NATO-aligned government agencies and Dutch National Police Force: An Alleged Russian FSB Hacker Traveled To Thailand. Now He's Facing 10 Years In A US Prison.

NATO-aligned government agencies and Dutch National Police Force: An Alleged Russian FSB Hacker Traveled To Thailand. Now He's Facing 10 Years In A US Prison.

Russian-Backed Hacking Group "Laundry Bear" Targets Dutch Police in High-Profile Cyber Espionage Case

In September 2024, Dutch cybersecurity experts uncovered a breach in the National Police Force’s systems, where attackers accessed an employee’s email account using a stolen browser cookie. The intrusion exposed the contacts of up to 64,000 police personnel, along with potential informants and sensitive sources. Dutch military intelligence later attributed the attack to Laundry Bear (also known as Void Blizzard), a Russian state-backed hacking group described as "particularly successful" in cyber sabotage.

The breach sparked widespread concern among Dutch lawmakers and security agencies, with officials confirming it marked the first known instance of deliberate Russian cyber sabotage against the Netherlands. The fallout prompted a broader investigation into the group’s activities, which extended beyond Dutch targets to include NATO-aligned government agencies and organizations supporting Ukraine’s resistance against Russia’s invasion.

The case took a dramatic turn in November 2024, when Denis Obrezko, a 35-year-old Russian IT programmer from Samara, was arrested in Phuket, Thailand, on a U.S. warrant. Authorities seized his laptop, phone, and a digital wallet during the raid. Extradited to the U.S. in late 2024, Obrezko pleaded not guilty in a Boston federal court to charges of hacking nearly a dozen U.S. companies and government agencies, facing up to 10 years in prison.

Obrezko’s background raised further suspicions. According to FBI affidavits, he had worked for Russia’s Federal Security Service (FSB) from 2012 to 2017 before joining Yutek-NN, a company licensed to sell covert surveillance technology and reportedly linked to former FSB officers. At the time of his arrest, Obrezko served as Yutek’s deputy director, a role U.S. prosecutors allege involved cyberespionage operations on behalf of the Russian government.

Investigators traced Obrezko’s digital footprint through cryptocurrency transactions, reused usernames, and a Russian phone number linked to multiple accounts, including social media and PayPal. His alleged co-conspirator, identified in court documents as "Ethan Hunt" (a reference to the Mission: Impossible character), remains at large. The FBI’s case against Obrezko relied on a chain of smaller operational errors, including his failure to mask his identity across platforms a common pitfall in long-term counterintelligence investigations.

The arrest highlighted Russia’s blurred lines between cybercriminals and state intelligence, a dynamic Western experts say enables hackers to operate with impunity as long as they avoid targeting Russian entities. Unlike typical ransomware attacks, the Dutch breach lacked a clear financial motive, leading analysts to speculate that Obrezko may have been directly employed by the Russian state or selling stolen data to government agencies.

Obrezko’s case is notable for its rarity in recent years, as extraditions of Russian hackers on U.S. warrants have declined since 2021. His travel to Thailand a country where Russian operatives have historically faced lower risks proved a miscalculation, with experts suggesting he either underestimated Western intelligence or overestimated protections from Moscow. His defense lawyer, Maksim Nemtsev, stated Obrezko would vigorously contest the charges in court.

The incident also tied back to earlier Russian cyber operations, including a 2021 breach of Aleksei Navalny’s anti-corruption organization, where over 500,000 email addresses were stolen via fake domains. Investigations linked those attacks to Mikhail Dudin, a Samara-based businessman with FSB connections, whose company, Yutek-NN, employed Obrezko.

As the case unfolds, it underscores the persistent threat of Russian cyber espionage, particularly against Western governments and organizations supporting Ukraine. The Dutch government formally identified Laundry Bear as a state-supported threat actor in May 2025, while Microsoft’s concurrent report labeled the group Void Blizzard, though neither disclosed specific individuals or companies involved. Obrezko’s arrest serves as a rare disruption in Russia’s otherwise unchecked cyber operations, offering a glimpse into the high-stakes cat-and-mouse game between Moscow’s hackers and Western law enforcement.

Source: https://www.rferl.org/a/russia-hacker-fsb-thailand-dutch-us-cyber-fraud/33805051.html

NATO Communications and Information Agency (NCIA) cybersecurity rating report: https://www.rankiteo.com/company/nato-communications-and-information-agency-ncia-

Dutchess County Government cybersecurity rating report: https://www.rankiteo.com/company/dutchess-county-government

"id": "NATDUT1784276720",
"linkid": "nato-communications-and-information-agency-ncia-, dutchess-county-government",
"type": "Cyber Attack",
"date": "9/2024",
"severity": "100",
"impact": "8",
"explanation": "Attack that could bring to a war"
{'affected_entities': [{'customers_affected': '64,000 police personnel, '
                                              'informants, and sensitive '
                                              'sources',
                        'industry': 'Law Enforcement',
                        'location': 'Netherlands',
                        'name': 'Dutch National Police Force',
                        'size': 'Large',
                        'type': 'Government Agency'},
                       {'industry': 'Defense, National Security',
                        'location': 'Multiple (NATO member states)',
                        'name': 'NATO-aligned government agencies',
                        'size': 'Large',
                        'type': 'Government Agencies'},
                       {'industry': 'Defense, Humanitarian Aid',
                        'location': 'Ukraine, Europe',
                        'name': 'Organizations supporting Ukraine’s resistance',
                        'type': 'Non-Governmental Organizations, Private '
                                'Entities'}],
 'attack_vector': 'Stolen browser cookie',
 'data_breach': {'number_of_records_exposed': 'Up to 64,000',
                 'personally_identifiable_information': 'Yes (police personnel '
                                                        'and informants)',
                 'sensitivity_of_data': 'High (police personnel, informants)',
                 'type_of_data_compromised': 'Email contacts, sensitive law '
                                             'enforcement sources'},
 'date_detected': '2024-09',
 'date_publicly_disclosed': '2024-09',
 'description': 'In September 2024, Dutch cybersecurity experts uncovered a '
                'breach in the National Police Force’s systems, where '
                'attackers accessed an employee’s email account using a stolen '
                'browser cookie. The intrusion exposed the contacts of up to '
                '64,000 police personnel, along with potential informants and '
                "sensitive sources. The attack was attributed to 'Laundry "
                "Bear' (Void Blizzard), a Russian state-backed hacking group. "
                'The breach marked the first known instance of deliberate '
                'Russian cyber sabotage against the Netherlands and extended '
                'to NATO-aligned government agencies and organizations '
                'supporting Ukraine’s resistance against Russia’s invasion.',
 'impact': {'brand_reputation_impact': 'High (Dutch government and '
                                       'NATO-aligned entities)',
            'data_compromised': 'Contacts of up to 64,000 police personnel, '
                                'potential informants, and sensitive sources',
            'identity_theft_risk': 'High (exposure of police personnel and '
                                   'informants)',
            'operational_impact': 'Compromised sensitive law enforcement data '
                                  'and sources',
            'systems_affected': 'National Police Force’s email systems'},
 'initial_access_broker': {'entry_point': 'Stolen browser cookie',
                           'high_value_targets': 'Dutch police, NATO-aligned '
                                                 'agencies, Ukraine-supporting '
                                                 'organizations'},
 'investigation_status': 'Ongoing (Denis Obrezko extradited to U.S., '
                         'co-conspirator at large)',
 'lessons_learned': 'Russian state-backed hackers blur lines between '
                    'cybercriminals and intelligence operatives; Western '
                    'intelligence can exploit operational errors in long-term '
                    'counterintelligence investigations; extraditions of '
                    'Russian hackers remain rare but possible in third-party '
                    'countries.',
 'motivation': 'Cyber sabotage, espionage, geopolitical advantage',
 'post_incident_analysis': {'corrective_actions': 'Arrest and extradition of '
                                                  'Denis Obrezko; seizure of '
                                                  'digital evidence; ongoing '
                                                  'investigation into Yutek-NN '
                                                  'and FSB links.',
                            'root_causes': 'Stolen browser cookie used for '
                                           'unauthorized access; lack of '
                                           'multi-factor authentication; '
                                           'operational errors by threat actor '
                                           '(e.g., reused usernames, unmasked '
                                           'identity).'},
 'recommendations': 'Enhance monitoring for stolen session cookies; implement '
                    'multi-factor authentication for sensitive systems; '
                    'conduct regular security audits for government and '
                    'NATO-aligned entities; improve cross-border law '
                    'enforcement cooperation for cyber espionage cases.',
 'references': [{'source': 'Dutch cybersecurity experts'},
                {'source': 'FBI affidavit'},
                {'source': 'Microsoft report on Void Blizzard'}],
 'regulatory_compliance': {'legal_actions': 'U.S. federal charges against '
                                            'Denis Obrezko'},
 'response': {'law_enforcement_notified': 'Yes (Dutch military intelligence, '
                                          'FBI, U.S. federal court)'},
 'stakeholder_advisories': 'Dutch government identified Laundry Bear as a '
                           'state-supported threat actor; NATO and '
                           'Ukraine-supporting organizations advised to '
                           'enhance cybersecurity measures.',
 'threat_actor': 'Laundry Bear (Void Blizzard)',
 'title': "Russian-Backed Hacking Group 'Laundry Bear' Targets Dutch Police in "
          'High-Profile Cyber Espionage Case',
 'type': 'Cyber Espionage'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.