of these operations is to gain initial access to target networks by subverting Wi-Fi infrastructure, after which long-term data collection is managed by teams in Russia. The recent case involving Dutch teenagers suggests an evolution in Russian tactics, leveraging local assets for reconnaissance and initial access. Authorities believe that mapping Wi-Fi networks in areas of interest could provide Russian intelligence with a strategic advantage for more sophisticated attacks. The recruitment of teenagers for such tasks raises concerns about the exploitation of vulnerable individuals and the potential for increased operational security risks. Law enforcement agencies across Europe are now on alert for similar recruitment efforts by foreign intelligence services. The incident underscores the persistent threat posed by Russian cyber espionage and the adaptability of its tactics. Security professionals are advised to monitor for unusual activity near sensitive facilities and to strengthen Wi-Fi security protocols. The use of local proxies may complicate attribution and detection efforts, making international cooperation among law enforcement and intelligence agencies even more critical. This case also highlights the importance of public awareness and education to prevent the recruitment of unwitting individuals into foreign espionage activities. The evolving nature of cyber espionage operations demands continuous vigilance and adaptation by both government and private sector security teams.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Dutch authorities arrested two teenagers accused of carrying out on-site espionage tasks for pro-Russian operators, including activities such as mapping Wi-Fi networks near high-value targets. The case highlighted the use of local proxies by foreign intelligence services for plausible deniability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.