Signal
Submitted
Jul 31, 2026, 19:25 UTC
Dutch intelligence exposed a previously unknown Russian hacking group 'Laundry Bear' responsible for cyber espionage attacks on Dutch organizations including the national police in 2024.
Dutch intelligence agencies AIVD and MIVD unmasked 'Laundry Bear,' a likely Russian state-sponsored hacking group conducting high-speed, automated, non-destructive espionage attacks targeting NATO countries' defense ministries, military units, aerospace and technology firms, and civilian entities focused on IT and technology sectors. The group exploited cloud email environments using simple, stealthy techniques avoiding malware, impersonated organizers in phishing campaigns, and targeted information relevant to Russian interests in Ukraine. Microsoft tracks the group as 'Void Blizzard,' noting its global activity since 2024 with a focus on NATO members and Ukraine. The hacking group was uncovered following a September 2024 session hijacking attack on a Dutch police employee account leading to theft of police contact details. The advisory warns that Laundry Bear's operations demonstrate knowledge about military equipment production and Western sanctions evasion. Dutch services emphasize incomplete insight into the group's activities and seek broader defensive measures.
Confidence: High
The signal describes deliberate, state-sponsored cyber operations affiliated with Russia targeting sensitive defense, governmental, and civilian sectors principally for espionage with known ties to Russian military intelligence tactics, constituting hostile hybrid warfare activity.
Source URL
https://therecord.media/laundry-bear-void-blizzard-russia-hackers-netherlands
Source reliability
B
Info credibility
2
Event time
Sep 1, 2024, 00:00 UTC
End time
Dec 31, 2024, 23:59 UTC
Event time confidence
pm24h
Location
The Netherlands
Primary actor
Laundry Bear
Country
Netherlands
Countries
Netherlands
Tags
Laundry Bear, Void Blizzard, Russian State-Sponsored, offensive cyber operations, Dutch Police Breach, APT28 Modus Operandi, Phishing, Cloud Email Compromise, NATO Defense Targets, russia–ukraine war