Danish critical infrastructure faced the biggest online attack in the country's history in May, according to SektorCERT, Denmark's specialist organization for the cybersecurity of critical kit. Detailing the attack waves in a report, it revealed that 22 companies were breached in just a few days. Some were forced to enter island mode operation, where they had to disconnect from the internet and cut any other other non-essential network connections [ref PDF]. In almost all cases unpatched vulnerabilities in Zyxel firewalls meant compromise was possible, and in some the attackers appeared well-resourced, exploiting vulnerabilities that weren't publicly announced (zero days). The attacks are thought to have been carried out by multiple groups, and at least one was potentially the infamous Sandworm operation nestled in Russia's Chief Intelligence Office (GRU), said the researchers. As the Zyxel devices weren't visible on public scanning services such as Shodan, SektorCERT believes Danish critical infrastructure was targeted specifically. Zyxel firewalls are used extensively by the organizations protected by SektorCERT and the vulnerabilities in these, announced in April, which allow remote attackers to gain complete control of the firewall without authentication, were blamed for most of the attacks. "For many of our members this was a surprise," SektorCERT said in the report [PDF]. "Many believed that because the firewall was relatively new, it must be assumed to have the latest ...
Inside Denmark’s hell week as critical infrastructure orgs faced cyberattacks
The Register
·Connor Jones
·Published Nov 13, 2023
·Updated
Affected Software
1 affected component
Zyxel Firewall
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a significant cyberattack on Denmark's critical infrastructure in May and its implications.
2
What security implications are discussed?
The article highlights the vulnerabilities of critical infrastructure to sophisticated cyberattacks and the need for enhanced cybersecurity measures.
3
What products or software are affected?
The attack specifically impacted Zyxel firewalls used in securing critical infrastructure.
4
Who is SektorCERT and what role do they play?
SektorCERT is Denmark's specialist organization for the cybersecurity of critical infrastructure, providing insights and updates on cyber threats.
5
What can organizations learn from Denmark's experience with this cyberattack?
Organizations can learn the importance of robust cybersecurity protocols and the necessity of preparedness for large-scale cyber threats.