Police seized and operated a server of a company called Blackbox Security which offered 'crypto phones'. Basically phones pre-installed with some software sometimes with all ability to communicate disabled aside from that application. The price for these phones was 1500 EUR including a 6 month plan, afterwards 750 EUR per 6 months for usage.
While the Dutch DA and Police have not given any details as to how the security was broken there are some clues (this is speculative as fuck):
* A users guide that used to be published on the Blackbox Security website hints towards their chat application being XMPP+OTR.
* Real-time access but no historical access hints towards an MITM to change the previously exchanged OTR keys (a common way to 'break' into a conversation).
* The application seemed to not enforce and/or check the key signatures for changes.
This is not the first time the Dutch DA and Police have taken action against a 'crypto phone' provider. Ennetcom, another provider was taken down a year or so ago: https://www.zdnet.com/article/police-hack-pgp-server-with-3-... leading to arrests as well.The reason given by the DA for the publication of this news is that threats of violence and reprisal were being made on the taken down chat messages by owners of these devices after police action was taken against them. They wrongfully blamed the people they were communicating with of leaking the information. As tensions increased retribution hits were likely and the risk to the public would be there. Hence: release the information.
To re-iterate, there is so far no reason to believe the actual cryptographic protocols in use got broken but that yes; taking over the server allowed them to MITM the OTR key exchanges and/or pretend to be another client. I could get more technical but since this is all speculation I don't see much value to it.