Ransomware continued to cause substantial harm to Dutch organizations in 2025, with attackers encrypting systems and increasingly stealing data for double extortion; some campaigns now steal data without deploying encryption. Dutch authorities warn that backups and cyber insurance do not eliminate the operational, financial, and privacy impact, and urge victims to report every incident—including those involving ransom payments—to police. Information sharing under the public-private Project Melissa partnership provided monthly visibility into ransomware incidents affecting the Netherlands and supports investigations, potential decryption opportunities, and suspect identification.
The threat remains driven primarily by preventable access failures rather than novel techniques: exploitation of unpatched vulnerabilities and compromised accounts are the leading intrusion paths. Earlier Dutch assessments recorded 178 successful ransomware attacks in 2023 affecting hundreds of organizations and millions of individuals; two-thirds of 90 examined victims lacked sufficient fundamentals such as MFA, strong password controls, timely patching, and network segmentation. Organizations should prioritize these controls, maintain tested and segregated backups, prepare and exercise incident-recovery procedures, and avoid paying ransoms, as payment neither guarantees recovery nor prevents further extortion.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
The 2025 ransomware overview found that many incidents combined encryption with theft of data for double extortion, while some actors extorted victims using stolen data without encrypting systems. Attacks affected systems, data stores, backups, removable media, and cloud-hosted data.
During 2025, the NCSC, Dutch Police, Public Prosecution Service, Cyberveilig Nederland, and private partners exchanged ransomware-incident information monthly under Project Melissa. The exchange was intended to improve visibility into the frequency and methods of attacks affecting Dutch organizations.
A Project Melissa-enabled analysis of ransomware attacks in the Netherlands during 2024 found no evidence of new ransomware deployment techniques. Exploitation of software vulnerabilities and account takeover remained the principal initial-access methods.
Among Dutch organizations hit by ransomware in 2023, 58% lacked a backup and 18% paid a ransom. The reported payment rate was below the cited global average of 46%.
The Dutch Data Protection Authority recorded 178 unique successful ransomware attacks in 2023, affecting hundreds of organizations and personal data belonging to millions of people. One incident affected more than 200 organizations simultaneously and involved data on 2.5 million people in the Netherlands.
Project Melissa identified an estimated 147 unique ransomware incidents involving Dutch organizations with more than 100 employees in 2023. Exploited vulnerabilities accounted for about 30% of initial access, while unauthorized logins accounted for 28%.
The public-private Project Melissa collaboration between Dutch law-enforcement, cybersecurity authorities, and private-sector partners began to improve information sharing and coordinated action against ransomware and cybercrime.
The Digital Trust Center became part of the Dutch National Cyber Security Centre.
The AP examined 90 organizations affected by ransomware and found that two-thirds had not adequately implemented baseline security measures, including multifactor authentication, sound password policies, timely patching, and network segregation. Nearly half said their incident involved double extortion.
The Melissa covenant established legal, organizational, and technical arrangements for structural public-private collaboration against ransomware and cybercrime in the Netherlands. The partnership cited earlier operations involving Deadbolt, Genesis Market, and Qakbot.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcepolitie.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.