LockBit leads a four-fold jump in Dutch leak-site listings

Published

Seven Dutch organizations were added to ransomware leak sites between Monday 31 August and Friday 4 September, according to IntelFusions incident records. The Netherlands normally sees fewer than two a week. The last time the country logged seven in a single week was the last week of May, so this ties the worst week the country has had in 2026.

Four of the seven came from one crew.

LockBit, which we track as Rust Flux, posted three Dutch names on 31 August alone: All Steel Products, a hydraulics wholesaler, and two smaller firms identified only by their domains, bartelsbv.nl and vkj.nl. On 4 September it added Huisartsencentrum Klein Iterson, a general-practice clinic. In our data that is only the second Dutch healthcare organization to appear on any leak site this year, and a family doctor's practice holds exactly the kind of records an extortion crew likes to threaten with.

Every one of these is an unverified claim written by the criminals themselves. None of the seven organizations has publicly confirmed an intrusion, and a leak-site entry is a negotiating tactic as much as it is a record of a breach. What the listings show reliably is where a crew is pointing.

Almost half of LockBit's week was Dutch

The Dutch cluster is out of proportion for LockBit as well as for the Netherlands. The crew posted nine claims worldwide in the same five days: four in the Netherlands, three in the United States, one in Germany (KALA Health, another healthcare provider) and one in Japan. It has named eleven Dutch organizations in 2026, and four of them arrived this week; in the thirteen weeks before this one it managed six.

The brand itself is far quieter than in June, when it posted 26 and 33 victims in consecutive weeks, a flood we covered at the time; since early August it has run at four to ten a week. A quieter LockBit concentrating on one small country is a different problem from a loud one.

The usual Dutch crews sat this week out

Over the previous eight weeks the Netherlands' most frequent lister was Qilin with three entries, then Aurora and LockBit with two each. Qilin posted no Dutch victims this week. The other three entries came from Settra (buroboot.nl, 3 September), Akira (Algra Group, an industrial input-systems maker, 2 September) and Brain Cipher (Adviesbureau De Beuckelaer, a consultancy, 31 August). We reported last week that Brain Cipher had resurfaced after six quiet weeks and that Settra has quietly become one of the busiest brands on the leak sites. Both are now working Dutch targets.

Why one Monday inflates the whole week

Four of the seven entries were posted on 31 August. Leak sites publish in batches, so a single upload can make a week look like a campaign. The defensible reading is narrower: Dutch organizations are moving through more crews' publication queues at once than at any point since May, and LockBit in particular has a run of Dutch mid-market victims to post. That is a shift worth a Dutch defender's attention, not proof that seven companies were encrypted in a week.

The victims are small and mid-sized, none with a press office. Firms like these rarely make the news even when a claim is real, which keeps the negotiation cheap for the crew.

Report it to NCSC-NL, and check the ESXi hosts

The leak-site posts say nothing about how anyone got in, and we will not guess. What is documented is LockBit's tooling: our earlier analysis of LockBit 5.0 found Windows and Linux builds and a routine for shutting down virtual machines on ESXi hosts ahead of encryption. For a mid-sized Dutch firm the virtualization host and the backup appliance are where the business actually lives, and they are usually the least-watched systems on the network. Confirm that at least one backup copy sits out of reach of a compromised domain administrator account.

The Netherlands rates as a high-targeting country in our profile, a major transit hub for European internet infrastructure with a mature response system under NCSC-NL. Organizations that find themselves on a leak site should report there, and a practice holding patient records should assume the GDPR's 72-hour breach-notification clock is already running. A quiet negotiation teaches the next Dutch company on the list nothing.

This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions