Lyce · Hybrid Watch

hw_27ac59a2e7e4610d

Denmark’s Centre for Cyber Security (CFCS) site knocked offline by pro-Russian DDoS.

On 1 February 2023 the website of Denmark’s CFCS went offline following what was described as a prolonged DDoS campaign by pro-Russian hacktivist actors. The incident followed a public warning by CFCS that cyber activism targeting Denmark was rising, especially from pro-Russian groups supporting Moscow’s strategic objectives. The choice of a national cyber-authority as the target underlines the intent to strike at the digital backbone of Denmark’s defence and resilience infrastructure rather than solely at peripheral systems. Although the outage did not appear to cause long-duration system compromise or data theft, it disrupted public access and forced intensified defensive measures. Analysts interpreted the action as part of a sustained hybrid-warfare readiness probe: small-scale, reversible, but aimed at exhausting and measuring state responses. The incident set a precedent for subsequent, larger campaigns targeting Danish critical infrastructure and financial sectors later in 2023. The event drove changes in Denmark’s SOC capabilities, traffic filtering protocols, and institutional awareness around state-sponsored hacktivism aligned with Russia. While the attribution stopped short of naming Moscow explicitly, the pattern of targeting institutions closely tied to NATO posture pointed toward Russian-aligned threat actors. This incident reinforces how cyber domain attacks serve as subordinate yet potent instruments in hybrid strategies—preparing the environment, probing defences, and nudging escalation thresholds.

Occurrence
2023-02-01
Publication
2023-01-31T23:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
DK
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2023-01-31T23:00:00Z

    On 1 February 2023 the website of Denmark’s CFCS went offline following what was described as a prolonged DDoS campaign by pro-Russian hacktivist actors. The incident followed a public warning by CFCS that cyber activism targeting Denmark was rising, especially from pro-Russian groups supporting Moscow’s strategic objectives. The choice of a national cyber-authority as the target underlines the intent to strike at the digital backbone of Denmark’s defence and resilience infrastructure rather than solely at peripheral systems. Although the outage did not appear to cause long-duration system compromise or data theft, it disrupted public access and forced intensified defensive measures. Analysts interpreted the action as part of a sustained hybrid-warfare readiness probe: small-scale, reversible, but aimed at exhausting and measuring state responses. The incident set a precedent for subsequent, larger campaigns targeting Danish critical infrastructure and financial sectors later in 2023. The event drove changes in Denmark’s SOC capabilities, traffic filtering protocols, and institutional awareness around state-sponsored hacktivism aligned with Russia. While the attribution stopped short of naming Moscow explicitly, the pattern of targeting institutions closely tied to NATO posture pointed toward Russian-aligned threat actors. This incident reinforces how cyber domain attacks serve as subordinate yet potent instruments in hybrid strategies—preparing the environment, probing defences, and nudging escalation thresholds.