Cyber Incident Victim: Folketinget
Date:
Dec 2015
Location:
Denmark
Summary
The Danish Parliament website was rendered inaccessible following a distributed denial-of-service (DDoS) attack that overwhelmed the system, causing prolonged downtime starting in the morning local time. The government acknowledged the disruption but could not identify the responsible actors or estimate a restoration timeline. This incident reflects a broader pattern of cyberattacks targeting governmental digital infrastructure globally, including notable breaches affecting U.S., German, and U.K. parliamentary systems, though specific impacts varied across these incidents.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On December 11, 2015, the Danish Parliament's official website, folketinget.dk, became inaccessible following a distributed denial-of-service (DDoS) attack. Parliamentary press spokesman Finn Tørngren Sorensen confirmed the incident, stating the attack commenced at 10:00 a.m. local time. The sustained barrage of malicious traffic overwhelmed the site’s infrastructure, forcing it offline. Despite immediate awareness of the attack, parliamentary officials could not restore functionality during the initial hours of the disruption. Sorensen publicly addressed the incident through Danish news outlet Avinsen.dk, acknowledging the attack’s operational impact but providing no technical details about its scale or methodology. The website remained nonfunctional for an unspecified duration after the initial outage, disrupting public access to parliamentary information and services. No ancillary systems or government networks beyond the primary website were reported as compromised.

Danish authorities did not identify the perpetrators or attribute motives for the attack during the incident’s immediate aftermath. Sorensen explicitly stated the government lacked knowledge regarding the responsible individual or group. No ransomware demands, hacktivist claims, or geopolitical statements accompanied the attack. The incident occurred amid a global pattern of cyberattacks targeting government entities, including contemporaneous breaches affecting U.S., German, and U.K. parliamentary systems. Restoration timelines for folketinget.dk were undisclosed, leaving public uncertainty about service continuity. The attack exclusively disrupted website availability, with no reported data exfiltration, defacement, or secondary malware infections.
