AddComm: AI Phishing Kits Drove 58% Breach Surge, Dutch Authority Warns Businesses

AddComm: AI Phishing Kits Drove 58% Breach Surge, Dutch Authority Warns Businesses

Dutch Data Breaches Surge 58% in 2025, Driven by AI-Powered Phishing and Supply Chain Attacks

The Netherlands saw a sharp rise in cyberattack-driven data breaches in 2025, with incidents jumping 58% to 2,428 up from roughly 1,500 in 2024 according to the Dutch Data Protection Authority’s (AP) Datalekkenrapportage 2025, published on July 10. The report attributes the surge to AI-powered phishing kits, which enable criminals to craft convincing, personalized lures without technical expertise, bypassing traditional detection methods.

Key Findings: The Shifting Threat Landscape

  • Account takeovers nearly tripled, rising from 607 in 2024 to 1,742 in 2025, as phishing evolved from a post-breach tactic to a primary attack vector.
  • Ransomware incidents (136 attacks) generated 283 breach notifications, but one attack on AddComm, a Dutch customer communications firm, triggered 5,407 downstream notifications highlighting the cascading impact of supply chain compromises.
  • AI-driven phishing kits eliminate the grammar errors and generic formatting that once flagged fraudulent messages, while adversary-in-the-middle (AiTM) attacks intercept multi-factor authentication (MFA) codes in real time, bypassing standard security measures.

The AddComm Breach: A Case Study in Supply Chain Risk

Between May 5–17, 2024, attackers breached AddComm, a vendor handling sensitive documents for banks, utilities, and other services. The ransomware attack exfiltrated customer data, forcing downstream organizations including ABN Amro to file breach notifications throughout 2025. The incident underscores how a single vendor compromise can trigger thousands of regulatory obligations under GDPR.

Regulatory Warnings and GDPR Enforcement

The AP’s report serves as a direct enforcement signal, warning that organizations relying on legacy monitoring tools risk violating GDPR Article 32 which mandates "appropriate technical and organizational measures" to protect data. Fines for non-compliance can reach €10 million or 2% of global turnover, with severe violations capped at €20 million or 4%.

The authority emphasizes that executives not just IT teams must prioritize cybersecurity, as the threat environment has fundamentally changed. With the Dutch Cyberbeveiligingswet (NIS2 implementation) taking effect on August 15, 2026, organizations face a tightening compliance deadline.

The AI Phishing Flywheel

The report details how AI-powered phishing kits create a self-reinforcing cycle:

  1. Personalized lures use breached data to craft contextually accurate messages.
  2. Commoditized toolkits lower the barrier to entry, enabling non-technical attackers to deploy sophisticated campaigns.
  3. Stolen credentials feed AI systems, improving future attacks.

Traditional email filters, calibrated to detect human errors, are now ineffective. The AP urges organizations to adopt behavioral monitoring (e.g., detecting unusual login patterns) and phishing-resistant MFA (e.g., FIDO2/WebAuthn) to counter these threats.

Broader Implications for the EU

As one of the EU’s most digitally advanced nations, the Netherlands’ breach trends serve as a leading indicator for the region. The 58% spike in cyberattack-driven breaches suggests a broader shift in the EU’s threat landscape, with AI-driven attacks and supply chain risks becoming dominant concerns.

Source: https://www.techtimes.com/articles/320084/20260710/ai-phishing-kits-drove-58-breach-surge-dutch-authority-warns-businesses.htm

AddComm cybersecurity rating report: https://www.rankiteo.com/company/addcommbv

"id": "ADD1783708450",
"linkid": "addcommbv",
"type": "Ransomware",
"date": "5/2024",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '5,407 downstream notifications',
                        'industry': 'technology/services',
                        'location': 'Netherlands',
                        'name': 'AddComm',
                        'type': 'customer communications firm'},
                       {'industry': 'financial services',
                        'location': 'Netherlands',
                        'name': 'ABN Amro',
                        'type': 'bank'}],
 'attack_vector': ['AI-powered phishing kits',
                   'adversary-in-the-middle (AiTM) attacks',
                   'supply chain compromise'],
 'data_breach': {'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'high',
                 'type_of_data_compromised': ['customer data',
                                              'sensitive documents']},
 'date_publicly_disclosed': '2025-07-10',
 'description': 'The Netherlands saw a sharp rise in cyberattack-driven data '
                'breaches in 2025, with incidents jumping 58% to 2,428 up from '
                'roughly 1,500 in 2024. The surge is attributed to AI-powered '
                'phishing kits and supply chain attacks, with account '
                'takeovers nearly tripling and ransomware incidents generating '
                'cascading breach notifications.',
 'impact': {'brand_reputation_impact': True,
            'data_compromised': True,
            'identity_theft_risk': True,
            'legal_liabilities': True,
            'operational_impact': 'cascading breach notifications for '
                                  'downstream organizations'},
 'lessons_learned': 'AI-powered phishing kits and supply chain risks are '
                    'dominant concerns, requiring behavioral monitoring and '
                    'phishing-resistant MFA to counter threats. Executives '
                    'must prioritize cybersecurity due to evolving regulatory '
                    'enforcement.',
 'motivation': ['financial gain', 'data exfiltration'],
 'post_incident_analysis': {'corrective_actions': ['behavioral monitoring',
                                                   'phishing-resistant MFA',
                                                   'supply chain security '
                                                   'enhancements'],
                            'root_causes': ['AI-powered phishing kits',
                                            'supply chain vulnerabilities',
                                            'weak MFA',
                                            'legacy monitoring tools']},
 'ransomware': {'data_exfiltration': True},
 'recommendations': ['Adopt behavioral monitoring to detect unusual login '
                     'patterns',
                     'Implement phishing-resistant MFA (e.g., FIDO2/WebAuthn)',
                     'Strengthen supply chain security to prevent cascading '
                     'breaches',
                     'Comply with GDPR Article 32 and Dutch '
                     'Cyberbeveiligingswet (NIS2)'],
 'references': [{'date_accessed': '2025-07-10',
                 'source': 'Dutch Data Protection Authority (AP)'},
                {'date_accessed': '2025-07-10',
                 'source': 'Datalekkenrapportage 2025'}],
 'regulatory_compliance': {'fines_imposed': ['€10 million or 2% of global '
                                             'turnover',
                                             '€20 million or 4% for severe '
                                             'violations'],
                           'regulations_violated': ['GDPR Article 32',
                                                    'Dutch '
                                                    'Cyberbeveiligingswet '
                                                    '(NIS2 implementation)'],
                           'regulatory_notifications': True},
 'response': {'enhanced_monitoring': ['behavioral monitoring',
                                      'phishing-resistant MFA '
                                      '(FIDO2/WebAuthn)']},
 'stakeholder_advisories': 'Executives must prioritize cybersecurity due to '
                           'tightening regulatory deadlines and enforcement '
                           'signals from the AP.',
 'title': 'Dutch Data Breaches Surge 58% in 2025, Driven by AI-Powered '
          'Phishing and Supply Chain Attacks',
 'type': ['data_breach', 'ransomware', 'phishing', 'supply_chain_attack'],
 'vulnerability_exploited': ['weak MFA',
                             'legacy monitoring tools',
                             'lack of behavioral monitoring']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.