Netherlands

Country

Cyberattack at Eurail

December 26, 2025

Eurail B.V., the Utrecht, Netherlands-based company that manages and markets the Eurail and Interrail passes, suffered a cyberattack in December where personally identifiable information ended up stolen in the hack.
“We recently identified unusual activity within a segment of our network,” the company said in a letter to victims. “We immediately implemented our incident response procedures, took steps to terminate the activity, and commenced an investigation with the support of third-party cybersecurity professionals.”
Eurail said it also notified law enforcement and are supporting its investigation.

read more

Air France, KLM Suffer Data Breach

August 6, 2025

Air France and KLM suffered a cyberattack Wednesday where threat actors were able get into a customer service platform and steal personally identifiable information from users.
The airlines said they eliminated attackers’ access to the compromised systems after they discovered the breach. They also said their networks did not fall into the hands of the attackers.
The airline said in a statement: “Air France and KLM have detected unusual activity on an external platform we use for our customer service. This resulted in unauthorized access to customer data.

read more

Ransomware at Logistics Company AB Texel in The Netherlands

February 15, 2024

“On February 15, 2024, AB Texel fell victim to the Cactus ransomware group. The recovery operation was immediately initiated. The attack has no impact on our services. Our operation continues, we supply our customers. We keep customers and employees informed.” says a statement on the company website. “AB Texel takes this incident very seriously and has filed a report with the police and immediately reported it to the Dutch Data Protection Authority. The digital attack ended at the end of March.”

read more

Liquid Transportation Carrier GCA Nederland Hit by Ransomware Attack

February 26, 2024

The claim of a cyberattack against the carrier GCA (Charles André Group) in the Netherlands appeared on Monday, February 26, 2024, on the RansomHouse showcase site.

In a message addressed to its customers the carrier GCA (Charles André Group) says it was the victim of a cyberattack on the night of February 17 to 18. “As a precautionary measure, we have decided to cut off external Internet access to our systems while we carry out a complete diagnosis of the situation and can restart securely as soon as possible,” we can read there. For the time being, “the usual email addresses, landlines, EDI and API connections are not functional.” In fact, the reception line, in particular, rings into the void.

read more

Ransomware Attack at HAL Allergy Impacts Customer Deliveries

February 19, 2024

HAL Allergy was hit by a ransomware attack on February 19, 2024. HAL Allergy engaged external cybersecurity experts to assist in restoring the affected network and investigate the issue.

On March 22 the company website states: “Following the ransomware attack on February 19, several of HAL Allergy’s IT systems have been restored. The recovered systems were gradually activated in recent weeks to enable deliveries to most of our customers. As of March 14, orders that predate the ransomware attack and were ready for shipment have now been delivered to customers in Germany and the Benelux. Orders placed after February 19 will be processed as of today, March 22, except for the so-called named patient products. As soon as the named patient deliveries can also be processed you will be informed.”

read more

EAS Europe Says it Shut Down Operations after Ransomware Attack

February 26, 2024

On February 26th EAS Europe was the victim of a ransomware attack. The attackers encrypted the EAS Europe servers and have potentially stolen sensitive data from the EAS servers. Customer and supplier data may have been taken.

This incident has caused the operations in the Netherlands to shut down while we restore the back ups.
We sincerely apologize for any delays caused by this incident.

read more

Widespread Fallout after Ransomware Attack at Service Provider for Customer Communication in the Netherlands

May 5, 2024

AddComm’s systems were recently hit by a ransomware attack. The hack took place between May 5 and May 17. On May 17, the security incident became known to AddComm because the systems were encrypted by the cybercriminals.

=ABN Amro reports that it will no longer use Addcomm’s services for the time being, but says that it is in close contact with AddComm.
=Energy Suppliers Essent en Vattenfall energy companies warn customers of dataleak at AddComm.
=The Hague housing corporation Staedion; Waterbedrijf Groningen; the Drenthe drinking water company WMD; the Regional Tax Group (RBG); Hoogheemraadschap Hollands Noorderkwartier (HHNK) ; and the Amsterdam housing corporation Eigen Haard also issued warnings .

read more

Operations Disrupted at US Branch of Grocery Giant Ahold Delhaize

November 6, 2024

Ahold Delhaize said it had “detected a cybersecurity issue within its U.S. network”. The company said the attack took certain systems offline and affected some pharmacies and e-commerce services.

Hannaford’s e-commerce services remained unavailable Monday morning, continuing an outage that began last week. On Friday, Hannaford posted on Instagram that it had canceled pickup and delivery orders that day “as our associates cannot view orders placed.” The websites for Giant Food, Stop & Shop, The Giant Company and Food Lion each posted an identical note online last Friday saying that customers may experience disruptions and reduced availability for pickup and delivery due to “system outages.” It’s unclear how much the cybersecurity issue has impacted Ahold Delhaize’s e-commerce sales.

UPDATE April 2025 : The company confirmed that data was stolen from its U.S. business systems.

read more

Ransomware Attack at Dutch Eurotrol B.V.

June 13, 2024

Eurotrol B.V. recently fell victim to a ransomware attack by the BlackSuit group. The ransomware encrypted files on Eurotrol’s systems, appending the .blacksuit extension and leaving a ransom note named README.BlackSuit.txt. The note directed Eurotrol to a Tor chat site for further communication with the attackers.

read more

Nexperia, Chip Maker Suffers Cyberattack

April 10, 2024

Netherlands-based chip manufacturer, Nexperia, suffered a cyberattack last week and ransomware attackers leaked samples of data it claims it stole from the semiconductor maker’s server.
As a result of the attack, the company said on Friday it shut down IT systems and launch an investigation to determine the scope of impact. It appears the attack came from a ransomware attack group.
In a statement, Nexperia said: “Nexperia has become aware that an unauthorized third party accessed certain Nexperia IT servers in March 2024.
“We promptly took action and disconnected the affected systems from the Internet to contain the incident and implemented extensive mitigation. We also launched an investigation with the support of third-party experts to determine the nature and scope of the incident and took strong measures to terminate the unauthorized access.”

read more