A Dutch appeals court sentenced a 44-year-old man to seven years in prison for hacking into the computer systems of a major Belgian port company, facilitating the smuggling of 210 kilograms of cocaine into the Netherlands. The court found that the individual played a central technical role in a criminal network that exploited port systems in 2020 and 2021, using malware delivered via a USB stick by a compromised port employee to create a digital backdoor, granting remote access to sensitive logistics and security controls.
Forensic analysis revealed that the malware remained active for months, allowing the hacker to issue access passes, interfere with gate operations, and exfiltrate sensitive information such as camera locations and terminal layouts. Investigators relied on intercepted Sky ECC encrypted messages, which included step-by-step instructions for deploying the malware and evidence of the hacker's control over port operations. The sentencing underscores the growing intersection of cybercrime and physical smuggling operations targeting critical infrastructure in Europe.

See the reporting duties and controls this puts on the clock.
10 events from the most recent confirmed update back to the earliest known activity.
Following the January 2026 appellate decision, the defendant appealed again while remaining in custody in the western Netherlands. This extended the legal proceedings after the reduced sentence was imposed.
On January 12, 2026, the Dutch appeals court reduced the prison term from 10 years to seven, citing the lengthy appeal process among the reasons for mitigation. The court also upheld convictions related to attempted extortion, including a €1.2 million demand.
On January 12, 2026, the Amsterdam Court of Appeal rejected the defendant's objections to the Sky ECC evidence and upheld most of the convictions. The court dropped one allegation involving the import of 5,000 kilograms of cocaine but maintained the remaining findings.
In 2022, the defendant was convicted on charges including computer hacking and attempted extortion tied to drug trafficking, and received a 10-year prison sentence. He appealed the ruling, challenging the use of intercepted Sky ECC communications as evidence.
Forensic evidence showed the implanted backdoor remained active until at least April 24, 2021. During that period it continued to access targeted systems and attempt privilege escalation.
In 2021, Europol's compromise of the encrypted Sky ECC service gave investigators access to messages that became central evidence in the case. The intercepted chats allegedly showed the defendant directing malware deployment and describing his control over port functions.
Between September 2020 and April 2021, authorities said the defendant also tried to sell the malware and guidance for using it to others. This activity was treated as part of the broader criminal operation around the port intrusions.
During 2020 and 2021, prosecutors said the compromised port systems were used to facilitate drug trafficking into the Netherlands, including the import of 210 kilograms of cocaine through the Port of Rotterdam. The court also linked the defendant to organizing a shipment concealed in wine bottles aboard the Callao Express.
From late 2020 into early 2021, the group used the malware to persist in port-related systems in Antwerp, Rotterdam, and Barendrecht, repeatedly attempting to gain administrator privileges. Investigators said the access enabled theft of operational and security information, including terminal layouts, camera locations, access-pass data, and gate functions.
On September 18, 2020, a port employee inserted a malware-laced USB stick at a container terminal in Antwerp, installing a backdoor used by a criminal network. The intrusion gave attackers access to port systems and the Solvo container management application.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourceuitspraken.rechtspraak.nl
Open sourcetherecord.media
Open sourcedatabreaches.net
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.