Dutch authorities arrested two 17-year-old boys on suspicion of attempting to conduct cyber espionage on behalf of Russian interests. The arrests took place after the Dutch General Intelligence and Security Service (AIVD) provided a tip to the police, leading to the apprehension of the suspects. The teenagers were reportedly recruited via the messaging app Telegram by pro-Russian hackers, who tasked them with carrying out reconnaissance activities. Their assignment involved using a WiFi sniffer device to collect information by walking past sensitive buildings in The Hague, including the headquarters of Europol, Eurojust, and several embassies such as the Canadian embassy. WiFi sniffers are devices capable of intercepting wireless network traffic and are often used in the early stages of cyberattacks to gather intelligence on potential targets. Europol confirmed awareness of the incident and stated that there was no evidence of compromise to their systems, emphasizing the robustness of their security infrastructure. The agency is working closely with Dutch authorities to monitor and address any potential risks arising from the incident. One of the suspects was arrested at home while reportedly finishing his homework, with his parents unaware of his alleged involvement in espionage activities. The severity of the charges means that at least one of the boys will remain in custody for two weeks as the investigation continues, while the other has been released on home bail. The Dutch prosecution service cited laws regarding state-sponsored interference as the basis for the arrests but withheld further details due to the suspects' ages and the ongoing nature of the investigation. This case is seen as an escalation from previous incidents in Europe, where young people were recruited by Russian agents for acts of sabotage and vandalism rather than direct espionage. The Dutch government has recently expanded its laws against cyber-espionage, reflecting growing concerns about state-sponsored cyber activities. The incident highlights the increasing trend of minors being targeted for recruitment by foreign intelligence services through online platforms. The use of simple but effective reconnaissance tools like WiFi sniffers demonstrates the evolving tactics employed in modern espionage operations. The case has raised concerns among parents and the broader community about the risks posed by online recruitment for cyber activities. Authorities continue to investigate the full extent of the teenagers' actions and any potential connections to broader Russian cyber operations. The incident underscores the importance of vigilance and robust security measures around critical infrastructure and international organizations in the Netherlands.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Dutch prosecutors disclosed that Russian hackers allegedly paid the arrested 17-year-old boy for espionage activities. This adds a new detail about the operational relationship between the suspect and the pro-Russian actors behind the case.
Subsequent reporting said the teens were allegedly recruited via Telegram and were suspected of working for pro-Russian hackers or Russia-backed operators. The disclosures added attribution and tradecraft details to the case beyond the initial arrest reports.
Dutch authorities arrested two teenagers, ages 17 and 18, on suspicion of conducting espionage activities in the Netherlands on behalf of pro-Russian actors. Reports say the case involved cyber-espionage and surveillance-related tasks, including alleged Wi-Fi sniffing and attempts to gather intelligence tied to Europol.
8 references tracked. Mallory keeps watching after this page renders.
nos.nl
Open sourcebitdefender.com
Open sourcego.theregister.com
Open sourcesecurityaffairs.com
Open sourcehackread.com
Open sourcebleepingcomputer.com
Open sourcenos.nl
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.