Two Dutch organisations paid ransoms to LockBit on the advice that criminals honour their deletion promises. Four months later, an international police operation seized LockBit’s servers and found the paid victims’ data still sitting on them. The forensic file that would explain how this happened is held by the Dutch data regulator, and the regulator will not release it.
Data Manifest
- Primary Investigation: The documented contradiction between corporate assertions of criminal data deletion and the systemic retention of stolen files recovered by law enforcement during Operation Cronos.
- Key Anomalies Documented: The KNVB and ABN AMRO assurances to victims directly conflict with National Crime Agency server seizures. The Autoriteit Persoonsgegevens' refusal to release the AddComm forensic file obscures the specific agreements made.
- Primary Sources Utilised: UK National Crime Agency Operation Cronos records, KNVB public statements, ABN AMRO customer notices, Autoriteit Persoonsgegevens reports, and the Rotterdam District Court judgment (ECLI:NL:RBROT:2023:2931).
Terminology
- Ransomware-as-a-Service (RaaS): A business model in which a core criminal group writes the ransomware and rents it out to less-skilled attackers, who share the ransom money with the developers.
- Initial Access Broker (IAB): A criminal specialist who breaks into a company's network and then sells that access to other criminals.
- Agentic AI: An AI system that can carry out multi-step tasks on its own without a human giving fresh instructions, including rewriting its own code.
- Double extortion: A ransomware tactic where attackers scramble the victim's files, steal a copy, and threaten to publish the data unless a second ransom is paid.
- Preliminary relief judgment: A fast-track Dutch court ruling (kort geding) forcing urgent action while the main case is decided.
- Woo request: A formal request under the Dutch Open Government Act (Wet open overheid) asking a public body to release documents.
How the Ransomware Franchise Replaced the Lone Hacker
The old picture of a hooded lone hacker at a laptop no longer describes the ransomware business. LockBit was first spotted in September 2019 under the preliminary name ‘ABCD’, with the formal 1.0 build following in January 2020. Since then, the group has run a franchise.
Three roles carry the work. Initial Access Brokers, or IABs, specialise in finding open doors into corporate networks, usually through stolen credentials or unpatched software, and then sell that access on to others. Affiliates buy the access, rent the encryption software from LockBit, break in properly, exfiltrate the files and deploy the ransomware.
Above them sit the operators. LockBit’s core developers write the code, host the extortion leak site and take roughly 20 per cent of every ransom paid. Affiliates keep the remaining 80 per cent.
That inventory of stolen access is not small. In 2025, infostealer infections generated 1.56 billion fresh sets of usernames and passwords, most of them sitting in dumps that any affiliate with a wallet can buy.
But then comes an odd part. In June 2022, when LockBit released its 3.0 build, the group also launched a bug bounty programme, paying researchers to find flaws in its own malicious software. It was mimicry of a legitimate software firm, almost exactly to the letter.
CISA published an advisory on this in 2023, numbered AA23-165A, in dry procedural prose. It does not answer the question that matters most locally. Of the 178 successful Dutch ransomware attacks the Autoriteit Persoonsgegevens logged that year, no one has published how many began with an access broker’s purchase and how many with an affiliate walking in directly.
RaaS Division of Labour
Specialises in finding open doors into corporate networks, usually through stolen credentials or unpatched software, and sells that access.
Purchases access, rents encryption software, exfiltrates files, and deploys the ransomware. Retains 80 per cent of the ransom revenue.
Writes the malicious code, hosts the extortion leak site, and takes 20 per cent of every ransom paid.
The Speed of AI Accelerated Ransomware Attacks
Something has changed in the pace of intrusions. In the JadePuffer incident, tracked by Sysdig’s threat research team and reported in the Hindustan Times, an autonomous AI agent broke into a server, stole credentials and deployed ransomware on its own. When the agent hit a failed login, it rewrote its own exploit code and moved past the block in 31 seconds.
The same agent generated a random decryption key, printed it once on screen and then permanently deleted it. If the victim ever paid the ransom, there would be nothing left to decrypt with.
CrowdStrike’s own logs record a wider compression.
The median ‘breakout time’, the interval between an initial intrusion and lateral movement across a network, has fallen to 29 minutes across the incidents CrowdStrike tracks. Their fastest confirmed breakout came in at 27 seconds.
Phishing, the standard doorway, has become easier to industrialise. Researchers report a 2.3 times uplift in phishing success rates when the messages are generated by AI, in part because non-native English speakers can now draft flawless, context-aware emails without any obvious tells.
Below that sit the tools. Purpose-built criminal language models such as WormGPT and FraudGPT are sold on subscription, offering to write malicious code and evasion logic to order. This class of tool is what makes the term ‘Agentic AI’ meaningful in a criminal context: an AI system that can carry out multi-step tasks on its own, correcting itself when it hits a problem.
None of this proves AI played a role in the Dutch breaches. The observations above concern the attack cycle in general.
Whether AI-assisted tools appeared inside the Nebu or the AddComm intrusion cannot be confirmed either way, because neither forensic report has been released.
Compression of the Intrusion Cycle
-
Pre-AI Average
Manual Lateral Movement
Industry-average breakout time typically measured in hours to days.
-
Current Median
CrowdStrike Benchmark
The median interval between initial intrusion and lateral movement across a network has fallen to 29 minutes.
-
Autonomous Agent Peak
JadePuffer Exploit Rewrite
An autonomous AI agent rewrote its own failed exploit code and moved past a block in 31 seconds.
Legal Accountability in the Nebu Data Breach
On the night of 10 to 11 March 2023, Nebu, a Dutch supplier of market research software, was hit by ransomware. Nebu did not confirm the intrusion to its main client, Blauw Research, until 27 March. Two weeks passed before that first disclosure.
This was not a small breach. In total, 190 customer organisations were affected, and the personal data of roughly 2.5 million Dutch citizens was compromised, according to the Autoriteit Persoonsgegevens Report Data Breaches 2023. Nebu told its clients it would launch an independent forensic investigation. It did not.
Seeking judicial intervention, Blauw Research turned to the courts. The Rotterdam District Court issued a preliminary relief judgment on 6 April 2023, compelling Nebu to appoint external forensic investigators and to provide Blauw with daily status updates by 18:00.
Courts do not usually specify a clock time in a summary judgment unless they expect the losing party to try to string things out. It is the signature of a court that no longer trusts the timetable of the party in front of it.
Rotterdam also ordered the external forensic report to be produced within four weeks. That report has never been made public.
Blauw Research issued a corporate statement announcing the win. The blank page where the external forensic report should be is the friction detail of this section.
There is a blank in the public record where the intrusion vector should be. Stolen credentials from a broker, or a spear-phish that landed: neither has been ruled in or out from the published documents. Rotterdam confirmed Nebu had failed at transparency, not who came through the door.
Priority Briefings
New investigations, evidence checks, and unresolved questions from Veriarch, sent directly to your inbox.
Lessons Learned from the KNVB Ransom Payment
The KNVB, the Royal Dutch Football Association, went public about its own attack in April 2023, when LockBit claimed on its leak site to have stolen 305 GB of association data. That 305 GB figure comes from LockBit’s own extortion post and cannot be independently verified.
Five months of silence followed.
On 12 September 2023, the KNVB issued a public statement. It confirmed that a ransom had been paid to LockBit to prevent publication of employee and member data. In the same statement, the KNVB said that, on advice from the security firm Fox-IT, it did not expect the data to be circulated, because ‘cybercriminals honour the agreements they have made’.
The statement was brief. Neither the ransom sum nor the negotiation timeline appeared in it, and Fox-IT’s specific technical rationale was left implicit.
Fox-IT’s underlying analysis has never been published. What guarantees LockBit gave the KNVB negotiators, whether verbal, written or built into the payment flow, is not in the record. Nor is the KNVB’s own transcript of the exchange.
At the time, no public evidence contradicted the Fox-IT advice. Nobody had yet seized LockBit’s servers. That contradiction would arrive five months later.
Exposing the Myth of Criminal Data Deletion
On 19 February 2024, an international police operation launched against LockBit. Britain’s National Crime Agency led the effort, joined by the FBI, Europol and partner agencies from ten other jurisdictions. Together they seized LockBit’s dark web leak site, 34 servers and the Stealbit exfiltration tool.
Stealbit was not new. LockBit had shipped it back in July 2021 alongside the 2.0 build, a bespoke tool for pulling large volumes of data off a victim network at speed. By the time the NCA reached LockBit’s servers, industrial data theft had been part of the product for two and a half years.
One day later, on 20 February 2024, the NCA published its central finding. LockBit had retained the data of victims who had paid.
Paid victims’ files sat on LockBit’s backend as routine business.
That deletion promise, handed to the KNVB on Fox-IT’s advice and echoed by every other paying victim on the same footing, was a documented fiction.
The FBI followed up. Roughly 7,000 decryption keys were recovered from the seized systems, and IC3 issued a public appeal for LockBit victims to come forward.
Yet the appeal itself contained an absence. The specific list of Dutch entities whose data was found on LockBit’s servers after payment has not been published. Whether the NCA or the FBI directly notified the KNVB or AddComm that their data had been recovered, and if so on what date, is not in any subsequent public statement from either organisation.
What the seized servers prove is retention. They do not prove that any Dutch record was resold, nor that any specific victim was individually notified. Evidence stops at ‘retained’, and the line after that has not been made public.
The Deletion Fiction: Statement vs Record
| Entity | Public Statement (Privileged) | Internal Record / Forensic Finding (Unprivileged) |
|---|---|---|
| KNVB | 12 Sept 2023: Stated cybercriminals 'honour the agreements they have made' to delete data. | 20 Feb 2024: NCA confirms LockBit systematically retained the data of victims who had paid. |
| AddComm / ABN AMRO | 13 Jun 2024: Confirmed AddComm made 'agreements' with attackers to delete stolen data. | LockBit's retained data server architecture had already been publicly seized and verified four months prior. |
The Reality of Secondary Markets for Stolen Data
Four days after the NCA finding, LockBit was posting fresh victims on a new leak site.
The list looked large. When threat intelligence firms cross-checked it, a substantial share turned out to be recycled 2023 breaches, and other entries were victims RansomHub had already claimed on its own site.
A near-identical trick was running under the Babuk name. Analyst1 and Check Point tracked impersonators, catalogued as ‘Babuk2’ or ‘Babuk-Bjorka’ depending on which team was writing, re-extorting victims off leak files stolen back in 2021. No fresh break-in behind any of it.
This secondary market for stolen credentials operates in the same fashion. In December 2023, a 7.8 GB user data leak from streaming platform Wakanim surfaced on Telegram, posted by an actor known as zxcv16. Those files had been circulating for months before that Telegram post, and the leak was catalogued by the threat-intelligence firm InsecureWeb rather than by any law-enforcement body.
Every LockBit 5.0 victim claim from this period sits in the record as an unverified criminal claim, not as forensic evidence. What percentage of LockBit 5.0 listings represents genuinely fresh breaches has never been independently established.
Support the Archive
Help fund the retrieval, hosting, and preservation of Veriarch investigations.
AddComm and the Secrecy of Forensic Records
Three months after Cronos, in May 2024, ransomware hit AddComm. AddComm is a Dutch supplier that handles document distribution, physical and digital, for corporate clients such as ABN AMRO and EasyPark. Both of those clients had customer data in the compromised systems.
ABN AMRO posted an update on 13 June 2024. It said AddComm had made ‘agreements’ with the attackers to delete the stolen data. By that point, the NCA finding on LockBit’s retained data had been public for almost four months.
This mirrored the KNVB pattern.
On 5 August 2025, the Dutch data regulator, the Autoriteit Persoonsgegevens, formally refused a request for the AddComm investigation file.
That refusal was issued under the Dutch Open Government Act, and cited Article 5.1(c) and 5.1(f), the statutory provisions covering business confidentiality and the need to maintain trust in the regulator’s supervisory role.
Two figures in the regulator’s own public record sit uneasily against that refusal. In 2023, 52 per cent of organisations affected by ransomware in the Netherlands lacked basic security measures such as multi-factor authentication. And in the same year, 69 per cent of affected organisations judged the risk to individuals as too low and did not inform the public of the breach.
What agreements ABN AMRO’s supplier reached with LockBit, whether written or verbal, whether time-bound or open-ended, has not been reproduced in any published document. That file remains sealed.
Chronology of the Deletion Fiction
-
6 April 2023
Nebu Judgment
Rotterdam District Court confirms Nebu failed to initiate an independent forensic investigation on its own.
-
12 September 2023
KNVB Ransom Assurance
KNVB announces ransom payment, citing advice that criminals honour deletion agreements.
-
20 February 2024
NCA Server Seizure (Operation Cronos)
Law enforcement publicly proves LockBit retained the data of victims who paid.
-
13 June 2024
AddComm Payment Assurance
ABN AMRO confirms AddComm made deletion 'agreements' with attackers, despite the NCA findings months earlier.
-
5 August 2025
Autoriteit Persoonsgegevens Refusal
Regulator blocks the release of the AddComm investigation file under the Open Government Act.
Source Box
Sources include: the UK National Crime Agency Operation Cronos press release (February 2024); the Autoriteit Persoonsgegevens ‘Report Data Breaches 2023’ (published October 2024); the Rotterdam District Court preliminary relief judgment ECLI:NL:RBROT:2023:2931 (6 April 2023); public statements from the KNVB (September 2023) and ABN AMRO (June 2024); the Cloud Security Alliance ‘Research Note on AI-Assisted Ransomware’ (2026); and CISA Cybersecurity Advisory AA23-165A.
Claim-Source Matrix
| Core Finding | Primary Source Document | Status |
|---|---|---|
| Nebu failed to initiate an independent forensic investigation on its own. | Rotterdam District Court judgment ECLI:NL:RBROT:2023:2931 (6 April 2023) | Confirmed (Privileged) |
| KNVB cited external advice that criminals 'honour the agreements they have made' to delete data. | KNVB Public Statement (12 September 2023) | Confirmed (Unprivileged) |
| LockBit systematically retained the data of victims who had paid ransoms. | UK National Crime Agency Operation Cronos release (20 February 2024) | Confirmed (Unprivileged) |
| AddComm made 'agreements' with criminals to delete data months after Operation Cronos. | ABN AMRO Customer Notice (13 June 2024) | Confirmed (Unprivileged) |
| AP blocked the release of the AddComm investigation file citing business confidentiality. | GDPRhub summary of AP Open Government Act decision (5 August 2025) | Confirmed (Privileged) |
What We Still Do Not Know
- Fox-IT's exact September 2023 briefing to the KNVB has never been disclosed, masking the origin of the 'criminals honour agreements' assurance.
- Nebu's court-ordered external forensic report has never been published, leaving the confirmed intrusion vector out of the public record.
- The exact number of 2023 Dutch ransomware attacks that began with an Initial Access Broker purchase rather than a direct affiliate intrusion remains unknown.
- The specific Dutch entities that appear on the Stealbit exfiltration logs seized by the NCA in February 2024 have not been named publicly.
- It is not recorded whether the NCA or the FBI directly notified the KNVB or AddComm that their data was found on LockBit servers.
- AddComm investigation file remains sealed by the Autoriteit Persoonsgegevens under the 5 August 2025 Open Government Act decision.

Comments (0)