---
title: "Belgian Ministry of Defence Log4Shell cyberattack"
description: "Evidence-backed account of Belgian Ministry of Defence Log4Shell cyberattack, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Vulnerability exploitation"
status: "closed"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/belgian-defence-log4shell-cyberattack-2021"
markdown_url: "https://www.ally.security/incidents/belgian-defence-log4shell-cyberattack-2021.md"
stix_url: "https://www.ally.security/incidents/belgian-defence-log4shell-cyberattack-2021/stix.json"
---

# Belgian Ministry of Defence Log4Shell cyberattack

Attackers exploited Log4Shell before Belgian Defence detected the compromise. The ministry responded by separating its networks from external connections and quarantining affected systems.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

The [Belgian Ministry of Defence](https://www.mil.be/) was compromised after attackers exploited Log4Shell. The documented activity began on December 10, 2021, and Belgian Defence detected the compromise five days later. [1](#source-1) [2](#source-2)

## Impact

Belgian Defence disconnected its networks from external networks and quarantined affected systems. The public record does not provide a reliable measure of data exposure, the number of affected systems, or the duration of operational disruption. [2](#source-2)

## Timeline

### December 10, 2021 — Activity began

December 2021 Belgian Defence network compromise is recorded on this date. [2](#source-2)

### December 15, 2021 — Discovery

December 2021 Belgian Defence network compromise is recorded on this date. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The record identifies exploitation of Log4Shell, tracked as CVE-2021-44228. Log4Shell was a remote-code-execution vulnerability in Apache Log4j Core. [1](#source-1) [2](#source-2)

The cited public record confirms exploitation in this incident but does not establish the attacker or a more detailed initial-access path. [1](#source-1) [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

The documented containment measures were external network disconnection and quarantine of affected systems. The parliamentary record distinguishes the start of the compromise from the later detection date. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/belgian-defence-log4shell-cyberattack-2021/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Apache Logging Services Security — CVE-2021-44228

advisory · Apache Software Foundation

<https://logging.apache.org/security.html>

<a id="source-2"></a>

### CRIV 55 COM 671 — National Defence Committee

official · Belgian Chamber of Representatives · Jan 26, 2022

<https://www.lachambre.be/doc/CCRI/pdf/55/ic671.pdf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exploited Vulnerability · 99% confidence · current**  
   December 2021 Belgian Defence network compromise: Log4Shell
2. **Began At · 95% confidence · current**  
   December 2021 Belgian Defence network compromise: 2021-12-10
3. **Affected Organization · 100% confidence · current**  
   December 2021 Belgian Defence network compromise: Belgian Ministry of Defence
4. **Resulted In · 99% confidence · current**  
   December 2021 Belgian Defence network compromise: Belgian Defence disconnected its networks from external networks and quarantined affected systems.
5. **Discovered At · 100% confidence · current**  
   December 2021 Belgian Defence network compromise: 2021-12-15

</details>
