Dutch court sentences hacker who used port systems to smuggle cocaine to 7 years

A Dutch appeals court sentenced a 44-year-old man to seven years in prison for hacking a major port company in Belgium to help smuggle cocaine into the Netherlands.

The Amsterdam Court of Appeal ruled Friday that the man played a central technical role in a criminal network that exploited port computer systems in 2020 and 2021, allowing traffickers to move drugs through Europe’s logistics hubs without detection.

Prosecutors said the operation enabled the import of 210 kilograms of cocaine via the Port of Rotterdam, one of Europe’s largest ports and a key gateway for global trade.

According to court documents, the defendant persuaded a port employee at a container terminal in Antwerp to plug a USB stick loaded with malware into a work computer. The malicious software created a digital backdoor, giving the hacker remote access to internal port systems used to manage containers, gates and personnel access.

Investigators relied heavily on intercepted messages from Sky ECC, an encrypted communications platform widely used by criminal groups before authorities dismantled it in early 2021. In those chats, the defendant provided step-by-step instructions on how to deploy the malware.

“Simply activate the program on the stick. Double-click it, wait 15 seconds, and then you can remove it,” he wrote in one message cited by the court.

Forensic analysis showed the malware remained active inside port systems for months, with repeated attempts to gain administrator privileges. In the intercepted chats, the defendant boasted that he had “total control,” including the ability to issue access passes and interfere with gate operations.

Authorities said the group also stole and circulated sensitive port information such as camera locations, staff photographs and terminal layouts. Judges concluded that the hack was explicitly designed to facilitate drug trafficking and posed a serious threat to the integrity and security of port operations.

The court also found the man guilty of helping organize the shipment of 210 kilograms of cocaine hidden in a container of wine bottles aboard the Callao Express, which Dutch authorities intercepted in Rotterdam in September 2020. He assisted in creating fake emails and transport orders and instructed accomplices on how to register the container in Portbase, the digital system used to manage container movements in Dutch ports.

In a separate charge, judges convicted the man of attempted extortion. He threatened relatives of a person involved in a dispute over missing cocaine, demanding €1.2 million and warning that violence would follow if the money was not paid.

The defendant was originally given a 10-year prison sentence by a lower court, but the appeals court cut it to seven years, pointing, among other things, to the unusually lengthy appeal process, which dragged on for more than 21 months.

The man, whose identity was not disclosed, is currently being held in a prison in western Netherlands and has appealed the latest ruling.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

 

Total
0
Shares
Previous Post

⚡ Weekly Recap: AI Automation Exploits, Telecom Espionage, Prompt Poaching & More

Next Post

n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens

Related Posts

Learn How Leading Companies Secure Cloud Workloads and Infrastructure at Scale

You’ve probably already moved some of your business to the cloud—or you’re planning to. That’s a smart move. It helps you work faster, serve your customers better, and stay ahead. But as your cloud setup grows, it gets harder to control who can access what. Even one small mistake—like the wrong person getting access—can lead to big problems. We're talking data leaks, legal trouble, and serious
Read More

Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection

The threat actor known as Curly COMrades has been observed exploiting virtualization technologies as a way to bypass security solutions and execute custom malware. According to a new report from Bitdefender, the adversary is said to have enabled the Hyper-V role on selected victim systems to deploy a minimalistic, Alpine Linux-based virtual machine. "This hidden environment, with its lightweight
Read More

CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity security flaw impacting OSGeo GeoServer to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation in the wild. The vulnerability in question is CVE-2025-58360 (CVSS score: 8.2), an unauthenticated XML External Entity (XXE) flaw that affects all versions prior to
Read More