Skip to content
    All briefs
    Daily Brief

    Published · 9 items · 3 Global · 3 European Union · 3 The Netherlands

    Global

    International security developments, NATO, and geopolitical threats.

    Intelligence
    Europol

    North Korean IT workers infiltrating European tech firms via remote contracting platforms, Europol warns

    Europol's European Cybercrime Centre (EC3) issued an intelligence alert on 12 July. It warns that networks of IT workers acting for North Korean state entities are systematically targeting European technology and defence contractors by posing as genuine remote freelancers on major contracting platforms. Once inside development teams, they steal source code, credentials and intellectual property, and in some cases leave backdoors that stay in place after the engagement ends. The alert was coordinated with national cyber agencies in Germany, France, the Netherlands and the UK. It estimates the scheme has earned the DPRK about €80 million in hard currency since late 2024. Affected sectors include software development, aerospace component design and defence procurement consultancies. Run enhanced due diligence on remote contractors: verify identity through video KYC, cross-check tax identification numbers against national registries, and limit contractor access to project-specific environments. For firms in regulated sectors, a mature insider threat programme is now a practical requirement.

    Our advisory and intelligence team vets remote contractors and assesses insider threat for organisations with remote workforces.

    Physical Security
    OCHA

    Sudanese paramilitary RSF targets UN aid convoy with electronic warfare jamming, killing three security escorts

    Three close protection officers contracted by a UN-affiliated humanitarian logistics operator were killed on 11 July in North Darfur. Rapid Support Forces (RSF) attacked their convoy using GPS jamming combined with drone-directed small-arms fire. The UN Office for the Coordination of Humanitarian Affairs (OCHA) documented the incident. It is the first confirmed use of electronic warfare against an NGO convoy in the region and a significant escalation in tactics. The navigation disruption pushed the convoy off its pre-cleared route into an RSF-controlled corridor, where it was ambushed. Major humanitarian operators, including MSF, WFP and UNHCR, have suspended overland operations in North and West Darfur while security is reassessed. Close protection teams working near active conflict should carry backup navigation, rehearse alternative routes in advance and keep to radio check-in schedules that do not depend on satellite positioning alone.

    We provide close protection officers and security escorts for staff who have to move through hostile and conflict-affected areas.

    Chinese intelligence operation targets diplomatic communications at G20 preparatory summit in Brazil

    Brazilian federal security services and the US National Counterintelligence and Security Center (NCSC) jointly disclosed on 12 July that a technical surveillance operation attributed to Chinese state intelligence had been detected. It targeted secure communications at a G20 preparatory working group summit in Rio de Janeiro on 9 to 11 July. IMSI catchers were deployed near the venue and at least two hotels housing delegations, alongside a phishing campaign aimed at senior delegates' personal devices. Brazilian authorities arrested two people carrying modified telecoms equipment near the venue perimeter. The speed of the disclosure stands out, since governments usually wait years before attributing counterintelligence incidents, and it is widely read as a deliberate diplomatic signal. If you host or attend multilateral summits, trade negotiations or ministerial meetings, treat them as priority TSCM sweep environments, and review mobile device security for participants before they travel.

    We carry out TSCM sweeps of summit venues, delegation hotels and meeting rooms before sensitive talks begin.

    European Union

    EU security directives, Europol threat assessments, and policy developments.

    Compliance
    EURACTIV

    EU Council adopts Hybrid Threats Regulation, mandating incident reporting for critical infrastructure operators within 24 hours

    On 11 July the Council of the European Union formally adopted the Hybrid Threats Regulation. The landmark measure extends mandatory incident reporting beyond the digital domain covered by NIS2 to physical sabotage, supply chain interference and coordinated disinformation aimed at critical infrastructure. Operators in energy, transport, water, healthcare and financial infrastructure must now notify their national competent authority within 24 hours of detecting a hybrid incident. That is defined broadly as any coordinated action using physical, digital or informational means to disrupt service delivery. Member states have 18 months to transpose the Regulation into national law. In practice, organisations will need legal and technical help to classify incidents correctly, write compliant notifications under time pressure and keep an audit trail that shows a proportionate response. Organisations active in several member states will also face notification requirements in more than one jurisdiction.

    Our advisory team helps you set up incident classification and 24-hour notification procedures that meet the new Regulation.

    Europol Operation SHIELD dismantles luxury hotel TSCM eavesdropping network operating across six EU capitals

    Europol announced on 13 July that Operation SHIELD, a 14-month joint investigation by Austria, Belgium, France, Germany, Italy and the Netherlands, has dismantled a sophisticated commercial eavesdropping network. The network had planted listening devices in boardrooms, suites and conference rooms at high-end hotels in Brussels, Vienna, Paris, Berlin, Rome and Amsterdam. Nineteen people were arrested in six countries. The network is believed to have worked for commercial intelligence clients, including at least two foreign state-affiliated entities. It used custom hardware hidden in standard room fittings such as power sockets, smoke detectors and picture frames, sending encrypted audio over the hotel Wi-Fi. The case began when a routine TSCM sweep by a security team accompanying a senior EU official found an anomalous device in a Brussels hotel. It confirms what specialist teams have long assessed: luxury hotels used for sensitive meetings are a prime target for technical eavesdropping. Sweep the room before any sensitive discussion in a hotel.

    Before sensitive discussions, we carry out TSCM sweeps of hotel meeting rooms, suites and conference spaces.

    Cyber
    ENISA

    ENISA publishes updated threat landscape for the maritime sector, flagging port cyberattack surge

    On 11 July the European Union Agency for Cybersecurity (ENISA) published its updated maritime cyber threat report. It records a 67% year-on-year rise in cyberattacks on European port operators and maritime logistics companies in the first half of 2026. The main cause is ransomware groups exploiting unpatched operational technology in port management systems, alongside more state-sponsored reconnaissance aimed at vessel tracking and cargo manifest systems. The Netherlands, home to the Port of Rotterdam, Europe's largest, is named as a high-priority target because of its critical role in EU supply chain resilience. The report recommends mandatory OT security assessments for port operators, separation of IT and OT networks, and incident response exercises that simulate vessel diversion and cargo misrouting. If your business depends on maritime supply chains, plan for what disruption at a major hub port would do to you.

    Our cyber security team assesses OT vulnerabilities and supports incident response for port, logistics and maritime operators.

    The Netherlands

    AIVD, NCTV, and domestic security developments relevant to Dutch operations.

    Intelligence
    AIVD

    AIVD annual threat assessment flags Russia and China as primary state threats to Dutch economic security

    The General Intelligence and Security Service (AIVD) published its 2026 Annual Report on 13 July. It names Russia and China as the two main state actors threatening Dutch economic security, critical infrastructure and the integrity of democratic processes. Detected foreign intelligence operations against Dutch technology companies, academic institutions and government contractors rose 34% compared with 2025. The AIVD points to a shift in Chinese tactics, away from traditional human intelligence recruitment and toward technical penetration of supply chains. The targets serve the Dutch semiconductor, aerospace and water management sectors, where the Netherlands holds globally significant market positions. The report also records more Russian hybrid operations aimed at Dutch public debate ahead of the municipal elections scheduled for March 2027. For organisations in sensitive sectors, the AIVD recommends a formal assessment of counter-intelligence capability and a clear procedure for reporting suspected approaches by foreign nationals.

    Our advisory and intelligence team assesses counter-intelligence capability and briefs staff in sensitive sectors on the threats the AIVD describes.

    Physical Security
    NCTV

    NCTV raises threat level for critical infrastructure to 'Substantial' following Port of Rotterdam incident probe

    On 12 July the National Coordinator for Security and Counterterrorism (NCTV) raised the threat level for critical infrastructure from 'Significant' to 'Substantial', the fourth tier on the five-tier Dutch scale. The decision follows a formal investigation into an incident at the Port of Rotterdam in late June involving suspected sabotage of cargo handling equipment. The full findings remain classified, but the NCTV confirmed the incident showed characteristics consistent with state-directed hybrid operations. Under the Wet beveiliging netwerk- en informatiesystemen (Wbni), the higher threat level triggers mandatory extra protective measures for critical infrastructure operators. These are more frequent security assessments, stronger perimeter monitoring and mandatory staff security awareness refreshers within 60 days. Shipping agents, customs brokers and third-party logistics providers serving Rotterdam should use the change as a prompt to review their own physical and cyber security.

    For port and logistics sites facing the higher threat level, our security officers can take over guarding and access control.

    Training
    NOS

    Amsterdam municipality mandates BHV certification for all public event operators with crowds above 500 from September 2026

    On 11 July the Municipality of Amsterdam published updated event safety rules. From 1 September 2026, every organiser of a public event expecting more than 500 people must show valid Bedrijfshulpverlening (BHV) certification for at least one certified BHV responder per 100 attendees. The rules follow a crowd safety review commissioned after incidents at European music festivals in 2025. Organisers must also submit a security plan to the municipality at least 30 days before the event, covering evacuation procedures, communication protocols and the placement of first-aid posts. Operators who don't comply risk having their permit suspended. That has real consequences for Amsterdam's events sector, since many smaller operators are currently below the new threshold. BHV training providers expect high demand in the run-up to September. If you are planning events in Amsterdam, check your current BHV ratio and book training places now so you meet the deadline.

    We run BHV training for event organisers and companies across the Netherlands, so you can reach the new ratio before September.

    Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.

    Ready to speak with a specialist?

    We respond within one business day. Initial conversations are confidential and without obligation.

    Request a Consultation