Netherlands
NLD
The Dutch Custodial Institutions Agency (DJI) disclosed a data breach and cyber incident after attackers exploited a security software vulnerability (Ivanti EPMM), maintaining access for months and exposing staff email addresses, phone numbers and security certificates of users of corporate phones, laptops and tablets. A 27 Feb 2026 letter to Parliament confirms device location data were also exposed. DJI notified the NCSC and instructed staff to disable location tracking; no service disruption has been reported.
Estimated severity
35 / 100
Source reliability
84 / 100
Approximate Date
27/02/2026
Targeted Company
DIENST JUSTITIELE INRICHTINGEN
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Netherlands
NLD
No other affected countries reported
Target country
Netherlands
Affected countries
Impacted regions
Duration
No information
Financial impact (USD M)
No information
Impact types
No information
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone