Investigation: Public Prosecution Service had inadequate IT security before hack
Committee identifies missing monitoring and outdated systems as key structural weaknesses.
The Public Prosecution Service’s IT security was inadequate when the organisation was hit by a cyberattack in July 2025. This is stated by a committee led by Jaap Smit in an evaluation report made public on Thursday.
The committee investigated the attack, the Public Prosecution Service’s response and the consequences for the criminal justice chain. The report was sent to the Lower House (Tweede Kamer) on 8 October. The Public Prosecution Service says it accepts the conclusions and has announced additional oversight of improvements to the systems.
According to the investigation, the intrusion began with what is known as a zero-day vulnerability in Citrix NetScaler. This is a security flaw that is not yet known to the supplier at the time it is exploited. As a result, the attack could not have been completely prevented, according to the committee. After the National Cyber Security Centre warned of a possible compromise, the Public Prosecution Service disconnected its internal systems from the internet.
The committee considers the decision to go offline understandable and sensible. At the same time, the organisation was insufficiently prepared before the attack. Permanent monitoring was missing from a crucial Citrix system, meaning the Public Prosecution Service could not immediately detect suspicious activity. There had also been warnings for some time about outdated systems, limited capacity and overdue maintenance.
The report does not provide a definitive answer to the question of who was behind the attack. There are indications, however, of involvement by a party that may be linked to a state. According to the Public Prosecution Service, there is no reason to assume that information was taken and the highly secured environment was not compromised. That statement does not rule out that the intrusion was serious; it says only what has been established so far.
Since the incident, monitoring has been expanded and the Public Prosecution Service says it can investigate suspicious patterns more quickly. The committee identifies improved information provision and the appointment of a chief information officer at board level as improvements. The Public Prosecution Service also says it will receive an additional €50 million annually for its IT programme and wants to establish an independent review board.
The issue affects more than the Public Prosecution Service’s internal operations. If the digital systems of the police, courts and prosecutors are unavailable, criminal cases may be delayed and the entire chain becomes dependent on emergency procedures. The committee therefore warns that improvements are needed not only within the Public Prosecution Service, but also in cooperation between organisations in the chain.
One story, several perspectives
What is established
- A committee concluded that the Public Prosecution Service’s IT security was inadequate before the intrusion.
- The attack used a vulnerability in Citrix NetScaler that was unknown at the time.
- The Public Prosecution Service has since expanded monitoring and other security measures.
Left
Arguments The government must invest structurally in public-sector IT and must not allow essential criminal justice infrastructure to depend on temporary projects or market logic.
Values Public control, protection of citizens and collective responsibility.
Consequences More permanent capacity and independent oversight may increase costs, but reduce the risk that backlogs are again shifted onto staff and citizens.
Centre
Arguments The key is professional risk management: clear responsibilities, measurable improvement plans and independent scrutiny without bringing the operational criminal justice chain to a standstill.
Values Continuity, feasibility and institutional reliability.
Consequences Phased modernisation prevents new disruption, but requires years of administrative discipline.
Right
Arguments An organisation that manages investigative information must itself demonstrably meet stricter security standards, and those responsible for its governance must be held accountable.
Values Security, authority and responsibility.
Consequences Stricter oversight and clear lines of accountability can compel faster intervention, but must not paralyse the effectiveness of investigations.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The article’s central point is directly based on the committee’s report and the Public Prosecution Service’s response. Uncertain aspects, such as the attacker’s identity, are explicitly presented as uncertain.
- confirmed The committee concluded that the Public Prosecution Service’s IT security was inadequate before the intrusion. — This is stated in the Public Prosecution Service’s official response and in the letter to the Lower House. source
- confirmed The attack used a zero-day vulnerability in Citrix NetScaler. — The Public Prosecution Service endorses this conclusion from the earlier forensic investigation. source
- confirmed There is no reason to assume that information was taken. — This is the Public Prosecution Service’s current assessment; the article does not present it as an absolute exclusion. source
- confirmed The Public Prosecution Service receives an additional €50 million annually for its IT programme. — Mentioned in the Public Prosecution Service’s official response. source
Editor's note
It is certain that the committee found inadequate security and missing monitoring. The exact attacker and any theft of data have not been established.Sources
- Reactie College op onderzoeksrapport ICT-inbreuk 2025 — Openbaar Ministerie
- Reactie op het rapport ICT-inbreuk Openbaar Ministerie — Tweede Kamer
- Beveiliging van OM-systemen was niet op orde in aanloop naar hack — Dutch IT Channel
More on this in Dutch media
- NOS — „openbaar ministerie”
- Het Parool — „openbaar ministerie”
- Trouw — „openbaar ministerie”