Last Update: 08/01/2026 at 1:00 PM EST

Dutch Breaches Expose Personal Data Risks

Coverage from BleepingComputer, ABN AMRO, and others

Articles

11

Active Days

123

The Topic

Dutch Breaches Expose Personal Data Risks topic image

Dutch organizations are investigating or responding to several cyber incidents involving telecommunications, football, government, and consumer data. The incidents show how weaknesses in employee-facing processes, exposed APIs, shared keys, and customer systems can enable unauthorized access or data theft, while police investigations have led to an arrest and a suspected link to the Odido breach. The practical concern extends beyond the initial intrusion: exposed identity and contact data can support more convincing phishing, impersonation, and identity-fraud attempts.

First Article: 03/24/26

Latest Article: 07/24/26

Summary

  • Odido reported unauthorized access to its customer contact system, with exposure affecting millions of customers and including varied personal and identity data.
  • Dutch police linked suspected Dutch hackers to the Odido incident, while ShinyHunters separately claimed responsibility; attribution remains unresolved.
  • A 35-year-old man was arrested over repeated alleged intrusions into AFC Ajax systems after vulnerabilities enabled access to fan data and ticket and stadium-ban functions.
  • Ajax patched the reported flaws and notified Dutch authorities, but the potential scale of fan and season-ticket exposure remains partly based on external reporting.
  • The Dutch Ministry of Finance blocked compromised systems after unauthorized access affected some policy-department employees; core tax, trade, and subsidy systems were reported unaffected.
  • ABN AMRO research indicates that many Dutch residents underestimate the value of personal data, while aggregated breach and social-media information can enable tailored fraud.

History

07/28/2026

The main change is a sharper attribution picture for the Odido breach: police now link it to suspected Dutch hackers while ShinyHunters separately claims responsibility, but the case remains unresolved. The rest of the story is largely a clarification and tightening of prior reporting, especially around Ajax remediation and the Finance Ministry impact.

07/27/2026

The update adds clearer attribution and scope details: police are now actively investigating the Odido intrusion and an arrest has been made in the Ajax case, while the reported extent of exposure is more specific but still partly unresolved. It also shifts the story toward remediation and uncertainty, with affected systems blocked or patched and final data-theft attribution still unconfirmed.

Full History

Featured

Timeline: 123 Days

Mar 24Apr 14May 12Jun 2Jun 30Jul 21

Additional Articles

⭐⭐⭐⭐⭐

The Record / Daryna Antoniuk05-27-2026
Dutch National Police arrested a 35-year-old man in Buren after Ajax disclosed a March data breach involving an unpatched vulnerability.
Help Net Security / Sinisa Markovic05-28-2026
Dutch National Police arrested a Buren resident on May 26, 2026, after AFC Ajax disclosed an intrusion that exposed private fan data via app and website vulnerabilities.
SC Media07-10-2026
Dutch National Police traced an Odido data breach disclosed February 12 to phishing impersonation and customer-contact-system access, affecting 6.2 million customers.
TechTimes / Chase Fiorini07-10-2026
Dutch Data Protection Authority reported 39,407 breach notifications in 2025, citing AI-assisted phishing and AddComm ransomware as key drivers in the Netherlands.
Lexology07-24-2026
Autoriteit Persoonsgegevens in the Netherlands reported 39,407 2025 data-breach notifications and cited AI-enhanced phishing as a driver of account takeover growth.

⭐⭐⭐

BleepingComputer / Sergiu Gatlan03-24-2026
The Dutch Ministry of Finance reported unauthorized access to policy department systems after third-party notification on March 19 and is investigating possible data theft.
BleepingComputer / Sergiu Gatlan03-27-2026
Dutch National Police reported a phishing-related breach on a Wednesday, saying attacker access was blocked quickly and citizens' data was not accessed.
BleepingComputer / Sergiu Gatlan03-30-2026
Eelco Heinen said the Dutch Ministry of Finance took treasury banking portal systems offline on March 23 after a cyberattack detected two weeks earlier, impacting 1,600 institutions during forensics.