
Behind the cyber attack on the Iranian nuclear complex in Natanze, held in 2007, is the Dutch engineer Eric van Sabben. This is stated in the investigation conducted by the publication De Volkskrant.
According to these data, 36-year-old Van Sabben managed to penetrate the nuclear complex and install Stuxnet from the external drive to its computer systems, which, using the zero day of the Microsoft Windows, made it possible to intercept management of industrial system controllers. With the help of Stuxnet, it was possible to disable centrifuges to enrich uranium in the complex and temporarily suspend the Iranian nuclear program.
It is also reported that the engineer was recruited by the general intelligence and safety service of the Netherlands on the instructions of the CIA and Mossad, since the operation itself was planned by the United States and Israel. At the same time, AIVD was not known about how a sabotage would be carried out at a complex in Natanze, and the Dutch intelligence service itself did not inform about the operation of the Prime Minister, as well as the government and the relevant committees of the Parliament of the Netherlands.
One of the sources of De Volkskrant in Dutch intelligence says that "the Americans used us very hard." In turn, the source of the publication in the political circles of the Netherlands says that “the special services decided that they are fulfilling the will of the Lord,” and a number of deputies require an investigation of what happened. DE Volkskrant also refers to an unnamed person in the AIVD leadership, which admits that the country's Prime Minister did not report anything about the operation, fearing possible political consequences.
It is reported that Van Sabben was recruited by AIVD in 2005. Thanks to his technical education, numerous contacts in the region and relations with Iran were considered an ideal candidate to perform the operation. He led a business in Iran and he had an Iranian wife. Probably, he introduced Stuxnet into the computer systems of the nuclear complex in Natanze, when he installed a water pump there. Whether he knew what exactly he was doing, as DE Volkskrant writes, is unknown. However, he was aware that his actions would be directed against the Iranian nuclear program.
The computer systems of the complex were not connected to the global network, so to install the worm on them, it was necessary to get physical access to them. However, Stuxnet was subsequently taken out of the complex and spread to the global network, infecting computers around the world. Assumptions were made that it could be a danger to the production of low -enriched uranium, including in the Netherlands.
At the end of 2008, Eric Van Sabben, who worked in Dubai, again came to Iran to visit his wife's family. However, ten days later, as DE Volkskrant writes, he hurriedly and “in a panic” left the country. On January 16, 2009, in the Dubai Sharje, the Dutch engineer drove beyond the highway during a trip on a motorcycle, rolled over and died, breaking his neck. Everything indicates that this was an accident, but the source of the publication in Dutch intelligence says that Van Sabben “paid a high price” for his sabotage.
In 2019, on the Yahoo News portal, the material of the journalists of De Volkskrant Kim Zetter and Guiba Modderkolka was published, which stated that the STUXNET implementation operation in Nanze was carried out by AVID. However, then it stated that the “worm” was carried into the complex by the Iranian engineer recruited by Dutch intelligence, who also handed over important information about the factory to the Americans and Israelis, which allowed the project to successfully complete the project.