Incident Blog
Analysis of recent security incidents, attack trends, and lessons learned.
Hack of the Month
Companies that got compromised, and what you can learn from it.
Lidl data breach: webshop customer data stolen through an IT service provider
Lidl began emailing webshop customers on 10 July 2026 to tell them their data had been stolen, not from Lidl's own systems, but from a file held by one of its IT service providers. Names, dates of birth, phone numbers and customer numbers are gone. Passwords and payment data are not. The number of affected customers was not disclosed.
Read moreDutch Ministry of Finance hack: a zero-day in access software, and why you cannot patch your way out
The Dutch Ministry of Finance was breached in March 2026 through a zero-day in supplier access software, disclosed in detail on 18 June. There was no patch to apply. What limited the damage was a security team that noticed the intrusion early.
Read moreFortiBleed: how the Fortinet credential leak exposed working firewall logins worldwide
On 13 June 2026, researcher Volodymyr Diachenko found an exposed server holding validated login credentials for Fortinet firewalls. By 19 June the count reached 86,644 devices across 194 countries. The credentials were confirmed working, which means an attacker can log in as you without any malware.
Read moreBelastingdienst Adobe Analytics breach: when your own tracking becomes the data leak
A data breach does not need a hacker. In early June 2026 the Belastingdienst reported one after Adobe Analytics quietly sent visitor behaviour to the US, with no consent, on tax payment pages and a benefits-recovery site. The data walked out through code the organisation installed itself.
Read moreBCD Travel data breach: ShinyHunters leaked the data after the ransom deadline passed
In late May 2026 the extortion group ShinyHunters claimed more than 30 gigabytes from BCD Travel, the Utrecht-based corporate travel company. When the 1 June ransom deadline passed, the data went public. Have I Been Pwned puts the verified count at 396,313 email addresses, alongside names, addresses, phone numbers, and job titles.
Read moreDutch hotels data breach: stolen bookings became fake payment requests within days
A data breach in hotel reservation software hit at least 100 Dutch hotels, plus hotels in Belgium and Ireland. Within days, guests with live bookings were receiving convincing fake payment requests that quoted their real reservation. The breach was weaponised for fraud before the guests had even checked in.
Read moreCanvas data breach: how the ShinyHunters attack on Instructure reached Dutch universities
In late April 2026, the extortion group ShinyHunters breached Canvas through its Free-For-Teacher program. Names, email addresses, student IDs, and private messages were exposed, hitting 44 Dutch institutions. The passwords held. The phishing fuel did not.
Read moreChipSoft data breach: how one ransomware attack reached most of the Dutch hospital sector
On 7 April 2026, ransomware hit ChipSoft, the company behind the patient-record systems most Dutch hospitals run on. The group Embargo stole roughly 100 gigabytes, including medical data. One supplier compromise became a breach across most of the sector.
Read moreBasic-Fit data breach exposes roughly one million members across six countries
Basic-Fit detected the intrusion within minutes and cut off access. The attackers still walked out with membership data on approximately one million people across six countries. Detection worked. Containment worked. The data was already gone.
Read moreOdido data breach: Kamerbrief confirms BSN exposure was worse than initially disclosed
A Kamerbrief confirmed that BSN numbers are in the Odido dataset, contradicting the company's earlier statements. 6.2 million accounts affected, data published on the dark web. The disclosure failures matter as much as the breach itself.
Read moreEurail data breach: passport data for 300,000+ travellers surfaces on the dark web
What started as a cautious disclosure about basic contact data in January has grown into 308,777 confirmed affected travellers with passport numbers on the dark web. The intrusion dates to December 2024, a 13-month gap.
Read moreInsights & Playbooks
Techniques, trends, and response strategies from the field.
The Rise of AiTM Phishing: Bypassing MFA at Scale
Adversary-in-the-middle (AiTM) phishing attacks have become the dominant method for bypassing multi-factor authentication. Here's what we're seeing in the field.
Read moreMicrosoft 365 Token Theft: An Incident Responder's Playbook
Session token theft has become one of the most effective techniques for maintaining persistent access to Microsoft 365 environments. Here's our response playbook.
Read moreQR Code Phishing: Why 'Quishing' Is Surging in 2026
Attackers are embedding phishing links in QR codes to bypass email security filters. Here's why it works and what you can do about it.
Read more