惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

腾讯CDC
N
Netflix TechBlog - Medium
aimingoo的专栏
aimingoo的专栏
P
Proofpoint News Feed
F
Fortinet All Blogs
大猫的无限游戏
大猫的无限游戏
I
InfoQ
V
V2EX
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
有赞技术团队
有赞技术团队
G
Google Developers Blog
L
LangChain Blog
博客园_首页
M
MIT News - Artificial intelligence
H
Hackread – Cybersecurity News, Data Breaches, AI and More
月光博客
月光博客
IT之家
IT之家
量子位
宝玉的分享
宝玉的分享
S
SegmentFault 最新的问题
Stack Overflow Blog
Stack Overflow Blog
V
Visual Studio Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
雷峰网
雷峰网

Cyberwarzone

Why Cyberwarfare Uses Ambiguity and Delayed Attribution as Pressure Why Cyberwarfare Pressures Trusted Access and Account Recovery Paths Why Cyberwarfare Keeps Pressuring Recovery Paths and Fallback Systems Why Cyberwarfare Keeps Pressuring Shared Service Providers Why Cyberwarfare Pressures Industry Clusters Why Cyberwarfare Turns Nearby Economies Into Spillover Zones Why Cyberwarfare Forces Firms to Scan Networks Early Why Cyberwarfare Targets Crisis Messaging Systems Why Cyberwarfare Keeps Pressuring Energy Networks Why Cyberwarfare Keeps Pressuring Communications Networks Why Cyberwarfare Keeps Pressuring Shipping and Logistics Networks Why Cyberwarfare Keeps Pressuring Banks and Financial Networks Why Endpoint Management Systems Are Becoming Cyberwarfare Choke Points Why Cyberwarfare Targets Healthcare and Medical Supply Chains Why Cyberwarfare Increasingly Exploits Trusted Civilian Apps Why Cyberwarfare Hits Civilian Companies First Critical Quest KACE SMA RCE (CVE-2025-32975) Under Attack Handala Rebounds After FBI Seizure, Exposing Iran Cyberwar Resilience Top 10 Cyber Escalation Risks Security Leaders Should Understand Top 10 Questions to Ask Before Calling an Incident Cyberwarfare Top 10 Cyber Deterrence Problems Security Leaders Should Understand Top 10 OT and ICS Risks in Modern Cyberwarfare Top 10 Cyberwarfare Doctrine Ideas Security Leaders Should Understand Top 10 Attribution Problems in State-Linked Cyber Operations Iran Cyberwar: Identity Systems Become the Target Iran Cyberwar Shifts to Spillover, Retaliation, and Control Top 10 Critical Infrastructure Sectors Most Exposed in Cyberwarfare Top 10 Below-Threshold Cyber Operations States Use Top 10 Differences Between Cyberwarfare and Cyber Espionage Top 10 Signs a Cyber Campaign Is Pre-Positioning for Future Conflict
Ivanti Hack at Dutch Custodial Agency Under Investigation
Elles De Yeager · 2026-04-14 · via Cyberwarzone

Elles De Yeager Avatar

·

2–3 minutes

An ongoing investigation into a security breach at the Dutch Custodial Institutions Agency (DJI) has revealed that attackers had access to the agency’s Ivanti EPMM server for five months. State Secretary of Justice and Security, Van Bruggen, confirmed the investigation in response to parliamentary questions. The full extent of the data breach is still being determined.

Sensitive Employee Data Compromised

The attackers gained access to sensitive information belonging to DJI employees, including names, email addresses, phone numbers, and location data. The compromised server, an Ivanti Endpoint Manager Mobile (EPMM), is used for mobile device management, allowing organizations to remotely manage their employees’ mobile devices. Unauthorized access to such a system can have far-reaching consequences, as it provides a gateway to a wide range of sensitive data and communications. The long duration of the breach raises concerns about the potential for extensive data exfiltration and misuse of the compromised information. For more information on how state-sponsored attacks can leverage ambiguity, see our article on cyberwarfare and delayed attribution.

Risk of Blackmail and Extortion

Due to the nature of their work, DJI employees face an elevated risk of blackmail and extortion if their personal information falls into the wrong hands. State Secretary Van Bruggen acknowledged these risks and stated that security measures have been implemented to protect the affected employees. A response plan has been provided to all DJI staff, and the National Cyber Security Centre (NCSC) has developed a set of actions based on the preliminary findings of the forensic investigation. The incident highlights the critical importance of robust cybersecurity measures within government agencies and the potential for real-world harm when such systems are compromised. To learn more about how data breaches can impact individuals, read our recent story on the Basic-Fit data breach.

Investigation and Future Measures

The investigation into the Ivanti hack is ongoing, and a full evaluation and cause analysis will be conducted once it is completed. The findings will be used to improve security protocols and prevent similar incidents in the future. The DJI has already implemented technical and monitoring measures based on the NCSC’s recommendations. The incident serves as a stark reminder of the persistent threat of cyberattacks against government institutions and the need for continuous vigilance and adaptation in the face of evolving cyber threats.

Tags

About the Author

Elles De Yeager Avatar

Elles De Yeager

With a keen eye for cyber trends, Elles researches and writes about the technologies, threats, and defenses shaping our connected future.


Continue Reading