Cyber Crime

Dutch National Cyber Security Centre warns ransomware infected thousands of businesses

According to a confidential report from the Dutch National Cyber Security Centre (NCSC), at least 1,800 companies were infected with 3 ransomware.

A confidential report published by the Dutch National Cyber Security Centre (NCSC) revealed that at least 1,800 companies are affected by three strains of ransomware across the world.

According to the report, the three ransomware LockerGoga, MegaCortex, and Ryuk) involved in the attacks were sharing the same infrastructure.

The NCSC did not name the companies infected with the ransomware, it only revealed that hackers targeted organizations having revenues of millions or billions.

The companies are from various industries, including the automotive industry, construction, chemical, health, food, and entertainment.

“Various Dutch companies have been hit by advanced hostage software. This appears from a confidential report from the National Cyber ​​Security Center, which is in the hands of the NOS.” reads The Dutch Broadcast Foundation (NOS) website. 

“Which companies are involved is unknown, as is the number of affected Dutch companies. Worldwide there are at least 1800 affected companies and the number of Dutch companies is a relatively small part, writes the NCSC.”

The NOS confirmed that Dutch branches of multinationals have also targeted by the ransomware-attacks, including an American chemical company that is a supplier of critical infrastructure in the Netherlands.

“We conducted this investigation following disruptive ransomware attacks abroad,” said an NCSC spokesperson. 

The malware campaign likely began in July 2018, and NCSC experts speculate the attackers may have exploited zero-day vulnerabilities to spread the ransomware.

In May, security experts at Sophos discovered the MegaCortex ransomware while it was targeting corporate networks. At the time, MegaCortex attacks were reported in the United States, Italy, Canada, France, the Netherlands, and Ireland.

LockerGoga was first spotted earlier in January, it was initially discovered after attacks were launched against European companies, such as Altran Technologies in France and also Norsk Hydro.

The list of victims of the Ryuk ransomware is long, it includes hospitals, municipalities, and private businesses.

The fact that the three ransomware families were using the same infrastructure and leveraged zero-day exploit to infect systems suggests that the attacks were conducted by a group of well-resourced same cybercriminals. The use of a shared infrastructure could also suggest that someone is offering it as a service.

Experts also warn that some ransomware also exfiltrates data from infected systems before encrypting their files with the intent to resell the information on the dark web or blackmail twice the victims once that will pay the ransom.

NCSC recommends organizations to be vigilant on potential threats. “Companies still do not take all basic measures,” a spokesperson said via email. “Run updates, make sure your staff are aware of the digital threats and make backups.”

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – malware, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Palo Alto Networks fixed multiple privilege escalation flaws

Palo Alto Networks addressed multiple vulnerabilities and included the latest Chrome patches in its solutions.…

9 hours ago

Unusual toolset used in recent Fog Ransomware attack

Fog ransomware operators used in a May 2025 attack unusual pentesting and monitoring tools, Symantec…

13 hours ago

Paraguay Suffered Data Breach: 7.4 Million Citizen Records Leaked on Dark Web

Resecurity researchers found 7.4 million records containing personally identifiable information (PII) of Paraguay citizens on…

1 day ago

Apple confirmed that Messages app flaw was actively exploited in the wild<gwmw style="display: none; background-color: transparent;"></gwmw>

Apple confirmed that a security flaw in its Messages app was actively exploited in the…

1 day ago

Trend Micro fixes critical bugs in Apex Central and TMEE PolicyServer

Trend Micro fixed multiple vulnerabilities that impact its Apex Central and Endpoint Encryption (TMEE) PolicyServer…

2 days ago