Skip to content
    All briefs
    Daily Brief

    9 items · 3 Global · 3 European Union · 3 The Netherlands

    Global

    International security developments, NATO, and geopolitical threats.

    GeopoliticsNATO

    Russia expands electronic warfare corridor along Finland border, NATO confirms signal jamming affecting civilian aviation

    NATO's Supreme Headquarters Allied Powers Europe (SHAPE) confirmed on 10 July that Russia has significantly expanded its electronic warfare operations corridor along the Finnish border, with persistent GPS spoofing and jamming events now affecting civilian aviation across a corridor extending from the Gulf of Finland to northern Karelia. The Finnish Transport and Communications Agency (Traficom) recorded 847 GPS anomaly events in June 2026 — a 220% increase on the monthly average for the first quarter. The disruptions have affected commercial flight navigation, maritime traffic in the Gulf of Finland, and overland logistics operations in eastern Finland. NATO is coordinating with Finnish authorities to assess the legal and operational response options under Article 3 of the North Atlantic Treaty. For organisations operating logistics, travel management, or security operations in the affected region, the disruptions underscore the fragility of GPS-dependent navigation and the importance of backup positioning systems, pre-planned alternative routing, and clear communications protocols when navigation degradation is detected.

    Mission Support's advisory team provides travel risk assessments and contingency planning for organisations operating in high-risk regions.

    IntelligenceInterpol

    Interpol Operation Tourniquet arrests 230 suspects in coordinated strike against executive kidnap-for-ransom networks

    Interpol's Financial Crimes and Anti-Corruption Centre announced on 10 July the conclusion of Operation Tourniquet, a six-month coordinated enforcement action involving police services in 31 countries that resulted in the arrest of 230 suspects linked to executive kidnap-for-ransom (K&R) networks operating across Latin America, West Africa, the Middle East, and Southeast Asia. The operation also disrupted four active hostage situations in Mexico, Nigeria, Lebanon, and the Philippines, resulting in the safe recovery of seven foreign nationals including two European business executives. Intelligence developed during the operation identified a growing trend of K&R networks conducting advance corporate intelligence gathering — researching target executives through social media, company websites, and flight tracking applications — to identify high-value individuals, predict travel patterns, and optimise timing of abduction operations. Organisations with executives travelling to elevated K&R risk environments should review their travel security protocols, ensure executives travel with minimal visible indicators of status, and brief staff on information hygiene practices that reduce exposure of travel itineraries.

    Mission Support provides close protection officers and K&R risk assessments for executives travelling to elevated-risk environments.

    Microsoft Threat Intelligence discloses Midnight Blizzard campaign targeting European foreign ministries via Teams

    Microsoft Threat Intelligence published on 9 July technical indicators for a renewed Midnight Blizzard (APT29 / Cozy Bear) campaign targeting foreign ministry staff across eight European Union member states using social engineering via Microsoft Teams. The campaign, active since May 2026, involves attackers posing as technical support representatives within Teams environments — exploiting external collaboration tenant configurations to send support requests appearing to originate from internal IT helpdesks. Victims are lured into sharing temporary access codes enabling attackers to enrol attacker-controlled devices in the target's Microsoft 365 environment, granting persistent access to email, SharePoint, and Teams conversation history. The campaign has successfully compromised accounts at foreign ministry level in at least three EU member states, according to Microsoft's assessment. Organisations using Teams with external collaboration enabled are urged to audit guest access configurations, disable automatic external user approval, and implement conditional access policies requiring device compliance verification before granting Teams access from external tenants.

    Mission Support's cyber security team supports embassy and diplomatic organisations with cyber resilience assessments and incident response.

    European Union

    EU security directives, Europol threat assessments, and policy developments.

    GeopoliticsEURACTIV

    EU Foreign Affairs Council approves expanded sanctions package against Belarus, targeting security apparatus members

    The EU Foreign Affairs Council approved on 10 July a new round of targeted sanctions against Belarus, designating 47 additional individuals and 12 entities connected to the Belarusian security services, state broadcaster, and judicial system responsible for the continued repression of civil society. The package includes asset freezes and travel bans, and extends the scope of existing sanctions to cover individuals involved in facilitating the instrumentalisation of irregular migration as a hybrid threat tool against EU member states. The sanctions also target individuals connected to forced diversion to Minsk of transit flights — expanding the 2021 aviation sanctions following the Ryanair incident. For security professionals, the designation of additional security apparatus members is relevant to due diligence processes: organisations conducting business in or with counterparts connected to Belarus must now screen against the expanded list, and supply chain relationships with Belarusian state-adjacent entities warrant re-evaluation.

    CBRNECDC

    ECDC updates travel health guidance for sub-Saharan Africa following Clade Ib mpox spread to new provinces

    The European Centre for Disease Prevention and Control (ECDC) published updated travel health guidance on 10 July for travellers and organisations deploying staff to sub-Saharan Africa, following the detection of Clade Ib mpox transmission in three new provinces in Uganda and the confirmation of sustained community spread in South Sudan. The updated guidance elevates the risk category for travel to the affected provinces and recommends that healthcare workers and security personnel with potential for close contact with local populations receive MPX vaccine (JYNNEOS) if not previously vaccinated, carry appropriate PPE, and follow enhanced hygiene protocols. Organisations with field teams in the region — including humanitarian security managers, corporate security staff overseeing extractive industry operations, and close protection officers — should review vaccination status and brief medical teams on the updated guidance. The ECDC note that JYNNEOS supply in the EU remains constrained and recommends early procurement.

    Mission Support provides CBRN awareness training and pre-deployment health risk briefings for organisations with staff in high-risk regions.

    Schengen border management agency Frontex reports record interceptions of concealed surveillance equipment at EU external borders

    Frontex's Risk Analysis Unit published a quarterly threat assessment on 9 July documenting a record number of interceptions of concealed surveillance and communications interception equipment at EU external borders in the second quarter of 2026 — totalling 312 devices across 18 member states' border crossing points. Intercepted equipment included miniaturised IMSI catchers, concealed audio transmitters, covert video devices embedded in everyday objects, and modified GPS trackers. The report notes that the sophistication of concealed devices continues to increase, with several intercepted items requiring laboratory-level analysis to distinguish from the legitimate electronics in which they were concealed. The finding has direct implications for security professionals and diplomats crossing EU external borders: the volume of surveillance equipment in circulation is substantial, and standard luggage X-ray screening is insufficient to detect all device types. Mission personnel and executives returning from travel to adversarial environments should consider TSCM screening of personal effects and devices before re-entering sensitive working environments.

    Mission Support conducts TSCM sweeps of devices, personal effects, and facilities for individuals returning from adversarial environments.

    The Netherlands

    AIVD, NCTV, and domestic security developments relevant to Dutch operations.

    Physical SecurityNOS

    Politie confirms arrest of three men linked to series of high-value art and executive vehicle thefts in Amsterdam South

    The Amsterdam-Amstelland police confirmed on 10 July the arrest of three men — aged 28, 34, and 41 — suspected of involvement in a series of 19 high-value thefts targeting art collections and premium vehicles in Amsterdam's Oud-Zuid and Apollobuurt districts between April and June 2026. The suspects are believed to have conducted advance surveillance of targets, including monitoring of daily routines and identification of security vulnerability windows. Two of the arrests resulted from analysis of ANPR camera data and a tip from a private security contractor whose mobile patrol had flagged suspicious behaviour. The arrests highlight the value of integrated physical and electronic surveillance in residential and commercial security, and the role of private security intelligence in supplementing police detection capacity. For residents and business operators in high-value property environments, the case underscores the importance of mobile patrol services, CCTV coverage with offsite monitoring, and rapid incident response protocols.

    Mission Support provides mobile patrol services and alarm response for residential and commercial clients across Amsterdam.

    ComplianceANP

    Dutch Ministry of Justice launches NIS2 sectoral audit programme for financial services and healthcare, first inspections from September

    The Dutch Ministry of Justice and Security published on 10 July the operational framework for the Netherlands' NIS2 sectoral audit programme, confirming that the Rijksinspectie Digitale Infrastructuur (RDI) will conduct the first round of compliance inspections for the financial services and healthcare sectors from September 2026. The framework specifies that initial inspections will focus on governance documentation (board-level cyber risk ownership, documented incident response plans), technical controls (patch management cadence, MFA implementation, network segmentation), and supply chain security (third-party security assessments, contractual security requirements). Organisations subject to NIS2 that cannot demonstrate documented processes in these areas face formal enforcement proceedings under the Cybersecuritywet, which transposes NIS2 into Dutch law. The September timeline gives organisations approximately eight weeks to close gaps. Entities in scope should prioritise a rapid compliance gap assessment and address the highest-risk documentation gaps before inspection windows open.

    Mission Support's advisory team supports NIS2 compliance gap assessments and documentation readiness for Dutch financial and healthcare operators.

    CBRNANP

    Utrecht University Hospital conducts first joint CBRN mass casualty drill with Veiligheidsregio Utrecht responders

    Utrecht University Medical Centre (UMC Utrecht) and the Veiligheidsregio Utrecht conducted a joint CBRN mass casualty exercise on 9 July simulating a chemical agent release at a public transit hub resulting in 150 simulated casualties requiring specialist decontamination and triage. The exercise, the first of its kind at UMC Utrecht, tested the hospital's ability to activate its CBRN mass casualty protocol, establish an outdoor decontamination corridor, and coordinate patient intake with hazmat-equipped emergency responders from the regional fire service and GHOR Utrecht. Observers from four other Dutch university hospitals participated as part of a national programme to develop standardised CBRN mass casualty response capability across the Netherlands' ten academic medical centres by the end of 2027. The exercise programme, coordinated by the NCTV, reflects growing recognition that healthcare facilities must be able to manage CBRN incidents as receivers of casualties — not just as facilities to be protected — and that this requires dedicated training beyond standard mass casualty planning.

    Mission Support provides CBRN training and exercise facilitation for healthcare, security, and emergency response organisations across the Netherlands.

    Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.

    Ready to speak with a specialist?

    We respond within one business day. Initial conversations are confidential and without obligation.

    Request a Consultation