READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Dutch Intelligence Forecasts Sharp Rise in Chinese Hacking of Firewalls and VPNs; Beijing Denies It

Dutch Intelligence Forecasts Sharp Rise in Chinese Hacking of Firewalls and VPNs; Beijing Denies It
The Netherlands' two intelligence services said on Oct. 7 that Chinese cyberattacks through firewalls, VPN gateways and similar edge devices will grow strongly in the coming years, aided by AI. China's embassy called the assessment baseless. The Dutch point to a 2024 campaign that reached at least 20,000 FortiGate devices worldwide as precedent.

The Dutch Military Intelligence and Security Service (MIVD) and the General Intelligence and Security Service (AIVD) issued a joint cyber advisory on Wednesday, Oct. 7. The core prediction: attacks by Chinese hackers through vulnerable "edge devices" will increase strongly over the next few years.

Edge devices are the boxes that sit between an organization and the open internet. Firewalls, VPN gateways, proxies and login portals all qualify. The advisory was prepared with the Dutch National Cyber Security Centre (NCSC-NL).

Source code and AI

The two agencies say Chinese hackers know these devices in intimate detail. They study Western hardware and software closely and, in some cases, have obtained non-public source code, the advisory says. That lets them hunt for vulnerabilities the manufacturer does not know about.

The advisory says some of that code was obtained through cyber espionage. It does not name the products or companies affected.

The agencies also say China's commercial and research sectors support the effort. According to the advisory, some Chinese firms research flaws in Western products and some sell ready-made attack tools. The Dutch also point to a 2021 Chinese law requiring people to report flaws they find, and to training programs aimed at hacking edge devices.

Then there is AI. The services say it helps hackers find and exploit vulnerabilities faster than before, and turn newly disclosed flaws into working attacks more quickly. The advisory says risk climbs sharply once a flaw becomes public. It also says Chinese hackers often use old, known flaws, not just secret ones.

Dutch Defense Minister Dylan Yesilgöz repeated the message on X. "Artificial intelligence allows hackers to find and exploit vulnerabilities more quickly. Chinese hackers are also taking advantage of this," she wrote.

Last month, NCSC director Matthijs van Amelsvoort warned that AI is automating the attack chain, from finding vulnerabilities to exploiting them. Dutch authorities believe attackers do not need the most advanced models; widely available tools may be enough.

The Coathanger precedent

The forecast builds on a case the Dutch made public in early 2024. Chinese state hackers broke into a Dutch military network by exploiting a flaw in Fortinet's FortiGate firewalls and planted a spying tool called Coathanger.

Dutch authorities later said the campaign was far larger than first thought. It hit at least 20,000 FortiGate devices worldwide, including those at Western government departments, diplomatic missions and defense contractors. The hackers began exploiting the flaw at least two months before Fortinet announced it.

The Dutch network involved was used for unclassified research and was standalone, so the wider defense network was not affected.

Beijing's response

The Chinese Embassy in the Netherlands rejected the advisory in a spokesperson's statement. It said the report "seriously damages China's image" and is "full of untruthful words and baseless accusations."

"China expresses its strong dissatisfaction and resolute opposition to this," the embassy said. It added that China is "one of the primary victims of cyberattacks" and has consistently cracked down on malicious cyber activity in accordance with the law. The embassy urged Dutch authorities to "stop baseless accusations under the pretext of cybersecurity."

The MIVD had already flagged the rise in Chinese edge-device hacking in its most recent annual report. The AIVD notes that many hacking groups target these devices, but says Chinese hackers in particular are known for the approach.

What the agencies want organizations to do

The advisory pushes "defense in depth":

  • Install security updates promptly.
  • Use multi-factor authentication across the organization.
  • Segment the network.
  • Encrypt data at several layers.
  • Run custom-configured firewalls and intrusion detection.
  • Diversify equipment suppliers, so a flaw in one vendor's products cannot compromise multiple layers of security at once.

The agencies also stress logging, and their language is blunt. "Practice shows that victims of a cyberattack are often unable to provide the necessary log files," they say. Logs are often not stored at all, or kept for a very short time. Incident logs are also frequently stored locally on the compromised device, where an intruder "can alter or delete" them.

The fix they recommend is centralized logging, stronger monitoring and "forensic readiness," meaning an organization can launch a forensic investigation immediately after a breach. They also recommend that staff practice those investigations periodically.

The advisory is public, but the intelligence behind its claims about source-code theft is not. The agencies have not said which vendors' code was taken. Whether any manufacturer confirms it is an open question.

The Dutch recommendation that organizations hold their own logs off the device is the concrete step the agencies say would leave victims able to prove what happened.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

unknown
Tech TimesDutch Intelligence: Chinese Malware Survives Firmware Patches, Compromised 20,000 Edge Devices - Tech Times
unknown
CybernewsChinese hackers target edge devices, Dutch agencies warn
unknown
ua.newsThe Dutch Ministry of Defense reported cyberattacks by Chinese hackers using AI
unknown
english.aivd.nlMIVD and AIVD warn of increase in Chinese cyber attacks through edge devices | AIVD
unknown
SBS News (South Korea)Netherlands Warns of Potential Increase in Cyberattacks from China, Prompting Strong Backlash
unknown
koreapostNetherlands warns of surge in Chinese cyber attacks targeting VPNs and firewalls as Beijing rejects allegations
unknown
privacysavvyDutch Intelligence Warns Chinese Hackers Have Source Code for Western Network Devices