CSIDB logo
Threat actor

AIVD

Attribution profile

Type
Nation State
Location
Netherlands
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-31 01:00
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as AIVD is the domestic intelligence service of the Netherlands. It operates under the alias AIVD, which stands for the Algemene Inlichtingen- en Veiligheidsdienst. Based in the Netherlands, AIVD functions as a state‑run organization tasked with collecting intelligence to protect national security. The service is referenced in open‑source reporting as the Dutch domestic intelligence agency.

According to the article, AIVD gained access to the Russian hacking group Cozy Bear beginning in mid‑2014 and maintained that access for at least a year. During this period, Dutch officials observed Cozy Bear’s intrusions into the Democratic National Committee and other targets, including a 2014 breach of the U.S. State Department. The information came from local media outlets that reported the Dutch agencies had provided crucial intelligence about Russia’s interference in U.S. elections. The Washington Post published the story on January 26, 2018, citing those Dutch media reports.

The intelligence gathered allowed the Dutch government to alert the United States about Russian interference in the 2016 presidential election, indicating that AIVD’s primary objective in this context was espionage‑focused information collection. The source does not attribute any financial motive or disruptive intent to AIVD’s activities in this case. Instead, the emphasis is on the collection and sharing of strategic intelligence regarding foreign cyber operations.

Attribution is clear: AIVD is an organ of the Dutch government, establishing a direct state nexus, with no indication of criminal consortium affiliation or private‑sector ties in the provided material. The article does not describe any specific malware families, initial access vectors, or tooling styles employed by AIVD itself; it only notes that the service was able to monitor the activities of Cozy Bear. Consequently, no details about AIVD’s own technical tactics, techniques, or procedures are available from the source. A notable outcome of this monitoring was the early warning shared with American authorities, which contributed to the broader understanding of the 2016 election interference episode and highlighted the 2014 State Department hack as part of the observed campaign.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB