© 2026 CoolTechZone - Latest tech news,
product reviews, and analyses.

Ransomware attacks continue to rise in the Netherlands


The number of ransomware attacks in the Netherlands increased again last year. In addition, data theft is becoming more than just encryption.

In 2025, the Dutch privacy and data protection authority (AP) recorded 136 ransomware attacks. Compared to the year before, when the AP received 127 reports of ransomware attacks, this constitutes an increment of 7.1%.

Last year’s ransomware attacks led to at least reported 283 data breaches. The number of data breaches is higher than the reported ransomware attacks due to the fact that a single ransomware attack can affect multiple organizations.

During a ransomware attack, hackers can encrypt data, steal the personal information of victims, or publish the exfiltrated data on the dark web.

In approximately half of last year’s ransomware attacks (48%), the attackers both encrypted and stole data. In nearly a quarter of all cases (23%), attackers only stole data. In one in five cases (19%), data was encrypted and probably also stolen. In the remaining 10% of the ransomware attacks, the attackers solely encrypted the victim’s data.

The sectors with the highest number of ransomware-related data breaches in 2025 were the health sector (40), retail and automotive branch (39), information and communications sector (34), manufacturing business (32), and construction sector (22).

Ransomware attacks have major consequences, not just for the businesses and organizations that are attacked, but for customers as well. According to the AP, some companies and organizations underestimate these risks.

They assume personal information like phone numbers or email addresses aren’t sensitive. However, hackers can use this information to launch a phishing campaign, steal someone’s identity, or commit fraud.

Furthermore, organizations regularly seem to think that if they see no trace of an attack, the risks aren’t too bad. However, this is false: in the event of a ransomware attack, an organization must always assume that the attackers have accessed and stolen data, until log data proves otherwise.

“Every ransomware attack is different, but the lessons are often the same. Organizations don’t have to make every mistake themselves. By learning from one another, they can significantly limit the damage to people and to their own organizations,” AP Vice Chairman Monique Verdier says in a statement.

To detect a cyberattack as soon as possible, the Dutch privacy and data protection authority recommends setting up a good monitoring system. In addition, a security protocol should be in place for when an organization falls victim to a cyberattack so they can respond immediately and effectively.

Also, victims should be informed when a data breach or security incident has occurred as soon as possible so they can spring into action.

“Ransomware costs organizations hundreds of thousands of euros. Invest in a high level of cybersecurity and address the biggest risks first. And ensure reliable and recent backups,” the AP concludes its 2025 ransomware attack report.