Menu
Browse

Cyber Incident Victim: Trust Krediet Beheer BV

Date:

Jan 2021

Location:

Netherlands

Summary

A cyber attack targeting Trust Krediet Beheer BV, a third-party collection agency servicing ANWB, potentially compromised personal data belonging to the organization's current and former members. The incident, which involved unauthorized access or encryption of files consistent with ransomware, did not directly breach ANWB's systems but exposed customer information handled by the agency. The breach was reported to Dutch data protection authorities and law enforcement, with affected individuals notified of the potential data exposure.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around January 7, 2021, Trust Krediet Beheer BV (TKB), a Dutch collection agency handling delinquent accounts for ANWB (Royal Dutch Touring Club), experienced a cyber attack resulting in potential unauthorized access to customer data. The attack involved encryption of TKB's files, consistent with ransomware or similar disruptive techniques, though the specific malware variant and initial attack vector were not publicly disclosed. ANWB clarified that its own internal systems remained uncompromised, confirming the breach originated solely within TKB’s infrastructure. The incident exposed personal data belonging to current and former ANWB members whose accounts had been referred to TKB for collections. While the exact scope of compromised records was not quantified publicly, the breach prompted immediate regulatory notifications.

Cyber Incident Image

ANWB proactively notified affected individuals via email shortly after discovering the incident, warning them of potential data exposure. The organization reported the breach to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and law enforcement agencies in accordance with legal obligations. TKB’s role as a third-party processor of sensitive financial and personal data underscored the supply chain risks inherent in outsourcing collections operations. No further technical details regarding containment measures, ransom demands, or data recovery efforts were disclosed in available public reporting. The incident highlighted operational disruptions at TKB and reputational impacts for ANWB, though specific financial losses or long-term consequences remained unconfirmed in source documentation.

Sources
Sources available to members
1 source