
A newly identified Russian-backed cyberespionage group known as “Laundry Bear” has been linked to the September 2024 breach of Dutch police systems. The Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) confirmed this connection in a joint advisory, warning that the hackers likely compromised other Dutch organizations as well.
## The Attack
During the breach, the hackers accessed a Dutch police employee’s account and stole work-related contact information from the Global Address List, including names, email addresses, phone numbers, and some private details. Investigators determined the attackers likely employed a “pass-the-cookie” technique, using stolen authentication cookies purchased from criminal marketplaces to impersonate legitimate users without needing passwords.
“We have seen that this hacker group successfully gains access to sensitive information from a large number of government organizations and companies worldwide,” said MIVD Director Vice Admiral Peter Reesink. “They have a specific interest in countries of the European Union and NATO.”
## Laundry Bear’s Profile
Also tracked as “Void Blizzard” by Microsoft, this Russian hacking group has been active since at least April 2024. Their operations align with Russian strategic objectives, primarily targeting Ukraine and NATO member states. Their tactics include:
– Using stolen credentials and spear-phishing emails
– Harvesting and exfiltrating files and emails from compromised systems
– Conducting highly targeted operations against specific organizations
Microsoft reports that the group poses “a heightened risk to NATO member states and allies to Ukraine,” with particular focus on government, defense, transportation, media, NGOs, and healthcare sectors across Europe and North America.
In October 2024, Laundry Bear compromised user accounts at a Ukrainian aviation entity that had previously been targeted by another Russian intelligence group linked to the GRU. Their primary objective appears to be gathering intelligence on military equipment purchases and Western weapons deliveries to Ukraine.
