Menu
Browse

Cyber Incident Victim: Dagens Industri

Date:

Mar 2016

Location:

Sweden

Summary

A distributed denial-of-service (DDoS) attack targeted multiple Swedish media outlets, including Dagens Industri, causing significant service disruptions and forcing several news sites offline. The incident prompted involvement from national police and security agencies, with international partners engaged to trace the attack sources, which reportedly originated from hijacked computers potentially located to the east. A deleted social media post had threatened media and government entities for spreading alleged false propaganda prior to the attack. Industry representatives described the assault as highly severe and more coordinated than previous large-scale incidents, noting its broader impact beyond media to include a ferry operator. Most affected organizations restored services after sustained mitigation efforts.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 19, 2016, beginning at 19:30 local time, multiple Swedish media outlets and a ferry operator suffered disruptions due to a coordinated distributed denial-of-service (DDoS) attack. The targeted organizations included newspapers Dagens Industri, Dagens Nyheter, Expression, Svenska Dagbladet, Aftonbladet, Sydsvenskan, Helsingborgs Dagblad, and ferry company Destination Gotland. The attack rendered several news sites inaccessible over the weekend, with the CEO of Sweden's Industry Association Newspaper Publishers characterizing the incident as "very severe" in scale. A deleted tweet—the only publicly identified threat—had accused media and government entities of spreading "false propaganda" prior to the attacks. Initial technical analysis by Swedish authorities indicated the DDoS traffic originated from compromised computers, described as "hijacked" systems.

Cyber Incident Image

Sweden's Police Cybercrime Agency, led by Anders Ahlqvist, engaged national and international partners to investigate the attack sources, noting the assailants demonstrated greater coordination than perpetrators of similar 2012 DDoS incidents against Swedish government and private entities. While Ahlqvist referenced geographical indicators pointing "to the east"—a veiled allusion to potential Russian involvement—he explicitly cautioned against definitive attribution, emphasizing attackers could have orchestrated the campaign from another jurisdiction. Most affected media outlets restored services independently during the incident, though police and Sweden's Civil Contingencies Agency remained actively involved in mitigation and forensic efforts. The ferry operator Destination Gotland confirmed service interruptions but provided no additional technical details regarding operational impacts. No further threat actor communications or claimed motives surfaced beyond the initial deleted tweet.

Sources
Sources available to members
1 source