Menu
Browse

Cyber Incident Victim: Netherlands

Date:

Jul 2022

Location:

Netherlands

Summary

A cyberattack targeted the software provider of five municipalities in Limburg, disrupting access to data systems handling social benefits, youth care, social support services, and energy allowances. While administrative functions were temporarily halted and required post-incident updates, municipal services remained largely operational through alternative communication channels like phone and email, with no direct impact reported on residents. A specialized cybersecurity firm investigated the breach, confirming no data theft occurred and systems were restored securely without ransom payments.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 27, 2022, a cyberattack targeted the software provider servicing five municipalities in the Dutch province of Limburg: Eijsden-Margraten, Gulpen-Wittem, Kerkrade, Meerssen, and Vaals. The attack disrupted access to critical municipal data systems, rendering information related to welfare benefits, youth care services, social support provisions under the Wet maatschappelijke ondersteuning (Wmo), and energy subsidies temporarily inaccessible. Municipal operations relying on these systems were partially interrupted, specifically impacting administrative functions such as processing or updating records. However, frontline citizen services remained largely operational, with residents still able to request assistance via phone or email for urgent matters like welfare payments. No evidence indicated data exfiltration or theft during the incident, according to official statements from the affected municipalities.

Cyber Incident Image

Immediate response measures included engaging a specialized cybersecurity firm to investigate the compromised systems following the attack’s detection. The investigation confirmed the integrity of the systems was restored, enabling safe reactivation without further disruption. Municipal representatives emphasized that no ransom payments were made to attackers throughout the incident. Administrative backlogs caused by the system outage were addressed through post-recovery data entry efforts, ensuring continuity in public service delivery. The municipalities reported no direct adverse effects on residents during or after the incident, attributing this outcome to contingency measures that maintained essential communications channels while technical remediation occurred.

Sources
Sources available to members
1 source