Skip to content
    All briefs
    Daily Brief

    9 items · 3 Global · 3 European Union · 3 The Netherlands

    Global

    International security developments, NATO, and geopolitical threats.

    IntelligenceEuropol

    North Korean IT workers infiltrating European tech firms via remote contracting platforms, Europol warns

    Europol's European Cybercrime Centre (EC3) issued an intelligence alert on 12 July warning that networks of IT workers operating on behalf of North Korean state entities are systematically targeting European technology and defence contractors by posing as legitimate remote freelancers on major contracting platforms. Once embedded within development teams, operatives exfiltrate source code, credentials, and intellectual property — in some cases deploying backdoors that persist after engagement termination. The alert, coordinated with national cyber agencies in Germany, France, the Netherlands, and the UK, notes that the scheme has generated an estimated €80 million in hard currency for the DPRK since late 2024. Affected sectors include software development, aerospace component design, and defence procurement consultancies. Organisations are advised to conduct enhanced due diligence on remote contractors, including identity verification through video KYC, cross-referencing of tax identification with national registries, and restricted access controls that limit contractor reach to project-specific environments only. Insider threat programme maturity is now a practical requirement, not an aspiration, for firms in regulated sectors.

    Mission Support's advisory and intelligence team conducts insider threat assessments and contractor vetting for organisations with remote workforces.

    Physical SecurityOCHA

    Sudanese paramilitary RSF targets UN aid convoy with electronic warfare jamming, killing three security escorts

    Three close protection officers contracted by a UN-affiliated humanitarian logistics operator were killed on 11 July when a convoy operating in North Darfur was targeted by Rapid Support Forces (RSF) using a combination of GPS jamming and drone-directed small arms fire. The incident, documented by the UN Office for the Coordination of Humanitarian Affairs (OCHA), marks the first confirmed use of electronic warfare assets against an NGO convoy in the region and signals a significant escalation in tactics. Navigation disruption caused the convoy to deviate from its pre-cleared route into an RSF-controlled corridor, where it was ambushed. The incident has prompted major humanitarian operators — including MSF, WFP, and UNHCR — to suspend overland operations in North and West Darfur pending security reassessment. Close protection teams operating in active conflict-adjacent environments are advised to incorporate redundant navigation systems, pre-rehearsed alternative route protocols, and regular radio communications schedules that do not rely on satellite positioning alone.

    Mission Support provides close protection officers and security escorts for personnel operating in hostile and conflict-adjacent environments.

    Chinese intelligence operation targets diplomatic communications at G20 preparatory summit in Brazil

    Brazilian federal security services and the US National Counterintelligence and Security Center (NCSC) jointly disclosed on 12 July that a technical surveillance operation attributed to Chinese state intelligence was detected targeting secure communications infrastructure at a G20 preparatory working group summit held in Rio de Janeiro on 9–11 July. The operation involved the deployment of IMSI catchers in proximity to the summit venue and at least two hotels housing delegations, alongside a phishing campaign targeting personal devices of senior delegates. Brazilian authorities arrested two individuals carrying modified telecommunications equipment near the venue perimeter. The disclosure is notable for its speed — governments typically wait years before attributing counterintelligence incidents — and is widely interpreted as a deliberate diplomatic signal. Organisations hosting or attending multilateral summits, trade negotiations, or ministerial meetings are reminded that high-stakes gatherings constitute priority TSCM sweep environments, and that mobile device security protocols for participants warrant review before travel.

    Mission Support conducts TSCM sweeps for summit venues, delegation accommodations, and sensitive meeting environments.

    European Union

    EU security directives, Europol threat assessments, and policy developments.

    ComplianceEURACTIV

    EU Council adopts Hybrid Threats Regulation, mandating incident reporting for critical infrastructure operators within 24 hours

    The Council of the European Union formally adopted the Hybrid Threats Regulation on 11 July, a landmark legislative measure that extends mandatory incident reporting obligations beyond the digital domain addressed by NIS2 to cover physical sabotage, supply chain interference, and coordinated disinformation operations targeting critical infrastructure. Operators in sectors including energy, transport, water, healthcare, and financial infrastructure are now required to notify their national competent authority within 24 hours of detecting a hybrid incident — defined broadly to include any coordinated action combining physical, digital, or informational means intended to disrupt service delivery. Member states have 18 months to transpose the Regulation into national law. For security professionals, the Regulation creates a new advisory mandate: organisations will need legal-technical support to correctly classify incidents, draft compliant notifications under time pressure, and maintain the audit trail demonstrating proportionate response. Organisations operating across multiple member states face the added complexity of multi-jurisdictional notification requirements.

    Mission Support's advisory team supports organisations in building incident classification frameworks and compliant notification procedures.

    Europol Operation SHIELD dismantles luxury hotel TSCM eavesdropping network operating across six EU capitals

    Europol announced on 13 July that Operation SHIELD — a 14-month joint investigation involving Austria, Belgium, France, Germany, Italy, and the Netherlands — has dismantled a sophisticated commercial eavesdropping network that had installed listening devices in boardrooms, suites, and conference facilities at high-end hotels across Brussels, Vienna, Paris, Berlin, Rome, and Amsterdam. Nineteen individuals were arrested across six countries. The network, believed to be operated for commercial intelligence clients including at least two foreign state-affiliated entities, used custom hardware concealed in standard room fixtures — power sockets, smoke detectors, and picture frames — transmitting encrypted audio over hotel Wi-Fi infrastructure. The operation was initiated after a routine TSCM sweep conducted by a security team accompanying a senior EU official at a Brussels hotel detected an anomalous device. The disclosure confirms what specialist security teams have long assessed: luxury hospitality venues used for sensitive meetings are a primary target environment for technical eavesdropping operations, and TSCM sweeps should be treated as standard operating procedure before any sensitive discussion in a hotel environment.

    Mission Support conducts professional TSCM sweeps for hotel meeting rooms, suites, and conference environments before sensitive discussions.

    CyberENISA

    ENISA publishes updated threat landscape for the maritime sector, flagging port cyberattack surge

    The European Union Agency for Cybersecurity (ENISA) published its updated Maritime Cyber Threat Landscape report on 11 July, documenting a 67% year-on-year increase in cyberattacks targeting European port operators and maritime logistics companies in the first half of 2026. The report attributes the surge primarily to ransomware groups exploiting unpatched operational technology systems in port management infrastructure, alongside a rising volume of state-sponsored reconnaissance operations targeting vessel tracking and cargo manifest systems. The Netherlands — home to the Port of Rotterdam, Europe's largest — is specifically identified as a high-priority target due to its critical role in EU supply chain resilience. The report recommends mandatory OT security assessments for port operators, network segmentation between IT and OT environments, and incident response exercises that simulate vessel diversion and cargo misrouting scenarios. For organisations dependent on maritime supply chains, the report underscores the systemic risk exposure that logistics disruptions at major hub ports create.

    Mission Support's cyber security team supports OT vulnerability assessments and incident response for logistics and maritime operators.

    The Netherlands

    AIVD, NCTV, and domestic security developments relevant to Dutch operations.

    IntelligenceAIVD

    AIVD annual threat assessment flags Russia and China as primary state threats to Dutch economic security

    The General Intelligence and Security Service (AIVD) published its 2026 Annual Report on 13 July, identifying Russia and China as the two primary state actors posing threats to Dutch economic security, critical infrastructure, and the integrity of democratic processes. The report documents a 34% increase in detected foreign intelligence operations targeting Dutch technology companies, academic institutions, and government contractors compared with 2025. Notably, the AIVD highlights a shift in Chinese intelligence tactics from traditional human intelligence recruitment toward technical penetration of supply chains serving Dutch semiconductor, aerospace, and water management sectors — industries in which the Netherlands holds globally significant market positions. The report also documents increased Russian hybrid operations targeting Dutch public discourse ahead of municipal elections scheduled for March 2027. For organisations in sensitive sectors, the AIVD recommends formal counter-intelligence capability assessments and structured protocols for reporting suspected approaches by foreign nationals.

    Mission Support's advisory and intelligence team provides counter-intelligence assessments and threat briefings for organisations in sensitive sectors.

    Physical SecurityNCTV

    NCTV raises threat level for critical infrastructure to 'Substantial' following Port of Rotterdam incident probe

    The National Coordinator for Security and Counterterrorism (NCTV) announced on 12 July an upward revision of the threat level for critical infrastructure from 'Significant' to 'Substantial' — the fourth tier on the five-tier Dutch threat scale — following the conclusion of a formal investigation into an incident at the Port of Rotterdam in late June involving suspected sabotage of cargo handling equipment. While full investigation findings remain classified, the NCTV confirmed that the incident exhibited characteristics consistent with state-directed hybrid operations. The elevated threat level triggers mandatory additional protective measures for operators of critical infrastructure under the Wet beveiliging netwerk- en informatiesystemen (Wbni), including increased frequency of security assessments, enhanced perimeter monitoring, and mandatory staff security awareness refreshers within 60 days. Organisations in the port logistics ecosystem — shipping agents, customs brokers, and third-party logistics providers serving Rotterdam — should treat the elevated threat level as a prompt to review their own physical and cyber security posture.

    Mission Support provides manned guarding, access control, and security assessments for critical infrastructure and logistics facilities.

    TrainingNOS

    Amsterdam municipality mandates BHV certification for all public event operators with crowds above 500 from September 2026

    The Municipality of Amsterdam published updated event safety regulations on 11 July requiring all operators of public events with anticipated attendance above 500 persons to demonstrate valid Bedrijfshulpverlening (BHV) certification for a minimum ratio of one certified BHV responder per 100 attendees, effective 1 September 2026. The regulation, enacted following a crowd safety review commissioned after incidents at European music festivals in 2025, also mandates that event operators submit a security plan to the municipality at least 30 days before the event, including evacuation procedures, communication protocols, and first-aid station placement documentation. Non-compliant operators face permit suspension. The change has significant practical implications for Amsterdam's events sector, with many smaller operators currently below the new certification threshold. Training providers offering BHV certification courses are expected to face high demand in the run-up to September. Organisations planning events in Amsterdam should verify their current BHV ratios and book training capacity immediately to ensure compliance before the deadline.

    Mission Support delivers BHV training and certification programmes for event operators and corporate clients across the Netherlands.

    Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.

    Ready to speak with a specialist?

    We respond within one business day. Initial conversations are confidential and without obligation.

    Request a Consultation