Lyce · Hybrid Watch

hw_48e61b8b65d89a47

Cyberattacks target Icelandic official websites and tech companies.

In mid-June 2023 Iceland’s cyber-authorities reported a spike in distributed-denial-of-service (DDoS) and intrusion attempts on multiple official websites and technology firms, with the hacktivist group NoName057(16) claiming responsibility and aligning itself with Russian-sympathetic objectives. The campaign caused broad service disruptions, intermittent website outages, and significant incident-response mobilisation within Iceland’s CERT-IS network. Being an island nation, Iceland’s geographic isolation amplifies the strategic effect of such cyber campaigns, as disruptions quickly gain public and media visibility in Reykjavík and across the country. No physical infrastructure was destroyed, the choice of multiple high-value targets (parliament, tech firms) and coordination over several days suggest more than mere opportunistic hacking. Analysts interpreted the campaign as part of a pattern of Russian-aligned hybrid threats across the Nordic and Arctic region, where cyber pressure co-exists with maritime, air-space and infrastructure vulnerabilities. Iceland’s government noted the timing around international diplomatic events and referenced the possibility of the attacks serving as a distraction or a testing of readiness. The incident prompted Iceland to raise its national cyber-threat level, accelerate resilience measures across the private-public sector, and collaborate more closely with NATO and Nordic partners on shared cyber-intelligence.

Occurrence
2023-06-14
Publication
2023-06-13T22:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
IS
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2023-06-13T22:00:00Z

    In mid-June 2023 Iceland’s cyber-authorities reported a spike in distributed-denial-of-service (DDoS) and intrusion attempts on multiple official websites and technology firms, with the hacktivist group NoName057(16) claiming responsibility and aligning itself with Russian-sympathetic objectives. The campaign caused broad service disruptions, intermittent website outages, and significant incident-response mobilisation within Iceland’s CERT-IS network. Being an island nation, Iceland’s geographic isolation amplifies the strategic effect of such cyber campaigns, as disruptions quickly gain public and media visibility in Reykjavík and across the country. No physical infrastructure was destroyed, the choice of multiple high-value targets (parliament, tech firms) and coordination over several days suggest more than mere opportunistic hacking. Analysts interpreted the campaign as part of a pattern of Russian-aligned hybrid threats across the Nordic and Arctic region, where cyber pressure co-exists with maritime, air-space and infrastructure vulnerabilities. Iceland’s government noted the timing around international diplomatic events and referenced the possibility of the attacks serving as a distraction or a testing of readiness. The incident prompted Iceland to raise its national cyber-threat level, accelerate resilience measures across the private-public sector, and collaborate more closely with NATO and Nordic partners on shared cyber-intelligence.