Dutch police suffered a major data theft attributed to a Russian cyber group after attackers gained access via an employee’s email account and exfiltrated sensitive personnel information. Stolen data reportedly included the contact details of nearly all ~65,000 police officers, along with profile photos and other personal data, triggering significant internal unrest and concern about officer safety and privacy.
Investigative reporting indicates the organization had been warned in advance about security weaknesses relevant to the intrusion path. Documents obtained under the Netherlands’ Open Government/Woo framework describe an internal November 2022 risk analysis that raised concerns about the implementation and security of Microsoft’s M365 cloud (used for tools such as Teams), explicitly noting “inherent” cloud risks and that state actors would be highly motivated to access the environment. Following the 2024 theft, police reportedly stood up a heavy crisis response structure (the Nationale Staf Grootschalig en Bijzonder Optreden) to reduce immediate risk and implement additional security measures, while political and union voices characterized the incident as severe and questioned why earlier warnings were not acted upon.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Follow the Money reported that Dutch police had been warned about the security weakness exploited in the major 2024 data theft, based on documents obtained under the Open Government Act. The reporting connected the earlier 2022 risk analysis to the later breach and highlighted the sensitivity of the exposed officer data.
In September 2024, a Russian cyber group reportedly accessed the Dutch police environment through an employee's email account and exfiltrated a large volume of police data. The stolen information included contact details for nearly all 65,000 police officers, along with profile photos and other personal data.
An internal Dutch police risk analysis reportedly identified implementation and security risks in the police's Microsoft 365 cloud environment, warning that state actors would be especially interested in accessing it. The analysis said the cloud carried inherent risks and raised concerns years before the later breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourceftm.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.