CSIDB logo
Incident

Tivoli

Incident posture

Attack window
Aug 2019
Location
Denmark
Status
Historical
CIA posture
Available to members
Updated
2025-11-03 00:00

Linked entities

Victim
Tivoli
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers compromised the website of a prominent Danish amusement park, resulting in the theft of personal information belonging to up to 1,000 guests. The breach, which occurred in early August, targeted one of Europe's oldest and most popular tourist destinations, marking it as another major Danish company to suffer a significant customer data compromise through its online systems.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early August 2019, unauthorized actors breached the website of Tivoli Park, a historic amusement park in Copenhagen and one of Europe’s oldest and most frequented tourist attractions. The cyberattack resulted in the theft of personal information belonging to as many as 1,000 guests. Details about the incident’s scope were not publicly disclosed until August 17, 2019, when media outlets reported the breach. The attack targeted customer data stored on Tivoli’s web systems, though the specific vulnerabilities exploited or methods used by the attackers were not described in available sources. No information was provided regarding how the intrusion was detected, whether systems were taken offline during the investigation, or what immediate containment measures were implemented by the organization.

The compromised data’s exact nature—such as names, payment details, or contact information—remained unspecified in public reporting. The breach positioned Tivoli among a growing list of major Danish companies that experienced customer data theft through website compromises, though the other affected entities were not named. Tivoli’s status as Denmark’s premier tourist destination amplified concerns about reputational harm following the incident. No customer-facing mitigation steps, such as credit monitoring offers or forced password resets, were detailed in the available information. The park did not disclose whether regulatory authorities or law enforcement were notified, nor were any operational disruptions or financial impacts quantified. Consequences centered on the unauthorized data access itself and the park’s inclusion in a broader pattern of Danish corporate cyber incidents.

Sources

Sources available to members: 1 source.

CSIDB