< Back to all clusters
[TECHNOLOGY] · Netherlands · 3 sources

Dutch Data Protection Authority reports surge in ransomware attacks

The Autoriteit Persoonsgegevens (Dutch Data Protection Authority) published its 2025 ransomware report, noting a rise to 136 ransomware incidents in the Netherlands last year, up from 127 the previous year. The report highlights that most attacks target the health and welfare, trade and automotive, and information and communication sectors, and often exploit unpatched software vulnerabilities or use phishing.

Data breaches affected personal information of potentially hundreds of thousands to millions of individuals, raising risks of identity fraud and phishing. In 65 cases both data theft and encryption occurred, with 13 incidents involving encryption only and 32 involving theft only. Financial losses per organization reached hundreds of thousands of euros.

The authority advises organisations to prepare with robust incident‑response plans, maintain up‑to‑date systems, implement monitoring, keep reliable backups, and communicate promptly with victims. It warns against paying ransoms, emphasizing that payment offers no guarantee and can encourage further attacks. Lessons from past incidents are meant to help reduce future damage to both victims and organisations.

Entities: Autoriteit Persoonsgegevens · Monique Verdier