Skip to content

The Dutch Ransomware Crisis – Examining Data Privacy and Regulator Silence

Dutch organisations paid LockBit ransoms relying on promises of data deletion. When the National Crime Agency seized the gang's servers, they proved criminal data retention was a systematic business practice.

A dark computer terminal screen displaying a glowing green progress bar.

Two Dutch organisations paid ransoms to LockBit on the advice that criminals honour their deletion promises. Four months later, an international police operation seized LockBit’s servers and found the paid victims’ data still sitting on them. The forensic file that would explain how this happened is held by the Dutch data regulator, and the regulator will not release it.

Data Manifest

  • Primary Investigation: The documented contradiction between corporate assertions of criminal data deletion and the systemic retention of stolen files recovered by law enforcement during Operation Cronos.
  • Key Anomalies Documented: The KNVB and ABN AMRO assurances to victims directly conflict with National Crime Agency server seizures. The Autoriteit Persoonsgegevens' refusal to release the AddComm forensic file obscures the specific agreements made.
  • Primary Sources Utilised: UK National Crime Agency Operation Cronos records, KNVB public statements, ABN AMRO customer notices, Autoriteit Persoonsgegevens reports, and the Rotterdam District Court judgment (ECLI:NL:RBROT:2023:2931).

Terminology

  • Ransomware-as-a-Service (RaaS): A business model in which a core criminal group writes the ransomware and rents it out to less-skilled attackers, who share the ransom money with the developers.
  • Initial Access Broker (IAB): A criminal specialist who breaks into a company's network and then sells that access to other criminals.
  • Agentic AI: An AI system that can carry out multi-step tasks on its own without a human giving fresh instructions, including rewriting its own code.
  • Double extortion: A ransomware tactic where attackers scramble the victim's files, steal a copy, and threaten to publish the data unless a second ransom is paid.
  • Preliminary relief judgment: A fast-track Dutch court ruling (kort geding) forcing urgent action while the main case is decided.
  • Woo request: A formal request under the Dutch Open Government Act (Wet open overheid) asking a public body to release documents.

How the Ransomware Franchise Replaced the Lone Hacker

The old picture of a hooded lone hacker at a laptop no longer describes the ransomware business. LockBit was first spotted in September 2019 under the preliminary name ‘ABCD’, with the formal 1.0 build following in January 2020. Since then, the group has run a franchise.

Three roles carry the work. Initial Access Brokers, or IABs, specialise in finding open doors into corporate networks, usually through stolen credentials or unpatched software, and then sell that access on to others. Affiliates buy the access, rent the encryption software from LockBit, break in properly, exfiltrate the files and deploy the ransomware.

Above them sit the operators. LockBit’s core developers write the code, host the extortion leak site and take roughly 20 per cent of every ransom paid. Affiliates keep the remaining 80 per cent.

That inventory of stolen access is not small. In 2025, infostealer infections generated 1.56 billion fresh sets of usernames and passwords, most of them sitting in dumps that any affiliate with a wallet can buy.

But then comes an odd part. In June 2022, when LockBit released its 3.0 build, the group also launched a bug bounty programme, paying researchers to find flaws in its own malicious software. It was mimicry of a legitimate software firm, almost exactly to the letter.

CISA published an advisory on this in 2023, numbered AA23-165A, in dry procedural prose. It does not answer the question that matters most locally. Of the 178 successful Dutch ransomware attacks the Autoriteit Persoonsgegevens logged that year, no one has published how many began with an access broker’s purchase and how many with an affiliate walking in directly.

RaaS Division of Labour

Initial Access Broker (IAB)

Specialises in finding open doors into corporate networks, usually through stolen credentials or unpatched software, and sells that access.

Affiliate

Purchases access, rents encryption software, exfiltrates files, and deploys the ransomware. Retains 80 per cent of the ransom revenue.

Operator (Core Group)

Writes the malicious code, hosts the extortion leak site, and takes 20 per cent of every ransom paid.

CISA Cybersecurity Advisory AA23-165A / FBI Operation Cronos Release.

The Speed of AI Accelerated Ransomware Attacks

Something has changed in the pace of intrusions. In the JadePuffer incident, tracked by Sysdig’s threat research team and reported in the Hindustan Times, an autonomous AI agent broke into a server, stole credentials and deployed ransomware on its own. When the agent hit a failed login, it rewrote its own exploit code and moved past the block in 31 seconds.

The same agent generated a random decryption key, printed it once on screen and then permanently deleted it. If the victim ever paid the ransom, there would be nothing left to decrypt with.

CrowdStrike’s own logs record a wider compression.

The median ‘breakout time’, the interval between an initial intrusion and lateral movement across a network, has fallen to 29 minutes across the incidents CrowdStrike tracks. Their fastest confirmed breakout came in at 27 seconds.

Phishing, the standard doorway, has become easier to industrialise. Researchers report a 2.3 times uplift in phishing success rates when the messages are generated by AI, in part because non-native English speakers can now draft flawless, context-aware emails without any obvious tells.

Below that sit the tools. Purpose-built criminal language models such as WormGPT and FraudGPT are sold on subscription, offering to write malicious code and evasion logic to order. This class of tool is what makes the term ‘Agentic AI’ meaningful in a criminal context: an AI system that can carry out multi-step tasks on its own, correcting itself when it hits a problem.

None of this proves AI played a role in the Dutch breaches. The observations above concern the attack cycle in general.

Whether AI-assisted tools appeared inside the Nebu or the AddComm intrusion cannot be confirmed either way, because neither forensic report has been released.

Compression of the Intrusion Cycle

  • Pre-AI Average

    Manual Lateral Movement

    Industry-average breakout time typically measured in hours to days.

  • Current Median

    CrowdStrike Benchmark

    The median interval between initial intrusion and lateral movement across a network has fallen to 29 minutes.

  • Autonomous Agent Peak

    JadePuffer Exploit Rewrite

    An autonomous AI agent rewrote its own failed exploit code and moved past a block in 31 seconds.

CrowdStrike Global Threat Report / Hindustan Times.

Legal Accountability in the Nebu Data Breach

On the night of 10 to 11 March 2023, Nebu, a Dutch supplier of market research software, was hit by ransomware. Nebu did not confirm the intrusion to its main client, Blauw Research, until 27 March. Two weeks passed before that first disclosure.

This was not a small breach. In total, 190 customer organisations were affected, and the personal data of roughly 2.5 million Dutch citizens was compromised, according to the Autoriteit Persoonsgegevens Report Data Breaches 2023. Nebu told its clients it would launch an independent forensic investigation. It did not.

Seeking judicial intervention, Blauw Research turned to the courts. The Rotterdam District Court issued a preliminary relief judgment on 6 April 2023, compelling Nebu to appoint external forensic investigators and to provide Blauw with daily status updates by 18:00.

Courts do not usually specify a clock time in a summary judgment unless they expect the losing party to try to string things out. It is the signature of a court that no longer trusts the timetable of the party in front of it.

Rotterdam also ordered the external forensic report to be produced within four weeks. That report has never been made public.

Blauw Research issued a corporate statement announcing the win. The blank page where the external forensic report should be is the friction detail of this section.

There is a blank in the public record where the intrusion vector should be. Stolen credentials from a broker, or a spear-phish that landed: neither has been ruled in or out from the published documents. Rotterdam confirmed Nebu had failed at transparency, not who came through the door.

Priority Briefings

New investigations, evidence checks, and unresolved questions from Veriarch, sent directly to your inbox.

Lessons Learned from the KNVB Ransom Payment

The KNVB, the Royal Dutch Football Association, went public about its own attack in April 2023, when LockBit claimed on its leak site to have stolen 305 GB of association data. That 305 GB figure comes from LockBit’s own extortion post and cannot be independently verified.

Five months of silence followed.

On 12 September 2023, the KNVB issued a public statement. It confirmed that a ransom had been paid to LockBit to prevent publication of employee and member data. In the same statement, the KNVB said that, on advice from the security firm Fox-IT, it did not expect the data to be circulated, because ‘cybercriminals honour the agreements they have made’.

The statement was brief. Neither the ransom sum nor the negotiation timeline appeared in it, and Fox-IT’s specific technical rationale was left implicit.

Fox-IT’s underlying analysis has never been published. What guarantees LockBit gave the KNVB negotiators, whether verbal, written or built into the payment flow, is not in the record. Nor is the KNVB’s own transcript of the exchange.

At the time, no public evidence contradicted the Fox-IT advice. Nobody had yet seized LockBit’s servers. That contradiction would arrive five months later.

Exposing the Myth of Criminal Data Deletion

On 19 February 2024, an international police operation launched against LockBit. Britain’s National Crime Agency led the effort, joined by the FBI, Europol and partner agencies from ten other jurisdictions. Together they seized LockBit’s dark web leak site, 34 servers and the Stealbit exfiltration tool.

Stealbit was not new. LockBit had shipped it back in July 2021 alongside the 2.0 build, a bespoke tool for pulling large volumes of data off a victim network at speed. By the time the NCA reached LockBit’s servers, industrial data theft had been part of the product for two and a half years.

One day later, on 20 February 2024, the NCA published its central finding. LockBit had retained the data of victims who had paid.

Paid victims’ files sat on LockBit’s backend as routine business.

That deletion promise, handed to the KNVB on Fox-IT’s advice and echoed by every other paying victim on the same footing, was a documented fiction.

The FBI followed up. Roughly 7,000 decryption keys were recovered from the seized systems, and IC3 issued a public appeal for LockBit victims to come forward.

Yet the appeal itself contained an absence. The specific list of Dutch entities whose data was found on LockBit’s servers after payment has not been published. Whether the NCA or the FBI directly notified the KNVB or AddComm that their data had been recovered, and if so on what date, is not in any subsequent public statement from either organisation.

What the seized servers prove is retention. They do not prove that any Dutch record was resold, nor that any specific victim was individually notified. Evidence stops at ‘retained’, and the line after that has not been made public.

The Deletion Fiction: Statement vs Record

Entity Public Statement (Privileged) Internal Record / Forensic Finding (Unprivileged)
KNVB 12 Sept 2023: Stated cybercriminals 'honour the agreements they have made' to delete data. 20 Feb 2024: NCA confirms LockBit systematically retained the data of victims who had paid.
AddComm / ABN AMRO 13 Jun 2024: Confirmed AddComm made 'agreements' with attackers to delete stolen data. LockBit's retained data server architecture had already been publicly seized and verified four months prior.
UK National Crime Agency Operation Cronos release / KNVB statement / ABN AMRO notice.

The Reality of Secondary Markets for Stolen Data

Four days after the NCA finding, LockBit was posting fresh victims on a new leak site.

The list looked large. When threat intelligence firms cross-checked it, a substantial share turned out to be recycled 2023 breaches, and other entries were victims RansomHub had already claimed on its own site.

A near-identical trick was running under the Babuk name. Analyst1 and Check Point tracked impersonators, catalogued as ‘Babuk2’ or ‘Babuk-Bjorka’ depending on which team was writing, re-extorting victims off leak files stolen back in 2021. No fresh break-in behind any of it.

This secondary market for stolen credentials operates in the same fashion. In December 2023, a 7.8 GB user data leak from streaming platform Wakanim surfaced on Telegram, posted by an actor known as zxcv16. Those files had been circulating for months before that Telegram post, and the leak was catalogued by the threat-intelligence firm InsecureWeb rather than by any law-enforcement body.

Every LockBit 5.0 victim claim from this period sits in the record as an unverified criminal claim, not as forensic evidence. What percentage of LockBit 5.0 listings represents genuinely fresh breaches has never been independently established.

Support the Archive

Help fund the retrieval, hosting, and preservation of Veriarch investigations.

DONATE >

AddComm and the Secrecy of Forensic Records

Three months after Cronos, in May 2024, ransomware hit AddComm. AddComm is a Dutch supplier that handles document distribution, physical and digital, for corporate clients such as ABN AMRO and EasyPark. Both of those clients had customer data in the compromised systems.

ABN AMRO posted an update on 13 June 2024. It said AddComm had made ‘agreements’ with the attackers to delete the stolen data. By that point, the NCA finding on LockBit’s retained data had been public for almost four months.

This mirrored the KNVB pattern.

On 5 August 2025, the Dutch data regulator, the Autoriteit Persoonsgegevens, formally refused a request for the AddComm investigation file.

That refusal was issued under the Dutch Open Government Act, and cited Article 5.1(c) and 5.1(f), the statutory provisions covering business confidentiality and the need to maintain trust in the regulator’s supervisory role.

Two figures in the regulator’s own public record sit uneasily against that refusal. In 2023, 52 per cent of organisations affected by ransomware in the Netherlands lacked basic security measures such as multi-factor authentication. And in the same year, 69 per cent of affected organisations judged the risk to individuals as too low and did not inform the public of the breach.

What agreements ABN AMRO’s supplier reached with LockBit, whether written or verbal, whether time-bound or open-ended, has not been reproduced in any published document. That file remains sealed.

Chronology of the Deletion Fiction

  • 6 April 2023

    Nebu Judgment

    Rotterdam District Court confirms Nebu failed to initiate an independent forensic investigation on its own.

  • 12 September 2023

    KNVB Ransom Assurance

    KNVB announces ransom payment, citing advice that criminals honour deletion agreements.

  • 20 February 2024

    NCA Server Seizure (Operation Cronos)

    Law enforcement publicly proves LockBit retained the data of victims who paid.

  • 13 June 2024

    AddComm Payment Assurance

    ABN AMRO confirms AddComm made deletion 'agreements' with attackers, despite the NCA findings months earlier.

  • 5 August 2025

    Autoriteit Persoonsgegevens Refusal

    Regulator blocks the release of the AddComm investigation file under the Open Government Act.

GDPRhub decision summary / ABN AMRO notice / AP Ransomware Report 2024.

Source Box

Sources include: the UK National Crime Agency Operation Cronos press release (February 2024); the Autoriteit Persoonsgegevens ‘Report Data Breaches 2023’ (published October 2024); the Rotterdam District Court preliminary relief judgment ECLI:NL:RBROT:2023:2931 (6 April 2023); public statements from the KNVB (September 2023) and ABN AMRO (June 2024); the Cloud Security Alliance ‘Research Note on AI-Assisted Ransomware’ (2026); and CISA Cybersecurity Advisory AA23-165A.

Claim-Source Matrix

Core Finding Primary Source Document Status
Nebu failed to initiate an independent forensic investigation on its own. Rotterdam District Court judgment ECLI:NL:RBROT:2023:2931 (6 April 2023) Confirmed (Privileged)
KNVB cited external advice that criminals 'honour the agreements they have made' to delete data. KNVB Public Statement (12 September 2023) Confirmed (Unprivileged)
LockBit systematically retained the data of victims who had paid ransoms. UK National Crime Agency Operation Cronos release (20 February 2024) Confirmed (Unprivileged)
AddComm made 'agreements' with criminals to delete data months after Operation Cronos. ABN AMRO Customer Notice (13 June 2024) Confirmed (Unprivileged)
AP blocked the release of the AddComm investigation file citing business confidentiality. GDPRhub summary of AP Open Government Act decision (5 August 2025) Confirmed (Privileged)

What We Still Do Not Know

  • Fox-IT's exact September 2023 briefing to the KNVB has never been disclosed, masking the origin of the 'criminals honour agreements' assurance.
  • Nebu's court-ordered external forensic report has never been published, leaving the confirmed intrusion vector out of the public record.
  • The exact number of 2023 Dutch ransomware attacks that began with an Initial Access Broker purchase rather than a direct affiliate intrusion remains unknown.
  • The specific Dutch entities that appear on the Stealbit exfiltration logs seized by the NCA in February 2024 have not been named publicly.
  • It is not recorded whether the NCA or the FBI directly notified the KNVB or AddComm that their data was found on LockBit servers.
  • AddComm investigation file remains sealed by the Autoriteit Persoonsgegevens under the 5 August 2025 Open Government Act decision.
PRIORITY_NEWSLETTER_BRIEFINGS

Archive Updates

New Veriarch investigations and unresolved questions, sent directly to your inbox every other week.

CONNECTION SECURE. UNSUBSCRIBE AT ANY TIME.

Comments (0)

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top