Looking Back at 7th Edition of Hâck the Hague
On 5 October, 120 ethical hackers -80 professionals and 40 students- tested the digital infrastructure of the Municipality of The Hague. From the Atrium of the city hall, students and professional hackers attempted to breach the systems. A total of 125 reports were submitted. The majority of these were resolved on the same day. The vulnerabilities identified included overdue updates and misconfigurations at suppliers.
Adeel Mahmood, Aldermen for Services at Municipality of The Hague: “In a society that is rapidly becoming digitalised, cybersecurity is a key prerequisite for providing reliable services to our staff, residents and businesses. We are constantly working to improve the security of our systems. We cannot do this without the human creativity of both our own security experts and ethical hackers. It’s quite exciting, but at the same time it yields many new insights that help us enormously. This is demonstrated year after year during Hack The Hague.”
Chain reaction in cybersecurity
The theme of this seventh edition is ‘chain reaction’. In cybersecurity, a chain reaction refers to an attack in which several small, isolated vulnerabilities or actions are cleverly combined in sequence. The end result is far greater and more damaging than the individual actions.
Hackers use this technique to bypass defence systems. The hacker often gains access via a relatively innocuous vulnerability, such as an outdated plug-in on a website or an employee who has fallen victim to phishing and has minimal access rights. From that position, the attacker looks for a second flaw, such as a misconfigured system or a script running with administrator privileges. By using the initial access to trigger the second flaw, the hacker can sometimes gain maximum privileges. This is a situation every organisation wants to avoid.
With this theme, Hâck The Hague is placing extra emphasis this year on how small, seemingly innocent vulnerabilities can, when combined, lead to major risks. This demonstrates why testing entire chains of systems is at least as important as testing individual components.

Vulnerabilities identified and prices
Various cash prizes were awarded in the categories of Most Creative Hack, Most Sophisticated Hack, Most Impactful Hack and The Hackademic Award, supplemented by two bonus prizes: Best Use of AI and Best Report. A total of €17,000 in prize money was awarded.
Lilian Knippenberg, CISO at Municipality of The Hague: “We are absolutely delighted with all the findings from this year’s event. Hackers took a fresh, critical look at our systems, which provides insights that we don’t always spot ourselves. We’ve already been able to resolve some of the issues reported today with the team, working together with our suppliers. Digital security is a responsibility we all share. Hâck The Hague emphasises this point year after year.”
In the digital society, every organisation is exposed to the risks of cybercrime on a daily basis. In the physical world, it is clear where a local authority’s responsibilities lie. In the digital world, this is often still uncharted territory. During Hâck The Hague, The Municipality of The Hague will gain a fresh, external perspective on its own municipal IT systems. Furthermore, this competition day helps to inspire students to pursue a career in cybersecurity. This is sorely needed, as the demand for cybersecurity specialists is set to rise further in the coming years.
Thank you to all ethical hackers, security specialists and ICT teams working together to assess findings and make improvements where possible. In the core DIVD Dutch Institute for Vulnerability Disclosure, futhermore: mnemonic, Zerocopter, Merlon Security, KPN, BDO, Eradix, Ministerie van Justitie en Veiligheid, Nationaal Cyber Security Centrum (NCSC-NL)