Dutch Critical Infrastructure Under Siege: Pro-Russia Hackers Launch Massive DDoS Campaign


# Russian Hacktivists Launch Persistent DDoS Attacks Against Dutch Organizations

The Netherlands is facing an ongoing wave of distributed denial of service (DDoS) attacks targeting both public and private organizations across the country. According to the National Cyber Security Center (NCSC), part of the Dutch Ministry of Justice, these large-scale attacks have caused significant service disruptions and access problems.

“This week, several Dutch organizations have been targeted by large-scale DDoS attacks,” the NCSC stated. “The DDoS attacks are directed at both Dutch and other European organizations. Within the Netherlands, both public and private entities are being attacked.”

## NoName057(16) Claims Responsibility

The Russia-aligned hacktivist group NoName057(16) has claimed responsibility for the attacks through their Telegram channel. While the NCSC indicated the threat actor’s motive was unclear, the group declared the attacks were retaliation for the Netherlands sending €6 billion in military aid to Ukraine and planning to allocate another €3.5 billion in 2026.

## Widespread Impact

Local media reports indicate the DDoS attacks have affected numerous Dutch provinces including Groningen, Noord-Holland, Zeeland, Drenthe, Overijssel, and Noord-Brabant. Municipalities such as Apeldoorn, Breda, Nijmegen, and Tilburg have also been impacted. Online portals of these public organizations were reportedly unreachable for several hours, though officials maintain there has been no compromise of internal systems or data.

## Persistent Threat Actor

NoName057(16) has been actively conducting DDoS attacks against European and American organizations since March 2022. The group developed a crowdsourced DDoS platform called ‘DDoSIA’ that pays “volunteers” to participate in attacks. This platform quickly gained thousands of users and launched multiple disruptive attacks on Western entities.

Despite Spanish authorities arresting three DDoSIA members in July 2024 and seizing their devices, the group’s leadership remains at large, allowing the DDoS campaign to continue unabated.

Share This Article