Desk live·
ForensicPost
Nation-state/Utilities/File 25-0422

Disclosed in 2025, Attempted the Year Before

Dutch military intelligence revealed on 22 April 2025 that Russian actors had attempted to sabotage the digital control system of a public facility during the previous year — the first known attack on Dutch critical infrastructure.

Constructed geometry · not a chart of case data
JurisdictionNetherlandsthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetDutch public facility
ActorRussian state-linked actors
S. Rosler12 min readConfidence: medium2 sources reviewed

The Dutch Military Intelligence and Security Service disclosed on 22 April 2025 that Russian actors had attempted to sabotage the digital control system of a Dutch public facility during the preceding year, describing it as the first known cyberattack against Dutch critical infrastructure.

The Gap Between Event And Disclosure Is The File

This corpus is built on disclosure, and it has repeatedly recorded delays: 74 days at 25-1027, four months at 25-0710, breached in 2024 and disclosed in 2026 at 26-0515. Each was criticised as a structural failure of notification law.

An intelligence service operates on entirely different logic. Disclosing an attempt reveals what was detected, which reveals detection capability, which is the thing an adversary most wants to know. Holding it is not a compliance failure; it is the point.

So the corpus’s usual criticism does not transfer. It also means the incident record for this category is systematically delayed by years, and nothing in this database corrects for that.

"Attempted" And "First Known" Both Carry Weight

Attempted means it did not succeed, which distinguishes it from every industrial-control file in this corpus and makes it a rare recorded instance of a defence working.

First known means first detected and disclosed. It is not a claim that nothing preceded it — the pre-positioning logic at 25-0522 and 26-0715 describes adversaries whose objective is to remain unnoticed, and the corpus should read "first known" as a statement about detection.

Sabotage Of A Control System Is A Different Objective

Nothing here was for sale. There was no extortion demand, no data to publish, no monetisation path. The objective was to affect a physical system.

That is the category the Polish grid file at 25-1229 also touches, and it is the one this database is least equipped to record — because it produces no notification, no affected count, and frequently no public acknowledgement until a security service chooses to speak.

How we reported this

Compiled from published reporting of an intelligence service disclosure, listed below. The facility is not identified. Attribution is the service’s assessment as reported. Corrections: corrections@forensicpost.com.

Sources
  1. Significant cyber incidentsCSIS
  2. Cyber Brief 25-05 — April 2025CERT-EU
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary