Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Documented record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
The Belgian Ministry of Defence was compromised after attackers exploited Log4Shell. The documented activity began on December 10, 2021, and Belgian Defence detected the compromise five days later. [1][2]
Impact
Belgian Defence disconnected its networks from external networks and quarantined affected systems. The public record does not provide a reliable measure of data exposure, the number of affected systems, or the duration of operational disruption. [2]
Timeline
Threat Group & Attack Vector
The record identifies exploitation of Log4Shell, tracked as CVE-2021-44228. Log4Shell was a remote-code-execution vulnerability in Apache Log4j Core. [1][2]
The cited public record confirms exploitation in this incident but does not establish the attacker or a more detailed initial-access path. [1][2]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
The documented containment measures were external network disconnection and quarantine of affected systems. The parliamentary record distinguishes the start of the compromise from the later detection date. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]
