Power Grid
Danish energy sector — coordinated Zyxel firewall intrusions
11–22 May 2023 (two waves)
Denmark
What happened
In a first wave on 11 May 2023, attackers exploited a critical command-injection vulnerability (CVE-2023-28771) in Zyxel firewalls to compromise 11 of 16 targeted Danish energy companies, reading device configurations and credentials. A second, more sophisticated wave beginning 22 May exploited two Zyxel zero-day vulnerabilities not patched until 24 May, and SektorCERT said attackers in this phase reached the industrial control systems of multiple companies. In total, 22 Danish energy-sector organizations were compromised across the two waves. Some operators deliberately disconnected from the wider grid and ran in island mode, generating and distributing power locally, as a precaution. SektorCERT described the campaign as the largest coordinated cyberattack on Danish critical infrastructure to date. The marker is placed at a national reference point since the affected companies were not individually named in the cited reporting.
When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.
- Evidence
- Documented
- Confidence
- High
- Infrastructure
- Power Grid
- Latitude
- 56.0000°
- Longitude
- 10.0000°
Attribution
Responsibility disputed SektorCERT assessed likely links to Sandworm (Russian military intelligence, GRU)
SektorCERT's November 2023 report suggested links to the Sandworm threat actor associated with Russian military intelligence, based on infrastructure overlap; this attribution was not independently confirmed by an allied government and remains an assessment rather than established fact.
