hw_e7834ea1ebc525fa
Pro-Russian DDoS knocks Danish Ministry of Defence websites offline for hours.
On 8 December 2022 a major distributed-denial-of-service campaign targeted the websites of Denmark’s Ministry of Defence, rendering them inaccessible for several hours according to Danish cybersecurity authorities. The attack was attributed by Denmark’s Centre for Cyber Security (CFCS) to pro-Russian hacktivist groups operating in the wake of the Ukraine war. Although no physical damage occurred, the disruption focused on a defence institution — signaling an escalation beyond mere digital nuisance. Danish briefings described the incident as hybrid pressure: leveraging cyber means to degrade readiness and test institutional resilience rather than directly destroy assets. The event catalysed upgrades of Denmark’s digital defences and prepared an uptick of subsequent campaigns in 2023-24. It also heightened awareness that infrastructure interruptions need not involve explosives or munitions to qualify as hybrid warfare. The episode prompted Denmark to raise its threat assessment for cyber exploitation of defence targets. Although attribution stopped short of naming the Russian state, the pattern aligned with Kremlin-linked cyber groups targeting NATO countries’ digital and defence systems.
E/M/R/S scores
- EExistence0/4 · Not assessed
- MIntent0/4 · Not assessed
- RRussian actor link0/4 · Not assessed
- SRussian state responsibility0/4 · Not assessed
Facts
No facts
Sources
-
- Role
- discovery_lead
- Date
- 2022-12-07T23:00:00Z
On 8 December 2022 a major distributed-denial-of-service campaign targeted the websites of Denmark’s Ministry of Defence, rendering them inaccessible for several hours according to Danish cybersecurity authorities. The attack was attributed by Denmark’s Centre for Cyber Security (CFCS) to pro-Russian hacktivist groups operating in the wake of the Ukraine war. Although no physical damage occurred, the disruption focused on a defence institution — signaling an escalation beyond mere digital nuisance. Danish briefings described the incident as hybrid pressure: leveraging cyber means to degrade readiness and test institutional resilience rather than directly destroy assets. The event catalysed upgrades of Denmark’s digital defences and prepared an uptick of subsequent campaigns in 2023-24. It also heightened awareness that infrastructure interruptions need not involve explosives or munitions to qualify as hybrid warfare. The episode prompted Denmark to raise its threat assessment for cyber exploitation of defence targets. Although attribution stopped short of naming the Russian state, the pattern aligned with Kremlin-linked cyber groups targeting NATO countries’ digital and defence systems.