Dutch cybersecurity companies have issued warnings to thousands of companies about a global ransomware attack. The attackers, known as the Cactus Gang, are from Eastern Europe and have been active since the end of last year.
The cybercriminals managed to penetrate the security systems of 122 companies, and at least 10 of those are in the Netherlands. The security experts exchanged information regarding the matter, and discovered that victims were being attacked in the same way every time. The four companies shared their findings with the Dutch authorities. There are around 5,200 Qlik Sense servers in use worldwide, of which around 3,100 are vulnerable.
Read more…
Source: NL Times
Related:
- Operation KillSwitch: Teenager suspected of leading KillSec ransomware group
October 1, 2026
On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom. The action was part of Operation KillSwitch, an international investigation led by German ...
- Dutch police arrest ‘security researcher’ in ShinyHunters probe
September 29, 2026
Dutch police have arrested a 24-year-old man on suspicion of involvement with the prolific ShinyHunters cybercrime group. Cops announced the arrest on Monday night and said the Amsterdam resident would appear before judges at Rotterdam District Court today (Tuesday). Officers have not named the suspect. However, a company has identified a person they believe to be the ...
- Iranian Cyber Targeting of Dissidents, Activists and Journalists
September 15, 2026
CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. CHOSEN BRICK enables Iranian state cyber actors to collect information on a target’s contacts, emails and social media messages, which could enable tracking of their movements. Iran almost ...
- EU-UK sanctions target Russia over Europe-wide ‘vast cyber campaign’
July 13, 2026
The European Union and the UK have announced coordinated sanctions against Russia after accusing Moscow’s FSB intelligence agency of carrying out a cyber attack in December targeting Poland’s energy grid and orchestrating a wider campaign of digital sabotage across Europe. The joint measures focus on individuals and organisations linked to Russia’s security services, with the EU ...
- Supermarket chain Lidl warns customers after data leak
July 10, 2026
Unknown individuals managed to gain access to customer data held by the supermarket chain Lidl. The German company informed affected customers of this via email this week. Thus far, the supermarket chain has declined to say how many customers were affected. However, the discount retailer did state that it has notified the Dutch Data Protection Authority. Read ...
- Dutch cops wrest 17M devices from mystery botnet’s clutches
May 29, 2026
Dutch police say they dismantled a large botnet this week comprising at least 17 million infected devices. After being tipped off by a researcher at the Netherlands’ National Cyber Security Centre (NCSC-NL), police began an investigation, which resulted in the discovery of 200 servers underpinning the botnet’s infrastructure located in the country. Cybercrime specialists at The Hague ...
