Public Prosecution Service was poorly protected against cyberattacks for years

An investigation has concluded that the Dutch Public Prosecution Service failed to adequately protect its ICT systems for years, leaving them vulnerable to cyberattacks. A security flaw in Citrix software allowed hackers to infiltrate the network last July, resulting in the delay of thousands of court cases and highlighting long-standing neglected warnings about outdated technology.
The Dutch Public Prosecution Service (OM) faced severe criticism after an investigation revealed its ICT systems were inadequately protected for years. The agency suffered a significant cyberattack last July, which was facilitated by a vulnerability in Citrix NetScaler software. This breach granted hackers unauthorized access to the network for approximately one month, causing disruptions that resulted in the postponement of thousands of legal proceedings.
Although forensic experts believe sensitive mailbox data remained secure, the lack of robust monitoring made it difficult to determine the full extent of the intrusion. Commission chair Jaap Smit noted that internal warnings about outdated systems had been ignored for years, effectively hitting the snooze button on critical security updates. While the agency has since increased its focus on digital infrastructure, officials emphasize that substantial additional capacity and priority are required to prevent future vulnerabilities and ensure the integrity of the judicial process.
Based on reporting by nu. Translated and condensed by LocalHeadlines.

