惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
aimingoo的专栏
aimingoo的专栏
S
SegmentFault 最新的问题
博客园_首页
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
博客园 - 【当耐特】
月光博客
月光博客
C
Check Point Blog
T
The Blog of Author Tim Ferriss
罗磊的独立博客
博客园 - Franky
MongoDB | Blog
MongoDB | Blog
H
Help Net Security
Microsoft Security Blog
Microsoft Security Blog
B
Blog
阮一峰的网络日志
阮一峰的网络日志
腾讯CDC
美团技术团队
N
Netflix TechBlog - Medium
Stack Overflow Blog
Stack Overflow Blog
Y
Y Combinator Blog
L
LangChain Blog
The Cloudflare Blog

Cyberwarzone

Why Cyberwarfare Uses Ambiguity and Delayed Attribution as Pressure Why Cyberwarfare Pressures Trusted Access and Account Recovery Paths Why Cyberwarfare Keeps Pressuring Recovery Paths and Fallback Systems Why Cyberwarfare Keeps Pressuring Shared Service Providers Why Cyberwarfare Pressures Industry Clusters Why Cyberwarfare Turns Nearby Economies Into Spillover Zones Why Cyberwarfare Forces Firms to Scan Networks Early Why Cyberwarfare Targets Crisis Messaging Systems Why Cyberwarfare Keeps Pressuring Energy Networks Why Cyberwarfare Keeps Pressuring Communications Networks Why Cyberwarfare Keeps Pressuring Shipping and Logistics Networks Why Cyberwarfare Keeps Pressuring Banks and Financial Networks Why Endpoint Management Systems Are Becoming Cyberwarfare Choke Points Why Cyberwarfare Targets Healthcare and Medical Supply Chains Why Cyberwarfare Increasingly Exploits Trusted Civilian Apps Why Cyberwarfare Hits Civilian Companies First Critical Quest KACE SMA RCE (CVE-2025-32975) Under Attack Handala Rebounds After FBI Seizure, Exposing Iran Cyberwar Resilience Top 10 Cyber Escalation Risks Security Leaders Should Understand Top 10 Questions to Ask Before Calling an Incident Cyberwarfare Top 10 Cyber Deterrence Problems Security Leaders Should Understand Top 10 OT and ICS Risks in Modern Cyberwarfare Top 10 Cyberwarfare Doctrine Ideas Security Leaders Should Understand Top 10 Attribution Problems in State-Linked Cyber Operations Iran Cyberwar: Identity Systems Become the Target Iran Cyberwar Shifts to Spillover, Retaliation, and Control Top 10 Critical Infrastructure Sectors Most Exposed in Cyberwarfare Top 10 Below-Threshold Cyber Operations States Use Top 10 Differences Between Cyberwarfare and Cyber Espionage Top 10 Signs a Cyber Campaign Is Pre-Positioning for Future Conflict
Ivanti Hack at Dutch Custodial Agency Under Investigation
Elles De Yeager · 2026-04-14 · via Cyberwarzone

Elles De Yeager Avatar

·

2–3 minutes

An ongoing investigation into a security breach at the Dutch Custodial Institutions Agency (DJI) has revealed that attackers had access to the agency’s Ivanti EPMM server for five months. State Secretary of Justice and Security, Van Bruggen, confirmed the investigation in response to parliamentary questions. The full extent of the data breach is still being determined.

Sensitive Employee Data Compromised

The attackers gained access to sensitive information belonging to DJI employees, including names, email addresses, phone numbers, and location data. The compromised server, an Ivanti Endpoint Manager Mobile (EPMM), is used for mobile device management, allowing organizations to remotely manage their employees’ mobile devices. Unauthorized access to such a system can have far-reaching consequences, as it provides a gateway to a wide range of sensitive data and communications. The long duration of the breach raises concerns about the potential for extensive data exfiltration and misuse of the compromised information. For more information on how state-sponsored attacks can leverage ambiguity, see our article on cyberwarfare and delayed attribution.

Risk of Blackmail and Extortion

Due to the nature of their work, DJI employees face an elevated risk of blackmail and extortion if their personal information falls into the wrong hands. State Secretary Van Bruggen acknowledged these risks and stated that security measures have been implemented to protect the affected employees. A response plan has been provided to all DJI staff, and the National Cyber Security Centre (NCSC) has developed a set of actions based on the preliminary findings of the forensic investigation. The incident highlights the critical importance of robust cybersecurity measures within government agencies and the potential for real-world harm when such systems are compromised. To learn more about how data breaches can impact individuals, read our recent story on the Basic-Fit data breach.

Investigation and Future Measures

The investigation into the Ivanti hack is ongoing, and a full evaluation and cause analysis will be conducted once it is completed. The findings will be used to improve security protocols and prevent similar incidents in the future. The DJI has already implemented technical and monitoring measures based on the NCSC’s recommendations. The incident serves as a stark reminder of the persistent threat of cyberattacks against government institutions and the need for continuous vigilance and adaptation in the face of evolving cyber threats.

Tags

About the Author

Elles De Yeager Avatar

Elles De Yeager

With a keen eye for cyber trends, Elles researches and writes about the technologies, threats, and defenses shaping our connected future.


Continue Reading