Global
International security developments, NATO, and geopolitical threats.
Russia expands electronic warfare corridor along Finland border, NATO confirms signal jamming affecting civilian aviation
NATO's Supreme Headquarters Allied Powers Europe (SHAPE) confirmed on 10 July that Russia has significantly expanded its electronic warfare operations corridor along the Finnish border, with persistent GPS spoofing and jamming events now affecting civilian aviation across a corridor extending from the Gulf of Finland to northern Karelia. The Finnish Transport and Communications Agency (Traficom) recorded 847 GPS anomaly events in June 2026 — a 220% increase on the monthly average for the first quarter. The disruptions have affected commercial flight navigation, maritime traffic in the Gulf of Finland, and overland logistics operations in eastern Finland. NATO is coordinating with Finnish authorities to assess the legal and operational response options under Article 3 of the North Atlantic Treaty. For organisations operating logistics, travel management, or security operations in the affected region, the disruptions underscore the fragility of GPS-dependent navigation and the importance of backup positioning systems, pre-planned alternative routing, and clear communications protocols when navigation degradation is detected.
Interpol Operation Tourniquet arrests 230 suspects in coordinated strike against executive kidnap-for-ransom networks
Interpol's Financial Crimes and Anti-Corruption Centre announced on 10 July the conclusion of Operation Tourniquet, a six-month coordinated enforcement action involving police services in 31 countries that resulted in the arrest of 230 suspects linked to executive kidnap-for-ransom (K&R) networks operating across Latin America, West Africa, the Middle East, and Southeast Asia. The operation also disrupted four active hostage situations in Mexico, Nigeria, Lebanon, and the Philippines, resulting in the safe recovery of seven foreign nationals including two European business executives. Intelligence developed during the operation identified a growing trend of K&R networks conducting advance corporate intelligence gathering — researching target executives through social media, company websites, and flight tracking applications — to identify high-value individuals, predict travel patterns, and optimise timing of abduction operations. Organisations with executives travelling to elevated K&R risk environments should review their travel security protocols, ensure executives travel with minimal visible indicators of status, and brief staff on information hygiene practices that reduce exposure of travel itineraries.
Microsoft Threat Intelligence discloses Midnight Blizzard campaign targeting European foreign ministries via Teams
Microsoft Threat Intelligence published on 9 July technical indicators for a renewed Midnight Blizzard (APT29 / Cozy Bear) campaign targeting foreign ministry staff across eight European Union member states using social engineering via Microsoft Teams. The campaign, active since May 2026, involves attackers posing as technical support representatives within Teams environments — exploiting external collaboration tenant configurations to send support requests appearing to originate from internal IT helpdesks. Victims are lured into sharing temporary access codes enabling attackers to enrol attacker-controlled devices in the target's Microsoft 365 environment, granting persistent access to email, SharePoint, and Teams conversation history. The campaign has successfully compromised accounts at foreign ministry level in at least three EU member states, according to Microsoft's assessment. Organisations using Teams with external collaboration enabled are urged to audit guest access configurations, disable automatic external user approval, and implement conditional access policies requiring device compliance verification before granting Teams access from external tenants.
European Union
EU security directives, Europol threat assessments, and policy developments.
EU Foreign Affairs Council approves expanded sanctions package against Belarus, targeting security apparatus members
The EU Foreign Affairs Council approved on 10 July a new round of targeted sanctions against Belarus, designating 47 additional individuals and 12 entities connected to the Belarusian security services, state broadcaster, and judicial system responsible for the continued repression of civil society. The package includes asset freezes and travel bans, and extends the scope of existing sanctions to cover individuals involved in facilitating the instrumentalisation of irregular migration as a hybrid threat tool against EU member states. The sanctions also target individuals connected to forced diversion to Minsk of transit flights — expanding the 2021 aviation sanctions following the Ryanair incident. For security professionals, the designation of additional security apparatus members is relevant to due diligence processes: organisations conducting business in or with counterparts connected to Belarus must now screen against the expanded list, and supply chain relationships with Belarusian state-adjacent entities warrant re-evaluation.
ECDC updates travel health guidance for sub-Saharan Africa following Clade Ib mpox spread to new provinces
The European Centre for Disease Prevention and Control (ECDC) published updated travel health guidance on 10 July for travellers and organisations deploying staff to sub-Saharan Africa, following the detection of Clade Ib mpox transmission in three new provinces in Uganda and the confirmation of sustained community spread in South Sudan. The updated guidance elevates the risk category for travel to the affected provinces and recommends that healthcare workers and security personnel with potential for close contact with local populations receive MPX vaccine (JYNNEOS) if not previously vaccinated, carry appropriate PPE, and follow enhanced hygiene protocols. Organisations with field teams in the region — including humanitarian security managers, corporate security staff overseeing extractive industry operations, and close protection officers — should review vaccination status and brief medical teams on the updated guidance. The ECDC note that JYNNEOS supply in the EU remains constrained and recommends early procurement.
Schengen border management agency Frontex reports record interceptions of concealed surveillance equipment at EU external borders
Frontex's Risk Analysis Unit published a quarterly threat assessment on 9 July documenting a record number of interceptions of concealed surveillance and communications interception equipment at EU external borders in the second quarter of 2026 — totalling 312 devices across 18 member states' border crossing points. Intercepted equipment included miniaturised IMSI catchers, concealed audio transmitters, covert video devices embedded in everyday objects, and modified GPS trackers. The report notes that the sophistication of concealed devices continues to increase, with several intercepted items requiring laboratory-level analysis to distinguish from the legitimate electronics in which they were concealed. The finding has direct implications for security professionals and diplomats crossing EU external borders: the volume of surveillance equipment in circulation is substantial, and standard luggage X-ray screening is insufficient to detect all device types. Mission personnel and executives returning from travel to adversarial environments should consider TSCM screening of personal effects and devices before re-entering sensitive working environments.
The Netherlands
AIVD, NCTV, and domestic security developments relevant to Dutch operations.
Politie confirms arrest of three men linked to series of high-value art and executive vehicle thefts in Amsterdam South
The Amsterdam-Amstelland police confirmed on 10 July the arrest of three men — aged 28, 34, and 41 — suspected of involvement in a series of 19 high-value thefts targeting art collections and premium vehicles in Amsterdam's Oud-Zuid and Apollobuurt districts between April and June 2026. The suspects are believed to have conducted advance surveillance of targets, including monitoring of daily routines and identification of security vulnerability windows. Two of the arrests resulted from analysis of ANPR camera data and a tip from a private security contractor whose mobile patrol had flagged suspicious behaviour. The arrests highlight the value of integrated physical and electronic surveillance in residential and commercial security, and the role of private security intelligence in supplementing police detection capacity. For residents and business operators in high-value property environments, the case underscores the importance of mobile patrol services, CCTV coverage with offsite monitoring, and rapid incident response protocols.
Dutch Ministry of Justice launches NIS2 sectoral audit programme for financial services and healthcare, first inspections from September
The Dutch Ministry of Justice and Security published on 10 July the operational framework for the Netherlands' NIS2 sectoral audit programme, confirming that the Rijksinspectie Digitale Infrastructuur (RDI) will conduct the first round of compliance inspections for the financial services and healthcare sectors from September 2026. The framework specifies that initial inspections will focus on governance documentation (board-level cyber risk ownership, documented incident response plans), technical controls (patch management cadence, MFA implementation, network segmentation), and supply chain security (third-party security assessments, contractual security requirements). Organisations subject to NIS2 that cannot demonstrate documented processes in these areas face formal enforcement proceedings under the Cybersecuritywet, which transposes NIS2 into Dutch law. The September timeline gives organisations approximately eight weeks to close gaps. Entities in scope should prioritise a rapid compliance gap assessment and address the highest-risk documentation gaps before inspection windows open.
Utrecht University Hospital conducts first joint CBRN mass casualty drill with Veiligheidsregio Utrecht responders
Utrecht University Medical Centre (UMC Utrecht) and the Veiligheidsregio Utrecht conducted a joint CBRN mass casualty exercise on 9 July simulating a chemical agent release at a public transit hub resulting in 150 simulated casualties requiring specialist decontamination and triage. The exercise, the first of its kind at UMC Utrecht, tested the hospital's ability to activate its CBRN mass casualty protocol, establish an outdoor decontamination corridor, and coordinate patient intake with hazmat-equipped emergency responders from the regional fire service and GHOR Utrecht. Observers from four other Dutch university hospitals participated as part of a national programme to develop standardised CBRN mass casualty response capability across the Netherlands' ten academic medical centres by the end of 2027. The exercise programme, coordinated by the NCTV, reflects growing recognition that healthcare facilities must be able to manage CBRN incidents as receivers of casualties — not just as facilities to be protected — and that this requires dedicated training beyond standard mass casualty planning.
Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.
Ready to speak with a specialist?
We respond within one business day. Initial conversations are confidential and without obligation.
Request a Consultation