Two 17-year-olds were arrested in the Netherlands in late September on suspicion of conducting reconnaissance for pro-Russian hackers by capturing Wi-Fi signals near sensitive locations in The Hague. The teenagers, equipped with Wi-Fi sniffing devices, followed a route that took them past high-profile sites including Europol, Eurojust, and the Canadian embassy. Dutch media reported that the arrests were prompted by a tip from the General Intelligence and Security Service (AIVD), which led to one teen being taken into custody and the other placed under home monitoring as the investigation continues. The teenagers were allegedly recruited through Telegram, where they were approached by individuals posing as peers. Security analysts have raised concerns that nation-state actors are increasingly using messaging platforms such as Telegram, Signal, and WhatsApp to recruit teenagers for low-skill reconnaissance tasks. The recruitment process often begins with seemingly innocuous conversations before escalating to requests for device access and credential theft. Sarah Ralston, vice president at Proxyware, noted that bad actors specifically target teens and young adults for phishing and malware attacks, sometimes turning their personal devices into espionage tools without their knowledge. Dutch Prime Minister Dick Schoof commented that the incident aligns with Russia's hybrid warfare tactics and expressed deep concern over the exploitation of minors for espionage activities. The case highlights a growing trend of nation-state cyber operations leveraging social engineering to involve unwitting young people in intelligence gathering. Security experts warn that children from military families may be particularly vulnerable to such recruitment efforts. The use of low-skill operatives for physical reconnaissance around sensitive government and international organization sites represents an evolution in cyberespionage tactics. Law enforcement and intelligence agencies are now on heightened alert for similar recruitment and reconnaissance activities. The incident underscores the need for increased awareness and education among young people about the risks of online interactions with unknown individuals. It also raises questions about the adequacy of current security measures around critical infrastructure and diplomatic sites. The ongoing investigation may reveal further details about the extent of the operation and whether additional individuals were involved. Authorities are also examining the technical methods used for Wi-Fi signal capture and the potential for data exfiltration. The case serves as a warning to organizations and families about the evolving tactics of nation-state cyber actors and the importance of proactive defense and monitoring.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
By October 2025, Dutch Prime Minister Dick Schoof and cybersecurity experts publicly warned that nation-state actors were increasingly recruiting teenagers through platforms such as Telegram, Signal, WhatsApp, Discord, and gaming environments for low-skill espionage tasks. The case heightened concern about minors, including children of military families, being groomed for hybrid cyber operations and credential theft.
In late September 2025, Dutch authorities arrested two 17-year-olds in The Hague for allegedly conducting Wi-Fi reconnaissance near sensitive sites including Europol, Eurojust, and the Canadian embassy. Prosecutors reportedly treated the case as government-sponsored interference and said the teens had been equipped with Wi-Fi sniffers and recruited via Telegram by pro-Russian hackers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.