A major cyber scandal has erupted in the Netherlands. The country's Financial Intelligence Unit conducted a large-scale operation, seizing approximately 800 servers. These machines fueled massive cyberattacks on government and banking websites across Europe, orchestrated by Russian hackers.
Two Data Centers in the Crosshairs
Last week, law enforcement struck at two Dutch data centers. The companies targeted were WorkTitans and MIRhosting, which had rented their servers to entities linked to Russian hackers. It turned out that the real beneficiaries were two Moldovan brothers—Yuriy and Ivan Neculiti. They are already on the EU sanctions list for aiding Russian state-sponsored hackers.
The Pianist Who Became a Hacker
One of the most striking elements of this story is the figure of Nesterenko, who admitted on LinkedIn to having previously collaborated with one of the Neculiti brothers. He claims to have cut ties after sanctions were imposed, but his company denies any wrongdoing, stating they noticed nothing suspicious in their own network. WorkTitans declined to comment.
NoName057(16) Group and Its Methods
The seized servers are linked to the Russian hacker group NoName057(16), which Europol accuses of launching mass attacks on government sites and banking services. The group specializes in DDoS attacks—overloading websites with traffic until they crash. Notable incidents include attacks on Danish government organizations last November and a Christmas Eve assault on France’s postal service, causing widespread delivery delays.
Kremlin’s Hidden Project
According to the U.S. Department of Justice, NoName057(16) is a covert project involving employees of the Kremlin-backed Youth Environment Monitoring Center. The group maintained a daily ranking of DDoS attacks and rewarded the most active volunteers with cryptocurrency. Experts note: the group heavily relies on servers in Western countries, making it vulnerable to police operations.
Russia’s New Tactics
The operation in the Netherlands is part of a broader trend: activity by hackers acting on behalf of aggressive states has significantly increased recently. DDoS attacks target not only government websites—in May, “Nova Poshta” was also hit, with its services under massive assault. Meanwhile, Russia is changing tactics: as revealed in Sweden, Russian cyberattacks now aim not just at digital but also at physical infrastructure in European countries. In Germany, hackers compromised Signal accounts of hundreds of top officials—including ministers and Bundestag leadership—through a sophisticated phishing attack.