Dutch national police breach exposes contact details of every officer
- Organization
- Dutch National Police
- Exploit
- Hacking
- Industry
- Government
The Dutch national police discovered on September 26, 2024 that attackers had stolen work contact details covering essentially the whole force, and made the theft public within days. Police chief Janny Knol told staff by email that names, work email addresses and work telephone numbers had been taken, and in some cases other personal data as well. Reporting put the number affected at about 62,000, with some accounts citing close to 63,000. The total covered civilian staff such as front desk and facilities employees as well as sworn officers.
The force said the theft followed the compromise of a police account but declined to explain how that account was taken over. ESET director Dave Maasland told NRC the breach could have begun with an officer falling for a phishing scam, or come from a clever hacker inside or outside the Netherlands, or from a foreign government. The police said they would withhold detail so as not to help the perpetrators or damage the ongoing inquiry.
In early October 2024, Justice Minister David van Weel told parliament that Dutch intelligence services considered it very likely that a state actor was responsible, meaning another country or people acting on its behalf. No country or group was named.
The police notified the Dutch data protection authority and said strong security measures had been taken in coordination with national security partners. Officers in covert and undercover roles raised concerns about being identified, and as of early October the stolen data had not surfaced publicly.