Living in the Gray Zone: A Rotterdam Perspective on Digital Warfare

· 9 min read · cybersecurity
#3 Gray Zone Warfare

The Port I Know

I live in Rotterdam. I’ve lived here for years, and during that time, the port has become part of my daily mental landscape. Not in any romantic way. I don’t stand on the waterfront gazing at cargo ships with a sense of wonder. It’s more mundane than that. The port is just there. A fact of life. The reason the city exists in the first place.

But here’s the thing about living near Europe’s largest port: you develop a kind of ambient awareness of scale. The Port of Rotterdam stretches 42 kilometers along the waterway. Every day, roughly 75 seagoing vessels arrive or depart. About 37,000 containers get handled. Somewhere in the system, a TEU is exchanged every three seconds. That rhythm, invisible to most of us, is what keeps the shelves stocked across half a continent.

I didn’t think much about any of this on January 27, 2026. I was doing whatever I normally do on a cold Monday morning. Coffee, email, the usual. But somewhere across thousands of kilometers, hackers were launching an attack on the port I’d driven past just the day before.

Then the news landed. And the port I’ve passed a hundred times without thinking became something else entirely. Not just infrastructure. A target.


What Happened

The attack on the Port of Rotterdam wasn’t sophisticated by cybersecurity standards. It was a distributed denial-of-service attack, the digital equivalent of clogging a highway with traffic until nothing can move. The attackers overwhelmed the port’s systems with fake requests, knocking the official website offline for hours. Similar attacks hit the ports of Amsterdam and Groningen around the same time.

No ships were stranded. No cargo was stolen. No sensitive data was compromised. No ransom was paid. By conventional measures, the attack “failed.”

But the attackers weren’t trying to steal or destroy. They were sending a message.

The group behind the attack calls itself NoName057(16). They’re pro-Russian hacktivists who emerged in March 2022, right at the start of Russia’s invasion of Ukraine. Since then, according to Europol, they’ve claimed responsibility for more than 1,500 attacks against NATO member states and countries they perceive as hostile to Russian interests.

What makes them particularly concerning is their connection to the Kremlin. CISA, the U.S. Cybersecurity and Infrastructure Security Agency, has assessed that NoName057(16) was created by CISM, an organization established on behalf of the Russian government. This isn’t random hacktivism. It’s state-sponsored disruption with a volunteer army of roughly 4,000 supporters helping execute attacks.

Why Rotterdam? Why January 2026? According to Dutch news outlet RTL, the attackers claimed the attack was retaliation for the Netherlands’ plans to procure Swiss tanks for Ukraine. The Dutch National Cyber Security Center confirmed pro-Russian groups were responsible, with the attacks traced to Russian and Serbian IP addresses.

For a small country that has consistently supported Ukraine, this was a pointed reminder: we are not invisible.


Why This Matters More Than It Seems

A DDoS attack that takes a website offline for a few hours might sound minor. It isn’t.

Rotterdam isn’t just a port. It’s a node. More than 30% of all container traffic for Northwest Europe passes through here. Over 400 million tonnes of cargo move through annually. The port serves as the EU’s external customs border and connects to 500 million European consumers. According to Erasmus University research, the port contributes €45.6 billion to the Dutch economy, representing 6.2% of the country’s total economic value. That’s twice what previous calculations had estimated.

When you attack Rotterdam, you’re not attacking one city. You’re poking at the nervous system of European trade.

This is why NATO is paying attention. James Appathurai, one of NATO’s senior policy officials, recently warned that “a port in Europe has been under a sustained cyberattack to try to lock the locks.” Think about that phrase. Lock the locks. Freeze the machinery that keeps goods flowing.

The threat is escalating. According to the NATO Cooperative Cyber Defence Centre of Excellence, maritime cyber incidents have risen 150% between 2020 and 2025. Critical port infrastructure, which handles 80% of global trade, is now regularly targeted by actors linked to Russia, Iran, and China.

We’ve seen what happens when these attacks succeed. In 2017, the NotPetya malware paralyzed Maersk’s global operations for weeks. Container terminals in Rotterdam, Los Angeles, and New York had to operate manually. The cascading effects rippled through supply chains worldwide.

And the Netherlands specifically? According to the Dutch Military Intelligence Service (MIVD), Russian state-sponsored hackers attempted sabotage attacks on Dutch critical infrastructure in both 2024 and 2025. One incident last year marked “the first time that a group like this has carried out a cyber sabotage attack against such a control system in the Netherlands.”

The MIVD assessed that these attacks were “probably aimed at gaining a digital position within critical infrastructure in order to sabotage it at a later time.”

In other words: they’re not just probing. They’re pre-positioning.


Life in the Gray Zone

Here’s where I need to introduce a phrase I’ve been thinking about since the attack: the gray zone.

The Atlantic Council defines it as “the space in which defensive and offensive activity occurs above the level of cooperation and below the threshold of armed conflict.” It’s not war. It’s not peace. It’s the uncomfortable space in between, where sabotage, cyber operations, disinformation, and infrastructure disruption happen without triggering a full military response.

This isn’t an academic concept anymore. It’s how Dutch officials describe our current reality. Defense Minister Ruben Brekelmans has stated that the Netherlands now faces “a grey zone between war and peace,” requiring continuous defense against cyber attacks, espionage, and sabotage attempts.

When a government minister uses that phrase, it’s not metaphor. It’s policy assessment.

What does gray zone warfare mean for those of us who live in the targeted areas? Traditional war has boundaries. There’s a front line. There are combatants and civilians. International law, however imperfectly enforced, provides frameworks for conduct.

The gray zone has none of that clarity. Civilian infrastructure becomes the battlefield. The attack on Rotterdam didn’t come with a declaration of war. No soldiers crossed a border. A group of hackers, operating under Kremlin direction, decided that the best way to punish the Netherlands for supporting Ukraine was to disrupt Europe’s largest port.

Democratic states struggle with this. Our legal and institutional systems are designed around a binary: war or peace. When someone operates in the space between, the response options are awkward. Overreact, and you escalate. Underreact, and you invite more.

Here’s what sits with me, though. The attack on Rotterdam “failed” in technical terms. The port’s cybersecurity measures held. No lasting damage occurred. But did it really fail?

Because what I remember isn’t the technical resilience. It’s the feeling of seeing my city’s name in the same sentence as “pro-Russian cyberattack.” It’s the sudden awareness that the conflict in Ukraine, which felt thousands of kilometers away, is actually much closer. The attackers didn’t shut down Rotterdam. But they demonstrated something important: you are reachable.

That’s the psychology of gray zone warfare. It’s not about destruction. It’s about demonstrating capability. Making you aware of your vulnerability. Creating uncertainty.


Europe’s Vulnerability

Rotterdam isn’t unique in this exposure. The same interconnectedness that makes European trade efficient makes it vulnerable.

NoName057(16) has targeted government and infrastructure across NATO countries: France, Italy, Sweden, Germany, and others. About 41% of their attacks target government and public sector entities. Transportation and banking make up another 25%.

The CCDCOE’s risk assessment identifies ports in Poland and Taiwan as facing the highest immediate risk. The Panama Canal is assessed as “the most probable next target.” State-sponsored actors from Russia, China, and Iran are responsible for most high-impact attacks on maritime infrastructure.

Europe is responding. The EU’s NIS2 Directive mandates cybersecurity standards across critical infrastructure sectors. The U.S. Coast Guard’s 2025 rule requires vessels and facilities to appoint Cybersecurity Officers and report incidents. NATO and EU members established the European Centre of Excellence for Countering Hybrid Threats in Helsinki.

But there’s a structural problem. Research from the German Council on Foreign Relations notes that Russia uses a “whole-of-society approach,” leveraging everything from private companies to government agencies. Democratic states, constrained by law and public accountability, can’t easily mirror that approach. We play by different rules.

And the attacks keep coming. Evidence cited by the CCDCOE points to a May 2025 Russian attack targeting Hamburg and Rotterdam that disrupted European logistics. The methods included phishing campaigns and supply chain compromises.

What makes Europe strong, our integration, our efficiency, our digital infrastructure, also makes us exposed. Every connection is also a potential attack surface.


Living With Awareness

I still see the port. I still drive past the terminals. The ships still come and go. The containers still move.

But something has shifted in how I think about it. The mundane has become strategic. The infrastructure I took for granted now registers differently. Not with fear, exactly. More like awareness.

I don’t think the right response is panic. Port of Rotterdam authorities demonstrated that resilient cybersecurity matters. The attack was contained. Operations continued. That’s worth noting. But I also don’t think the right response is complacency.

The space between war and peace is getting smaller. That’s not alarmism. That’s what the Dutch Defense Minister is saying. That’s what NATO intelligence assessments show. That’s what the MIVD reports document. For people who live in cities with critical infrastructure, this isn’t abstract geopolitics. It’s the new normal.

The hackers in January didn’t shut down Rotterdam. They didn’t sink ships or steal cargo. By narrow metrics, they failed.

But they made their point. And for those of us who live here, the question isn’t whether we’re safe. Port defenses held this time. The question is whether we’re paying attention to what the attack actually meant.

I am now.

G.

All views expressed here are my own and do not represent the opinions or positions of my employer or any organization I am affiliated with.

AIL: 0 1 2 3 4 5

Giulio wrote the core content and analysis. claude-opus-4.6 / Anthropic (primary contributor) and other AI models supported with research, sounding board, refinement, and structural editing.