Security services expect more Chinese cyber-attacks via firewalls
AIVD and MIVD warn organisations about attacks on devices at the edge of their networks.
Dutch security services expect more Chinese cyber-attacks via firewalls, VPN servers and other devices directly connected to the internet in the coming years. AIVD and MIVD have published new security guidance together with the NCSC.
The warning concerns so-called edge devices: equipment that connects an internal network to the internet. Examples include firewalls, VPN gateways and internet portals. According to AIVD and MIVD, such devices are attractive targets because a vulnerability can provide access to a larger network.
The services say that Chinese cyber actors have in-depth knowledge of Western hardware and software. In some cases, attackers are even said to have access to source code. This enables them to investigate vulnerabilities before manufacturers become aware of them. According to the Ministry of Defence, artificial intelligence can help exploit discovered weaknesses more quickly.
The services present this expectation as an intelligence assessment, not as a measurement of an exact number of attacks. In their 2025 annual report, AIVD and MIVD had already written that Chinese groups systematically target European, NATO and Dutch interests. They also warned that only part of the attacks is likely to be detected in time.
The warning does not mean that every attack on a Dutch firewall can be attributed to China. The services write that state involvement cannot always be established immediately and that opportunistic attackers worldwide can also exploit the same vulnerabilities.
The new guidance calls on organisations to map all directly accessible devices, install security updates promptly and use multiple layers of security. Two-step verification and proper monitoring of access rights are also mentioned. The NCSC is contributing to the guidance.
For companies, government bodies and vital organisations, the main task according to the services is not only to purchase new security products. They must also know which devices are actually connected to the internet and whether old systems are still being maintained. Unknown or forgotten connections in particular can provide an entry point.
One story, several perspectives
What is established
- AIVD and MIVD expect an increase in Chinese attacks on internet-facing devices.
- The services have published security guidance together with the NCSC.
- Public sources do not contain a complete overview of the number of attacks.
Left
Arguments The government must better protect vital digital infrastructure and cannot shift security obligations entirely onto smaller organisations with fewer resources to deal with them.
Values Collective security, protection of public services and reducing power disparities between large and small organisations.
Consequences Without public investment and oversight, vulnerable organisations could become a gateway into wider systems across society.
Centre
Arguments The warning calls for proportionate standards, better information-sharing and cooperation between government and business, without imposing the same burdensome requirements on every company.
Values Resilience, practicality and careful use of government power.
Consequences A joint approach can raise baseline security, but requires clear responsibilities and measurable standards.
Right
Arguments Organisations must first and foremost take responsibility for their own systems. The government should act in a targeted way against state actors and avoid unnecessary bureaucracy.
Values Personal responsibility, national security and room for entrepreneurship.
Consequences Stricter rules can increase costs and hamper innovation; inadequate security can at the same time increase economic and security risks.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The main claims are based directly on publications by AIVD, MIVD and the Ministry of Defence. The text clearly distinguishes between an expected trend and proven individual attacks.
- confirmed AIVD and MIVD expect more Chinese attacks via edge devices. — This is stated in the joint cyber guidance and the Ministry of Defence's explanation. source
- confirmed Edge devices include firewalls, VPN gateways and portals, among other things. — Examples are given in the Ministry of Defence's explanation. source
- confirmed AI can help attackers find and exploit vulnerabilities more quickly. — The claim appears in the Ministry of Defence's publication. source
- confirmed Only part of Chinese attacks is likely to be detected in time. — This is stated in AIVD's annual report on China. source
Editor's note
It is certain that AIVD and MIVD expect an increase and have published guidance. There is no public figure for the number of attacks or any new specific attack on the Netherlands.Sources
- Meer Chinese cyberaanvallen verwacht — Ministerie van Defensie
- Cyberadvies Edge devices structureel doelwit van Chinese cyberactoren — AIVD
- China — AIVD
More on this in Dutch media
- RTL Nieuws — „cyberaanvallen china”
- FD — „cyberaanvallen china”
- Trouw — „cyberaanvallen china”