Denmark’s cyber agency SAMSIK and the Danish Defence Intelligence Service have raised their assessment of the threat from destructive cyberattacks against Danish targets. The move follows an escalation in Russian hybrid activity intended to pressure European governments to reduce support for Ukraine, including cyber and influence operations, DDoS attacks, compromises of CCTV systems, and manipulation of inadequately protected critical-infrastructure components.
Organizations connected to support for Ukraine face elevated risk, particularly defence-sector personnel and Western supply-chain factories, warehouses, and critical-infrastructure operators. Authorities expect activity to become more frequent and potentially more disruptive, including attacks conducted through proxies or disposable agents; however, cybercrime and cyber espionage remain the most prevalent threats to Nordic organizations. A direct Russian military attack on a NATO member is still assessed as unlikely, but any such conflict could include destructive cyber operations aimed at supporting military activity and disrupting Western decision-making.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
ICCT research documented more than 180 Russian-attributed hybrid incidents in Europe since the start of Russia's war against Ukraine, including carried-out, attempted, and foiled activity. Arson and explosive placements were the most common recorded category, followed by vandalism; ICCT said the count excludes cyberattacks, drone incidents, and cases still under investigation.
Denmark's SAMSIK and the Danish Defence Intelligence Service raised their assessed threat level for destructive cyberattacks against Danish targets. The assessment cited an escalating Russian hybrid-threat campaign intended to pressure European countries to reduce support for Ukraine, with Ukraine-supporting entities facing elevated risk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
icct.nl
Open sourcemalware.news
Open sourcetruesec.com
Open sourcesamsik.dk
Open sourcefe-ddis.dk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.