Lyce · Hybrid Watch

hw_61fe2658b4e241c4

Icelandic Parliament and multiple government websites knocked offline amid pro-Russian hacktivist DoS campaign.

On the morning of 16 May 2023 the web-portal of Iceland’s Parliament and a number of other critical public-institution websites experienced outages attributed by Iceland’s cyber-authorities to a coordinated denial-of-service campaign. Iceland’s CERT-IS (National Cyber Security Centre) elevated the civil-protection “uncertainty level” and publicly flagged the disruption as being unusually broad, citing multiple hosting-parties and infrastructure-dependencies. Around the same time the pro-Russian hacktivist group NoName057(16) claimed responsibility for attacks on Icelandic websites, suggesting the action was part of a larger Russia-aligned hybrid-campaign. Although no physical damage was inflicted, the targeting of the defence/government ecosystem in Iceland underscores the country’s exposure to cyber-domain pressure as part of hybrid warfare. Reykjavík hosts key state institutions, making any disruption there symbolically potent and operationally meaningful in the small-state context of Iceland. The dynamics reflect disruption of availability rather than data exfiltration, forcing resource diversion from readiness tasks to incident management, and occurring in the lead-up to the Council of Europe summit held in Reykjavík, which heightened the signalling value. The incident fed into Iceland’s threat-assessment upgrading—recognising that cyber-attacks on governmental domains can serve as test-beds for layered hybrid operations. In short, this event demonstrates how even a digitally remote island nation like Iceland is part of the multi-domain hybrid warfare theatre, where cyber-attacks precede or accompany air, sea or infrastructure threats.

Occurrence
2023-05-16
Publication
2023-05-15T22:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
IS
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2023-05-15T22:00:00Z

    On the morning of 16 May 2023 the web-portal of Iceland’s Parliament and a number of other critical public-institution websites experienced outages attributed by Iceland’s cyber-authorities to a coordinated denial-of-service campaign. Iceland’s CERT-IS (National Cyber Security Centre) elevated the civil-protection “uncertainty level” and publicly flagged the disruption as being unusually broad, citing multiple hosting-parties and infrastructure-dependencies. Around the same time the pro-Russian hacktivist group NoName057(16) claimed responsibility for attacks on Icelandic websites, suggesting the action was part of a larger Russia-aligned hybrid-campaign. Although no physical damage was inflicted, the targeting of the defence/government ecosystem in Iceland underscores the country’s exposure to cyber-domain pressure as part of hybrid warfare. Reykjavík hosts key state institutions, making any disruption there symbolically potent and operationally meaningful in the small-state context of Iceland. The dynamics reflect disruption of availability rather than data exfiltration, forcing resource diversion from readiness tasks to incident management, and occurring in the lead-up to the Council of Europe summit held in Reykjavík, which heightened the signalling value. The incident fed into Iceland’s threat-assessment upgrading—recognising that cyber-attacks on governmental domains can serve as test-beds for layered hybrid operations. In short, this event demonstrates how even a digitally remote island nation like Iceland is part of the multi-domain hybrid warfare theatre, where cyber-attacks precede or accompany air, sea or infrastructure threats.