Dutch Intelligence Warns Chinese Hackers Have Source Code for Western Network Devices

Justice Ekaeze  - Tech Writer
Last updated: October 9, 2026
Share
Dutch Intelligence Warns Chinese Hackers Hold Western Network Source Code
  • Dutch intelligence says Chinese hackers hold the secret source code of some Western network products. That lets them hunt for weak spots in private.
  • The agencies predict a sharp increase in attacks targeting firewalls and VPN gateways in the coming years, with AI making it faster.
  • While updates are helpful, they’re not sufficient, organizations need extra layers of defense, store their logs safely, and plan for attacks that have no fix yet.

Dutch intelligence agencies warned this week that Chinese hackers are getting better at breaking into the devices that guard company networks. The hackers hold the hidden blueprints of some Western products. They also have AI to help them use what they find.

The Netherlands’ two spy services, the AIVD and the MIVD, made the announcement on October 7. They released a joint advisory with the country’s National Cyber Security Center. It says attacks on so-called edge devices will “increase considerably” in the coming years.

Edge devices and the source code problem

Edge devices are those located at the border of a network and have direct access to the internet. Firewalls, VPNs, proxies and login pages all fall under this category.

That position makes them easy targets. Anyone online can reach them. Many also lack the monitoring software that runs on regular computers. A hacker who gets in through one can slip past the other defenses.

Source code is the set of instructions behind a product. It shows exactly how the product works. Companies guard it closely.

The agencies claim that the Chinese hackers have obtained some part of that code. The advisory states that some of it was obtained via cyber spying. However, it does not disclose any products or companies.

The maker never suspects anyone is looking. That means the hackers may find “zero-day” flaws, which are flaws with no fix available. Defenders have no warning and no patch.

China also gets help beyond its spy agencies. The advisory points to a wide network of Chinese companies and research institutes. Some firms do research on flaws in Western products. Some even sell ready-to-use attack tools.

A Chinese law passed in 2021 requires people to report flaws they find. The Dutch say China also set up training programs aimed at hacking edge devices.

AI speeds up the attack process

The agencies say AI is speeding up the work. It helps hackers find flaws in code. It also helps them turn newly announced flaws into working attacks faster.

This matters because the gap between a public bug report and the first attack keeps shrinking. The advisory says the risk grows sharply once a flaw becomes known. It also says Chinese hackers often use old, known flaws, not only secret ones.

Put together, the Dutch expect hackers to find many unknown flaws each year. They also expect fast use of known ones.

The attack pattern has already played out before

The warning builds on past cases. In early 2024, the Dutch revealed that Chinese state hackers had broken into a Dutch military network. They used a flaw in Fortinet’s FortiGate firewalls and planted a spying tool called Coathanger.

The Dutch later said the campaign was much larger than first thought. This attack targeted at least 20,000 FortiGate devices around the world. These included Western government departments, diplomatic missions, and defense contractors.

The hackers began using the flaw at least two months before the company announced it. The affected Dutch network was used for unclassified research. It stood alone, so it did not harm the wider defense network.

China has denied such claims in the past. After the 2024 report, its embassy in the Netherlands called the accusations groundless. Beijing has not yet answered the new advisory, as far as public reports show.

The MIVD’s annual report earlier this year also said China’s cyber skills now rival those of the United States. It said only a small share of Chinese operations against Dutch targets are ever detected.

What the agencies advise

The advisory says no action can prevent all the hacks. Instead, its purpose is to lower the probability of a hack as well as reduce the consequences of one.

Installing vendor updates is still important. The agencies report that some companies postpone updates since a patch may affect some other systems. But managers need to balance that worry against the risk of waiting too long.

Their advice basically acknowledges that hackers might get through anyway:

  • Build layers. Install firewalls designed to fit your purposes, intrusion detection systems, and two-step authentication throughout the organization. Create sections within the network. Encrypt data in multiple spots. If one defense falls, the others help slow attackers down.
  • Mix vendors. There’s a bonus to using different tool brands, too. If hackers know one product inside out, switching up brands on different layers can stump them.
  • Keep logs elsewhere. Many victims cannot show investigators what happened. Usually, logs are not saved at all or saved for a short period of time. Another problem is that logs are saved on the same device that the attacker has taken over, which enables them to erase the logs. The experts recommend sending logs to a different and secure system. Additionally, all logs should be stored for at least 6 months, and preferably for one year or more.
  • Practice is important. Have a trained security team. Test your defenses with fake attacks to see if anything gets noticed. 
  • And be ready to investigate. Train your staff in digital forensics so they’re ready to act as soon as something goes wrong.

Why this matters outside the Netherlands

The advisory has no limits when it comes to threats to Dutch businesses and other organizations. Similar firewalls and VPN gateways are found in various offices, hospitals, and governmental agencies throughout the world.

Cybersecurity concerns can also extend to how major online platforms handle personal information, as shown by Dutch judges’ ruling that Facebook violated data privacy rules.

The AIVD says Chinese hackers have hit networks of many victims in recent years through these devices, including Dutch organizations. The agencies expect more of the same.

The message to network managers is simple and clear. The entrance to the network is the most watched target, and those who are watching it might know its layout better than the personnel who designed it.

Share this article

About the Author

Justice Ekaeze is a freelance tech writer with experience working for specialized content agencies. Justice has acquired extensive content writing experience over the years. He’s handled several projects in diverse niches but loves the cybersecurity and VPN sectors the most. His friends call him 'the VPN expert.' In his free time, he likes to play football, watch movies, and enjoy a good show.

More from Justice Ekaeze

Comments

No comments.