Denmark’s Eastern High Court ordered the state to pay telecom operator TDC Net 80 million Danish kroner, about $12 million, after cybersecurity authorities required the company to remove Huawei equipment from its network on national security grounds. The dispute focused on Huawei-based infrastructure in TDC Net’s DWDM network, which the operator had built and maintained since 2011, and a 2023 order from Denmark’s Center for Cyber Security to phase out the vendor’s equipment over security concerns.
The court held that Denmark was entitled to impose the restriction based on objective security assessments, but ruled that forcing replacement of existing Huawei infrastructure amounted to expropriation, triggering a right to compensation. The decision underscores the legal and financial consequences governments may face as European countries implement 5G security measures and reduce reliance on suppliers such as Huawei under broader regional telecom security policies.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Denmark’s Eastern High Court in Copenhagen ruled that forcing replacement of TDC NET’s existing Huawei-based infrastructure amounted to expropriation, and ordered the state to pay 80 million Danish kroner, about $12 million, in compensation. The court also upheld the legality of the security-driven restriction itself.
In 2023, Danish cybersecurity authorities, identified as the Center for Cyber Security, ordered TDC NET to remove or phase out Huawei equipment from its DWDM network on national security grounds.
TDC NET had built and maintained its Huawei-based DWDM network in good faith since 2011, forming the basis for the later dispute over mandated equipment removal.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.