CSIDB logo
Incident

Danish Data Protection Authority

Incident posture

Attack window
Sep 2023
Location
Denmark
Status
Historical
CIA posture
Available to members
Updated
2026-01-06 21:04

Linked entities

Victim
Danish Data Protection Authority
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Danish Data Protection Authority's website was rendered inaccessible due to a DDoS attack attributed to the Russian hacker group NoName057(16), which also targeted multiple other government agencies. The attack caused physical infrastructure damage described as a hardware failure, forcing the agency to restore stable operations while its website displayed connection errors. NoName057(16) publicly claimed responsibility for the incident via their Telegram channels, though the technical identification process by the authority's service provider remained unspecified.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On September 11, 2023, the Danish Data Protection Agency (Datatilsynet) reported that its website became inaccessible the previous afternoon, displaying a "connection failed" error message to visitors. The outage stemmed from a distributed denial-of-service (DDoS) attack targeting multiple Danish government websites, attributed to the Russian hacker group NoName057(16). According to Datatilsynet’s statement, their service provider confirmed the attack caused a physical infrastructure failure—described metaphorically as wires falling from ceilings amid sparks—necessitating hardware restoration to stabilize operations. The group publicly claimed responsibility through Telegram channels, though the article notes skepticism about direct Russian state involvement while acknowledging the attackers’ self-identification. NoName057(16)’s actions disrupted access to Datatilsynet’s public-facing services for at least several hours, with recovery efforts ongoing at the time of reporting.

Datatilsynet’s provider identified the attack’s origin but did not disclose technical detection methods or mitigation specifics beyond confirming the physical infrastructure damage. The incident impacted multiple governmental entities, though Datatilsynet was the only named agency. Restoration efforts focused on repairing hardware components rather than solely addressing software or traffic overloads, indicating an unusually severe disruption. The agency’s communication emphasized transparency regarding the attack’s source and infrastructural consequences but did not detail data compromises, operational downtime duration, or broader systemic effects beyond immediate service unavailability. NoName057(16)’s Telegram posts served as the primary attribution evidence, though the article highlighted unresolved questions about the provider’s forensic validation process.

Sources

Sources available to members: 1 source.

CSIDB