Summary
The core message of the available transcript is that a seemingly narrow account-compromise alert became a high-pressure investigation into how stolen police credentials and cookies could give an actor access without leaving the expected traces. The case began on the evening of 09/25/2024, when Maikel Rollman received a call while preparing to leave his hotel for dinner. The trigger was a Microsoft report to the security operations center stating that a suspected state-sponsored threat actor, tracked by Microsoft as Storm 0950, had targeted and compromised an account in the organization. Initial SOC checks of logs, the user account, and work devices found nothing abnormal, but intelligence services then warned that the Dutch police global address list had been stolen, turning what appeared to be a closed incident into “this is bad.”
The speakers then framed why the investigation was unusually complex: the Dutch police was simultaneously the victim, the employer of thousands of potentially affected personnel, and the investigative body working the case. Frank Demmers described the tension between informing employees, protecting the victim organization, and keeping investigative knowledge from the perpetrator. Political and media pressure arrived almost immediately; parliament was informed within two days, and internal messages appeared in newspapers. The investigation started with practical questions: what exactly was stolen, whether the entire global address list was obtained, how the actor did it, whether the organization remained vulnerable, and who was behind the attack. Investigators followed two early routes: the compromised “patient zero” account and an IP address that had obtained multiple megabytes of data it should not have accessed.
The operational work began with a visit to the affected colleague, who appeared tech savvy and did not recall suspicious activity. Investigators seized work and personal devices, reviewed Dutch police logs, and examined the hybrid environment created when the organization rushed into Microsoft Office 365 and Microsoft Teams during COVID, connecting cloud identities to on-premises systems. Device and account analysis showed Microsoft Teams use, misuse of Discord, suspicious Gmail activity, and login attempts elsewhere, leading investigators to conclude quickly that an infostealer was likely involved. They found the colleague’s data being sold online, including valid credentials and cookies that any actor could try against police systems. The available transcript closes with the finding that the actor’s infrastructure appeared broad and automated, using harvested infostealer cookies in a checker to identify which credentials were still valid.
Key Topics
5 key topics from Frank Demmers and Maikel Rollman at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Treat leaked internal updates as public within minutes.
- Investigate personal devices when work-account compromise seems unexplained.
- Monitor infostealer markets for employee credentials and cookies.
- Validate cloud-to-on-premise risk during incident response.
- Separate employer, victim, and investigator communication priorities early.
“There isn't such thing as internal communication with cases like this.”
Up Next


Next in agenda
How to build a world-class Cyber Defense Center

Also on cybersecurity
Squaring the Circle: Lawful Access to Encrypted Data while preserving Cyber Security
Otmar Lendl


Also on incident response
