Between 2021 and 2023, the UNC4841 group allegedly exfiltrated about 10% of the incoming and outgoing emails of the State Security Service.

On February 26, 2025, the Belgian daily Le Soir revealed that cybercriminals affiliated with China had stolen sensitive data from the State Security Service (VSSE), Belgium’s intelligence agency. The hackers exploited a vulnerability in a network gateway from the American company Barracuda Networks, allowing them to exfiltrate approximately 10% of the incoming and outgoing emails processed by the agency between 2021 and 2023.

However, this vulnerable gateway was only used by the VSSE for handling external emails. The most confidential information was transmitted through more secure channels. Nevertheless, sensitive data was exposed, including identity documents of VSSE agents as well as communications with the public prosecutor’s office, the police, and the Ministry of Justice.

The Belgian federal prosecutor’s office has opened an investigation into the matter. According to Le Soir, the state-backed Chinese group UNC4841, specialized in espionage operations, is believed to be behind this cyberattack.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.