Listen to this Post
Introduction: Two Companies, One Ransomware Operation, and a Growing Warning for Dutch Businesses
The ransomware landscape continues to move quickly, and on August 31, 2026, new activity linked to the LockBit 5 operation drew attention to two companies in the Netherlands. Threat intelligence monitoring identified Van Kessel & Janssen and All Steel Products as organizations added to the LockBit 5 victim infrastructure.
The development is another reminder that ransomware operations continue to search for organizations whose operations depend on valuable data, continuous business activity, supplier relationships, engineering documentation, financial information, and project management systems.
For companies operating in construction, manufacturing, engineering, and industrial supply chains, a cyberattack can create consequences far beyond the loss of individual files. Project schedules can be disrupted, confidential documentation can be exposed, suppliers can be affected, and customers can lose confidence in the organization’s ability to protect critical information.
The appearance of two Dutch companies in connection with LockBit 5 activity therefore deserves serious attention from cybersecurity teams and business leaders alike.
the Reported Incident
According to ransomware activity monitored by the ThreatMon Threat Intelligence Team, the LockBit 5 ransomware group added two Dutch organizations to its list of victims on August 31, 2026.
The organizations identified were:
Van Kessel & Janssen
Van Kessel & Janssen operates in the construction and project management environment, presenting services related to effective project management, professional advice, and construction project results.
Companies involved in construction management often handle large volumes of commercially sensitive information. This can include architectural documentation, project budgets, contracts, supplier details, construction schedules, engineering files, and communications involving multiple organizations.
All Steel Products
The second organization identified was All Steel Products, a Dutch company operating in the industrial and steel-related sector.
Industrial organizations are increasingly attractive targets for ransomware groups because their operations frequently depend on interconnected systems, production schedules, supplier networks, technical documentation, and business applications that cannot remain unavailable for extended periods.
The reported activity placed both organizations under renewed scrutiny within the cyber threat intelligence community.
LockBit 5 Continues to Demonstrate the Evolution of Ransomware Operations
LockBit has remained one of the most recognizable names in the global ransomware ecosystem, and the continued appearance of LockBit-branded operations demonstrates how difficult it can be to permanently eliminate a major cybercriminal ecosystem.
Modern ransomware operations are no longer simply focused on encrypting computers and demanding money.
They have evolved into complex criminal businesses.
Ransomware Is Now a Multi-Stage Business Model
A modern ransomware intrusion may involve several stages before the victim even realizes that an attack has occurred.
Attackers may first gain access through compromised credentials, vulnerable internet-facing systems, phishing campaigns, third-party access, or previously stolen authentication information.
Once inside a network, the attackers can attempt to move laterally.
They may search for domain controllers, file servers, backup systems, cloud infrastructure, and databases.
Sensitive information may then become a target alongside operational systems.
Only after reconnaissance and preparation can the most visible stage of the attack begin.
That stage may include widespread disruption, encryption, extortion, or the publication of stolen information.
The Pressure Is No Longer Limited to Encryption
The biggest change in ransomware strategy has been the rise of multiple forms of pressure.
An organization may face operational disruption.
It may also face the possibility of sensitive information being exposed.
Customers, suppliers, employees, and business partners can become concerned when an organization appears on a ransomware operation’s infrastructure.
This creates a powerful combination of technical and reputational pressure.
For industries where trust and long-term contracts are essential, the consequences can continue long after systems are restored.
Why Construction Companies Are Attractive Targets
Construction and project management companies may not always receive the same cybersecurity attention as banks or technology companies.
However, they often possess exactly the type of information cybercriminals find valuable.
Construction Projects Generate Valuable Data
Large construction projects involve significant amounts of sensitive material.
This can include contracts.
It can include financial projections.
It can include engineering documentation.
It can include project schedules.
It can include customer information.
It can also include supplier and subcontractor relationships.
A successful compromise can potentially give attackers access to information connected to numerous organizations rather than just one company.
Project Delays Can Create Immediate Financial Pressure
Construction projects are highly dependent on timing.
A delayed schedule can affect contractors, suppliers, investors, customers, and employees.
If ransomware disrupts access to project management systems or essential documentation, the organization may face pressure to restore operations quickly.
Cybercriminal groups understand this.
Industries with limited tolerance for downtime can become particularly attractive targets.
The Industrial Sector Faces a Different but Equally Serious Risk
The steel and industrial sector faces another layer of cybersecurity exposure.
Industrial businesses may depend on complex relationships between office systems, logistics platforms, production planning, suppliers, and operational infrastructure.
Manufacturing Downtime Can Be Expensive
A single interruption can affect production schedules.
Orders may be delayed.
Materials may remain unavailable.
Suppliers may face uncertainty.
Customers may begin looking for alternatives.
The financial consequences of downtime can grow rapidly.
This creates an environment where cyber resilience becomes a business issue rather than simply an IT issue.
Supply Chains Can Multiply the Impact
A compromised company may have connections to dozens or hundreds of suppliers and customers.
This does not necessarily mean those organizations have been compromised.
However, the exposure of contact information, invoices, business communications, or project documentation can create additional risks.
Cybercriminals may attempt follow-up phishing attacks.
They may impersonate trusted contacts.
They may use stolen information to make social engineering campaigns more convincing.
The original ransomware incident can therefore become the beginning of additional cyber threats.
What Undercode Say:
The Appearance of Two Dutch Organizations Is a Strategic Warning
The reported LockBit 5 activity should not be viewed as two isolated names appearing on a ransomware monitoring feed.
It reflects a broader reality.
Cybercriminal operations continue to search for organizations with valuable information and expensive downtime.
Construction and Industry Are Becoming Increasingly Digital
Construction companies now depend heavily on digital project management.
Engineering documents are stored electronically.
Budgets are managed through business platforms.
Communication occurs through cloud systems.
The traditional idea that construction is primarily a physical industry is no longer accurate.
The digital infrastructure behind modern projects is enormous.
Attackers Follow Business Dependency
Cybercriminals do not necessarily need to target the largest company.
They need to target an organization where disruption creates pressure.
A smaller organization can still have major dependencies.
It may be responsible for an important project.
It may control valuable engineering information.
It may connect multiple suppliers.
It may have limited cybersecurity resources.
The Supply Chain Remains a Critical Weak Point
Businesses should remember that their own network is not their only attack surface.
Suppliers matter.
Contractors matter.
Cloud providers matter.
Remote access platforms matter.
Every external connection can potentially increase risk.
Security assessments must therefore include third-party relationships.
Backup Systems Must Be Treated as Critical Infrastructure
Many organizations still discover too late that backups were accessible from the same environment as production systems.
That is dangerous.
If attackers compromise administrative credentials, they may attempt to locate and destroy recovery options.
A backup that cannot survive an intrusion is not a reliable recovery strategy.
Organizations need isolated and regularly tested recovery capabilities.
Identity Security Is Becoming More Important Than Traditional Perimeters
The old security model focused heavily on protecting the network perimeter.
Modern environments are different.
Employees work remotely.
Applications operate in the cloud.
Suppliers require access.
Mobile devices connect from outside the office.
The identity of the user has become one of the most important security boundaries.
Strong authentication is no longer optional.
Multi-Factor Authentication Is a Basic Requirement
Critical accounts should not depend only on passwords.
Administrative systems require stronger protection.
Remote access systems require stronger protection.
Cloud accounts require stronger protection.
Stolen credentials remain valuable to cybercriminal groups.
MFA can significantly reduce the usefulness of many stolen passwords.
Monitoring Must Detect Behavior, Not Just Malware
Traditional antivirus remains useful.
But modern attacks can involve legitimate tools.
Attackers may use administrative utilities.
They may use remote management software.
They may use compromised accounts.
This means security teams must watch for suspicious behavior.
Unusual login locations matter.
Unexpected privilege changes matter.
Large data transfers matter.
Unusual access to backup systems matters.
Speed of Detection Can Determine the Size of the Incident
The earlier an intrusion is discovered, the greater the chance of limiting damage.
A compromise discovered within hours is very different from one discovered after weeks of attacker activity.
Threat hunting and centralized logging therefore remain essential.
Cybersecurity Must Reach the Boardroom
Ransomware is no longer purely a technical issue.
A major incident can affect revenue.
It can affect legal obligations.
It can affect customer relationships.
It can affect public reputation.
Executives must understand cyber risk as a business continuity issue.
Transparency Will Become Increasingly Important
When organizations experience serious cyber incidents, communication becomes critical.
Customers want answers.
Partners want clarity.
Employees want information.
Poor communication can create confusion and speculation.
Organizations should prepare communication strategies before an incident happens.
LockBit Activity Shows That Major Cybercrime Brands Remain Resilient
The continued appearance of LockBit-related activity demonstrates a difficult reality for law enforcement and defenders.
Disrupting infrastructure can damage a criminal operation.
Arrests can create pressure.
Sanctions can limit financial movement.
But cybercriminal ecosystems can reorganize.
New infrastructure can appear.
Former affiliates can join other groups.
The threat landscape constantly adapts.
The Most Important Lesson Is Preparation
Organizations cannot assume they are too small.
They cannot assume their industry is uninteresting.
They cannot assume a firewall alone is enough.
Every company handling valuable information or critical operations can become a target.
The strongest organizations are not necessarily those that never face an intrusion.
They are the organizations capable of detecting, containing, recovering, and learning quickly.
Deep Analysis
Security Teams Should Begin With Immediate Exposure Assessment
Organizations concerned about ransomware exposure should first identify internet-facing services and unnecessary remote access points.
A basic Linux network inspection can begin with:
ss -tulpn
This command helps administrators identify listening network services.
Administrators Should Review Failed Authentication Activity
Repeated failed login attempts can indicate password attacks or unauthorized access attempts.
On many Linux systems, administrators can review authentication logs with:
sudo grep "Failed password" /var/log/auth.log
Security Teams Should Search for Recently Modified Files
Unexpected modifications can help investigators identify suspicious activity.
A useful command is:
find / -type f -mtime -2 2>/dev/null
This searches for files modified within approximately the previous two days.
Organizations Should Identify Suspicious Processes
Attackers frequently attempt to execute unfamiliar tools or scripts.
Administrators can inspect active processes using:
ps aux --sort=-%cpu | head -20
This can help identify processes consuming unusual amounts of system resources.
Network Connections Should Be Investigated
Unexpected outbound connections deserve attention.
Administrators can inspect active network connections with:
ss -tpn
Connections to unfamiliar external infrastructure should be investigated carefully.
Backup Integrity Must Be Tested
Listing backup files is not enough.
Organizations should verify that restoration actually works.
A backup strategy should include:
restic check
or the equivalent verification mechanism for the
Logs Should Be Preserved During an Incident
Organizations should avoid immediately destroying evidence.
A simple archive of relevant logs can be created with:
tar -czf incident-logs.tar.gz /var/log/
Incident response teams should follow established forensic procedures and preserve evidence appropriately.
The Real Defense Is Layered Security
No single command can stop ransomware.
Security requires multiple layers.
Strong authentication.
Network segmentation.
Endpoint monitoring.
Offline backups.
Patch management.
Centralized logging.
Incident response planning.
Employee awareness.
Continuous testing.
That combination provides a far stronger defense than relying on a single security product.
✅ Threat intelligence reporting identified vkj.nl and allsteelproducts.nl in connection with reported LockBit 5 ransomware activity on August 31, 2026.
✅ Van Kessel & Janssen publicly presents itself as a company involved in construction projects, project management, and professional advisory services.
❌ The available report alone does not independently confirm the full technical details of the intrusion, including the initial access method, the specific data affected, or the operational impact on either organization.
Prediction
(+1) Positive prediction: The increased visibility of ransomware activity against construction and industrial organizations will push more companies in these sectors to strengthen identity security, isolated backups, threat monitoring, and incident response planning.
Negative prediction: Ransomware groups will likely continue targeting organizations with valuable supply-chain relationships and high operational dependency, increasing the risk of secondary phishing, data extortion, and business disruption.
Positive prediction: Companies that invest in tested recovery procedures and rapid detection capabilities will increasingly be able to reduce the financial and operational impact of future ransomware incidents.
▶️ Related Video (76% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




