DCG A.I CyberSecurity Scoring
DCG
Company Information
Website:http://dutchessny.gov
Employees number:126
Number of followers:331
NAICS:92
Industry Type:Government Administration
Homepage:dutchessny.gov
DCG Risk Score (AI oriented)
Between 550 and 599
DCGGovernment Administration
Updated:
17/07/2026
17/07/2026
590/1000
Very Poor
Ca
DCG Global Score (TPRM)
xxxx
DCGGovernment Administration
Score locked

DCGVery Poor
Current Score
590Ca (VERY POOR)
01000
3 incidents
-83.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
590
JUNE 2026
587
MAY 2026
582
APRIL 2026
580
MARCH 2026
673
Breach
12 Mar 2026 • DCG
Dutch municipality of Epe: Nearly all Epe residents affected by major data breach involving personal details
Massive Data Breach Exposes Personal Information of Nearly All Epe Residents
575
CRITICAL-98
DUT1776969214
Massive Data Breach Exposes Personal Information of Nearly All Epe Residents
On March 12, the Dutch municipality of Epe suffered a severe data breach, resulting in the theft of sensitive information belonging to nearly all of its residents. An investigation revealed that attackers accessed approximately 552,000 files, including names, addresses, birth details, gender, and BSN (citizen service) numbers. For individuals who had interacted with municipal services, additional data such as contact details, bank account information, and copies of IDs may also have been compromised.
The municipality will notify all affected residents by letter, with those whose ID copies were stolen receiving separate communication. Impacted individuals will be eligible for free ID replacements. Authorities have not confirmed whether the attackers have made ransom demands or if the stolen data has been leaked.
The breach was executed using the ClickFix technique, where victims were tricked into clicking a malicious link disguised as a system error, granting hackers access to municipal systems. While DigiD login credentials used for Dutch government services were not exposed (as they are not stored by the municipality), officials warn of potential risks, including identity theft and phishing attempts.
Epe has reported the incident to Dutch police and the Dutch Data Protection Authority (AP). In response, the municipality has reset staff passwords and implemented additional security measures. Cybersecurity experts, alongside law enforcement, are monitoring for any public release of the stolen data. No further details on attacker communication have been disclosed.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
740
Breach
12 Feb 2026 • DCG
Dutch Police: Man arrested for demanding reward after accidental police data leak
Dutch Man Arrested for Extortion After Downloading Mistakenly Shared Police Files
671
MEDIUM-69
DUT1771273454
Dutch Man Arrested for Extortion After Downloading Mistakenly Shared Police Files
Dutch authorities arrested a 40-year-old man from Ridderkerk on Thursday evening after he downloaded confidential police documents sent in error and allegedly demanded compensation in exchange for their deletion. The suspect, detained at his Prinses Beatrixstraat residence, faces charges of computer hacking following a failed extortion attempt.
The incident began on February 12 when the man contacted police about images potentially relevant to an investigation. Instead of providing an upload link, an officer mistakenly shared a download link to sensitive files. Despite recognizing the error, the man proceeded to download the documents. When police instructed him to delete the materials, he reportedly refused unless given "something in return."
Under Dutch law, knowingly accessing files from a misdirected link especially after being told not to can constitute computer trespass. Authorities emphasized that recipients of unintended confidential data have a legal obligation to report the error and avoid retaining or distributing such materials.
While police confirmed the breach and launched an investigation, they stated there is no evidence the files were shared beyond the suspect’s possession. A search of his home yielded data storage devices as part of the ongoing probe. The case highlights the legal risks of exploiting administrative errors involving sensitive information.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
740
DECEMBER 2025
739
NOVEMBER 2025
739
OCTOBER 2025
738
SEPTEMBER 2025
738
AUGUST 2025
737
SEPTEMBER 2024
762
Cyber Attack
01 Sep 2024 • DCG
NATO-aligned government agencies and Dutch National Police Force: An Alleged Russian FSB Hacker Traveled To Thailand. Now He's Facing 10 Years In A US Prison.
Russian-Backed Hacking Group 'Laundry Bear' Targets Dutch Police in High-Profile Cyber Espionage Case
729
CRITICAL-33
NATDUT1784276720
Russian-Backed Hacking Group "Laundry Bear" Targets Dutch Police in High-Profile Cyber Espionage Case
In September 2024, Dutch cybersecurity experts uncovered a breach in the National Police Force’s systems, where attackers accessed an employee’s email account using a stolen browser cookie. The intrusion exposed the contacts of up to 64,000 police personnel, along with potential informants and sensitive sources. Dutch military intelligence later attributed the attack to Laundry Bear (also known as Void Blizzard), a Russian state-backed hacking group described as "particularly successful" in cyber sabotage.
The breach sparked widespread concern among Dutch lawmakers and security agencies, with officials confirming it marked the first known instance of deliberate Russian cyber sabotage against the Netherlands. The fallout prompted a broader investigation into the group’s activities, which extended beyond Dutch targets to include NATO-aligned government agencies and organizations supporting Ukraine’s resistance against Russia’s invasion.
The case took a dramatic turn in November 2024, when Denis Obrezko, a 35-year-old Russian IT programmer from Samara, was arrested in Phuket, Thailand, on a U.S. warrant. Authorities seized his laptop, phone, and a digital wallet during the raid. Extradited to the U.S. in late 2024, Obrezko pleaded not guilty in a Boston federal court to charges of hacking nearly a dozen U.S. companies and government agencies, facing up to 10 years in prison.
Obrezko’s background raised further suspicions. According to FBI affidavits, he had worked for Russia’s Federal Security Service (FSB) from 2012 to 2017 before joining Yutek-NN, a company licensed to sell covert surveillance technology and reportedly linked to former FSB officers. At the time of his arrest, Obrezko served as Yutek’s deputy director, a role U.S. prosecutors allege involved cyberespionage operations on behalf of the Russian government.
Investigators traced Obrezko’s digital footprint through cryptocurrency transactions, reused usernames, and a Russian phone number linked to multiple accounts, including social media and PayPal. His alleged co-conspirator, identified in court documents as "Ethan Hunt" (a reference to the Mission: Impossible character), remains at large. The FBI’s case against Obrezko relied on a chain of smaller operational errors, including his failure to mask his identity across platforms a common pitfall in long-term counterintelligence investigations.
The arrest highlighted Russia’s blurred lines between cybercriminals and state intelligence, a dynamic Western experts say enables hackers to operate with impunity as long as they avoid targeting Russian entities. Unlike typical ransomware attacks, the Dutch breach lacked a clear financial motive, leading analysts to speculate that Obrezko may have been directly employed by the Russian state or selling stolen data to government agencies.
Obrezko’s case is notable for its rarity in recent years, as extraditions of Russian hackers on U.S. warrants have declined since 2021. His travel to Thailand a country where Russian operatives have historically faced lower risks proved a miscalculation, with experts suggesting he either underestimated Western intelligence or overestimated protections from Moscow. His defense lawyer, Maksim Nemtsev, stated Obrezko would vigorously contest the charges in court.
The incident also tied back to earlier Russian cyber operations, including a 2021 breach of Aleksei Navalny’s anti-corruption organization, where over 500,000 email addresses were stolen via fake domains. Investigations linked those attacks to Mikhail Dudin, a Samara-based businessman with FSB connections, whose company, Yutek-NN, employed Obrezko.
As the case unfolds, it underscores the persistent threat of Russian cyber espionage, particularly against Western governments and organizations supporting Ukraine. The Dutch government formally identified Laundry Bear as a state-supported threat actor in May 2025, while Microsoft’s concurrent report labeled the group Void Blizzard, though neither disclosed specific individuals or companies involved. Obrezko’s arrest serves as a rare disruption in Russia’s otherwise unchecked cyber operations, offering a glimpse into the high-stakes cat-and-mouse game between Moscow’s hackers and Western law enforcement.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for DCG ??
What was DCG's A.I Rankiteo Cyber Score in June 2026 ??
What was DCG's A.I Rankiteo Cyber Score in May 2026 ??
What was DCG's A.I Rankiteo Cyber Score in April 2026 ??
What was DCG's A.I Rankiteo Cyber Score in March 2026 ??
What was DCG's A.I Rankiteo Cyber Score in February 2026 ??
What was DCG's A.I Rankiteo Cyber Score in January 2026 ??
What was DCG's A.I Rankiteo Cyber Score in December 2025 ??
What was DCG's A.I Rankiteo Cyber Score in November 2025 ??
What was DCG's A.I Rankiteo Cyber Score in October 2025 ??
What was DCG's A.I Rankiteo Cyber Score in September 2025 ??
What was DCG's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on DCG's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with DCG ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view DCG's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?