Cyber Incident Victim: Dierenkliniek Dijkstra
Date:
Jan 2022
Location:
Netherlands
Summary
A veterinary clinic experienced a cyberattack resulting in prolonged operational disruption, forcing systems offline for multiple weeks. The clinic's owner reluctantly paid a ransom to restore access, despite personal objections, due to the absence of viable alternatives. The incident severely impacted daily operations and client services, highlighting the coercive nature of such attacks. Recovery efforts remained ongoing as the organization worked to regain full functionality while addressing the ethical and practical challenges posed by the extortion demand.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The Dierenkliniek Dijkstra veterinary clinic in Arnhem suffered a cyberattack around January 2022 that forced its systems offline for multiple weeks. Hackers compromised the clinic's digital infrastructure, disrupting all operations dependent on networked technology. The attack rendered the business unable to access critical systems required for daily functions, causing sustained operational paralysis. Clinic owner Peter van der Velden publicly confirmed the incident on January 21, 2022, revealing the severity of the disruption. The clinic faced complete technological incapacitation, with no indication of when systems might be restored through conventional recovery methods. This extended downtime created significant challenges for delivering veterinary services and managing administrative tasks.

Van der Velden ultimately decided to pay the ransom demanded by the attackers despite personal objections to the principle of rewarding criminal behavior. He stated the payment "went against my feelings" but acknowledged having no viable alternative to restore operations. The financial transaction occurred under duress as an emergency measure to regain system functionality. No details were disclosed regarding the ransom amount, payment method, or whether data recovery succeeded post-payment. The incident highlighted the ethical and operational dilemmas facing small businesses targeted by cybercriminals, particularly when critical infrastructure remains inaccessible through legal remediation channels. The clinic's experience demonstrated how prolonged system outages can force organizations into compromising positions contrary to their values.
