Skip to content
Back to Blog
6 min readdata-breachzero-daysupply-chainincident-response

Dutch Ministry of Finance hack: a zero-day in access software, and why you cannot patch your way out

The Dutch Ministry of Finance was breached in March 2026 through a zero-day in supplier access software, disclosed in detail on 18 June. There was no patch to apply. What limited the damage was a security team that noticed the intrusion early.

TL;DR

The Dutch Ministry of Finance was breached in March 2026 through a zero-day in the software that controls access to its digital workplace, run by an external supplier. The ministry's own security operations centre detected the intrusion on 19 March, and employee data was probably stolen. The attacker remains unidentified, and core services of the Tax Administration, Customs, and Benefits were not affected.

Incident Response PlaybookExpand
  1. Treat the alert as a live intrusion. When your SOC sees anomalous user behaviour, assume compromise until proven otherwise.
  2. Identify the entry point. A zero-day in an access gateway means no patch exists yet, so containment comes before remediation.
  3. Engage the affected supplier immediately. If the vulnerable software runs at a third party, they must act in parallel.
  4. Isolate or restrict the affected systems and any portal that depends on them, accepting temporary loss of service.
  5. Revoke sessions and credentials that could have passed through the access layer.
  6. Run structured forensic evidence collection to establish dwell time and movement.
  7. Determine what data was reachable and likely taken. With a stealthy actor, assume exfiltration where you cannot prove otherwise.
  8. Notify legal counsel, the Autoriteit Persoonsgegevens, and national bodies (NCSC-NL, and law enforcement) where they apply.
  9. Inform affected employees and guide them on the personal impact.
  10. Coordinate with the supplier so every downstream customer of the same software is warned.
  11. Restore service only once the supplier's fix is confirmed and your environment is validated.
  12. Run a post-incident review focused on edge exposure, supplier dependency, and detection speed.

An attack you cannot patch your way out of

The Dutch Ministry of Finance hack, disclosed in detail on 18 June 2026, is a useful study in an attack you cannot prevent with patching. The intrusion happened back in March, through a zero-day vulnerability in the software that controls access to the ministry's digital workplace. Because a zero-day is unknown until it is used, no update existed to block it. What the ministry could influence was detection and response, and according to the letter Minister Heinen sent to parliament, its own security operations centre spotted the anomalous activity on 19 March and the supplier moved the same day.

What happened

On 19 March 2026, the ministry's security operations centre detected that an actor had gained access to part of its ICT systems, as Minister Heinen described in his letter to the Tweede Kamer and as Security.NL and Techzine reported. Further investigation showed a sophisticated intrusion that abused a zero-day in the access software. The vulnerable software runs at an external supplier that handles various digital processes on the ministry's behalf, and that supplier took mitigating measures the same day and shut down certain functions. On 27 March the supplier informed its other customers.

Because timely action was taken, the minister said the intrusion caused no damage to systems, although data theft is considered likely. The Mijn Schatkist portal was switched off as a precaution, which meant around 1,600 public institutions could not view their balances digitally, though payments continued manually. By the time of disclosure, systems were back online.

How the attack worked

The entry point was a zero-day in software governing access to the working environment, which is the kind of identity and access layer that, once breached, can open a path into much more. The minister was explicit that the actor exploited a vulnerability unknown at the time, for which no security updates existed, and that the supplier acted on that knowledge to close it.

The attribution picture is honest and instructive. Forensic investigation could not establish who was responsible or exactly which files were taken, and the minister noted that for sophisticated intrusions of this kind it is rarely possible to identify the party behind it. Team High Tech Crime, the NCSC, and the Autoriteit Persoonsgegevens are involved in the investigation.

Who is affected

The impact was contained to the policy department of the ministry. The minister stated that the services of the Belastingdienst (Tax Administration), Douane (Customs), and Dienst Toeslagen (Benefits) were not affected, and that primary processes such as the spring budget decisions went ahead.

Data theft is considered likely, and it appears to involve employee data. Affected staff have been informed and supported in limiting the personal impact. The wider exposure ran through the supplier: any other organisation using the same access software was potentially at risk, which is why the supplier notified its customer base.

What this means for your organisation

A few takeaways that apply well beyond government.

You cannot patch a zero-day before it is known, so detection is the control that matters. The thing that limited the damage here was a security operations centre noticing unusual behaviour early. If you have no way to spot anomalous access in your own environment, a zero-day in an edge or identity product gives an attacker quiet time to work.

Your access layer is a high-value target. Software that governs who gets into your environment is worth more to an attacker than any single application, because it is the doorway to everything behind it. Treat identity and access infrastructure as crown-jewel exposure, and watch it accordingly.

Supplier software is your exposure too. The vulnerable component ran at a third party, yet the ministry carried the consequences. Knowing which suppliers sit in your access path, and how fast they will tell you when something breaks, is part of managing your own risk.

Continuously understanding where you are exposed, including third-party and internet-facing access systems, is what SecDesk's Threat Exposure Management is designed to do, and the incident response team is there for the moment something gets through. You can reach the responders directly at response.secdesk.com.

Talk to a senior responder about Dutch Ministry of Finance hack: a zero-day in access software, and why you cannot patch your way out.

Schedule a response call
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now