⌂ Home › News › Dutch Privacy Authority Warns AI Accelerates Data Breaches and Cyberattacks
News

Dutch Privacy Authority Warns AI Accelerates Data Breaches and Cyberattacks

Cybersecurity concept with digital lock and binary code
Cybersecurity concept with digital lock and binary code
A A Text Size16px

The Dutch Data Protection Authority (AP) announced in its annual report on July 8, 2026, that reported data breaches in the Netherlands rose to 39,407 in 2025, warning that artificial intelligence is significantly accelerating the speed and scale of cyberattacks.

According to the AP report, the total number of data breaches increased from 37,839 cases in the previous year.

The authority highlighted a sharp rise in accidental public exposure of personal data within public administration, which jumped from 199 cases in 2024 to 346 in 2025, often due to government agencies forgetting to redact personal details before publishing documents online.

Conversely, the public sector saw improvements in securing physical data carriers, as cases of lost laptops, phones, or USB sticks dropped from 288 in 2024 to 89 in 2025.

The AP emphasized that cybercriminals are increasingly utilizing artificial intelligence to create highly personalized phishing campaigns quickly and at scale through ready-made "phishing-as-a-service" kits available online.

To combat these escalating digital threats, cybersecurity firm Commvault introduced a live, scenario-driven simulation called "Commvault Minutes to Recovery" to help organizations measure and test their response times against AI-driven attacks under realistic conditions.

Data from 2025 indicates that the timeframe between discovering a vulnerability and exploiting it has shrunk to just 29 minutes, marking a 65 percent increase in speed compared to the prior year.

The authority also highlighted specific localized impacts resulting from administrative oversights.

The municipality of Midden-Delfland accidentally published a document online containing the names and addresses of 133 residents who opposed the arrival of an asylum seekers' center, causing widespread concern and fear among the community.

The agency concluded that the rise of AI tools means organizations must act immediately to elevate their cybersecurity measures.

"Phishing emails and scam messages can be created faster and on a larger scale with AI, and these messages can also appear increasingly realistic," the AP warned.

The regulator stated that criminal operations no longer require advanced technological knowledge due to the high quality of DIY phishing software.

The authority insisted that institutions must proactively secure their digital perimeters and ensure a high level of cybersecurity.

Corporate leaders emphasized that traditional recovery playbooks are no longer sufficient given the rapid execution of modern cyberattacks.

"The question organizations should ask themselves is no longer 'Do we have a recovery plan?' but 'Can we demonstrate that we can recover under high pressure?'"

said Anna Griffin, Chief Marketing Officer at Commvault.

Griffin noted that quantifiable readiness has become a strategic necessity for modern enterprises, as AI shortens the time between a successful attack and its impact.

Industry partners noted that theoretical preparedness frequently collapses during actual cyber incidents.

"Most organizations think they are prepared for a cyberattack until they actually have to respond under time pressure to a real attack," said Allen Downs, Vice President of Security and Resiliency at Kyndryl.

Downs explained that testing realistic attack scenarios is the only way to validate true operational resilience, as cyberattacks become faster, more sophisticated, and increasingly unpredictable.

🔗 Related Post
📰 Latest Updates