MIT TRACE

MIT CTL Logo
Back to Main Dashboard

DJI breach via Ivanti exploitation exposed staff contact, certificates and device location data

The Dutch Custodial Institutions Agency (DJI) disclosed a data breach and cyber incident after attackers exploited a security software vulnerability (Ivanti EPMM), maintaining access for months and exposing staff email addresses, phone numbers and security certificates of users of corporate phones, laptops and tablets. A 27 Feb 2026 letter to Parliament confirms device location data were also exposed. DJI notified the NCSC and instructed staff to disable location tracking; no service disruption has been reported.

35

Estimated severity

35 / 100

84

Source reliability

84 / 100

Approximate Date

27/02/2026

Targeted Company

DIENST JUSTITIELE INRICHTINGEN

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Netherlands

NLD

Other Affected Countries

No other affected countries reported

Target country

Netherlands

Affected countries

Netherlands

Impacted regions

Netherlands · Netherlands

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.