Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

22 Danish Energy Organizations Were Hacked Through Zyxel Firewalls—Was Russia Really Behind It?

By TheFinanceBase Team9 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

In May 2023, attackers compromised 22 organizations involved in Denmark’s energy infrastructure by exploiting vulnerabilities in Zyxel firewalls. Some attackers reached industrial-control environments, while affected operators disconnected from the internet and continued operating in “island mode.”

The incident was initially associated with Russia’s Sandworm group, but that attribution remains unresolved. SektorCERT reported possible Sandworm-related activity; later analysis by Forescout found no direct link to Sandworm and suggested that at least part of the activity resembled broad Mirai-related exploitation. The public evidence does not establish a nationwide blackout, physical damage, or Russian control of the entire campaign.

The short answer

  • When: May 2023.
  • Where: Denmark’s energy sector and related critical infrastructure.
  • How: Exploitation of internet-facing Zyxel firewalls, primarily through CVE-2023-28771.
  • Scale: SektorCERT said 22 energy organizations were compromised.
  • Impact: Attackers obtained control of some firewalls, extracted configurations and usernames, deployed Mirai-related malware in some cases, and reached some industrial-control environments.
  • Operational response: Several organizations disconnected from the internet and entered island mode.
  • Attribution: Possible Sandworm involvement was initially reported, but Forescout later found no direct link.
  • Confirmed nationwide outage: Not established by the available sources.

SektorCERT described the incident as the most extensive coordinated cyberattack against Danish critical infrastructure it had seen at the time. That description should be attributed to SektorCERT rather than presented as an independent ranking.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happened to Denmark’s energy organizations?

The affected organizations operated parts of Denmark’s energy infrastructure. Public reporting does not provide a complete victim-by-victim matrix showing which companies experienced each type of impact. The figure of 22 therefore should not be read as meaning that all organizations suffered identical compromises.

#1 Best Overall
Sale
Zyxel Cyber Security Firewall | Up to 5 Users | Dual-WAN | USGLITE60AX
  • WITH 1-YEAR ELITE PACK INCLUDED – New devices registered on or after January 19, 2026 receive complimentary comprehensive web filtering, advanced Nebula Pro features, and enhanced ransomware protection for 12 months. Previously registered devices are not eligible
  • ENTERPRISE-GRADE SECURITY WITH DUAL-WAN INTELLIGENCE – Real-time threat intelligence with IPS and anti-malware delivers wire-speed protection, while smart traffic distribution ensures optimal bandwidth usage and uninterrupted connectivity for critical business applications
  • AX6000 WIFI 6 READY WITH 2X 2.5G MULTI-GIG PORTS – Dual-band support with seamless Zyxel mesh capability provides far-reaching wireless coverage, while multi-gig Ethernet enables high-speed WAN/LAN connectivity without re-cabling
  • CLOUD MANAGEMENT MADE SIMPLE – Set up in minutes via Nebula mobile app and manage your entire network from a single centralized cloud platform without additional hardware controllers or software
  • SUSTAINABLE DESIGN – Constructed with up to 95% post-consumer recycled plastics, reduced packaging, and eco-friendly inks to minimize carbon footprint and environmental impact

The incident included several different outcomes: successful compromise of perimeter firewalls, access to configurations and usernames, infection of some devices with Mirai-related malware, possible access to industrial-control environments, and temporary isolation from the public internet. Those are serious security events, but they are not equivalent to process manipulation or a power-grid shutdown.

The available reporting does not establish that attackers changed generation settings, opened breakers, disrupted heating, damaged equipment, or caused a nationwide electricity or district-heating outage. Access to an industrial-control environment creates risk; it does not by itself prove that a physical process was manipulated.

Timeline of the attack

Date What happened
May 11, 2023 The first major wave targeted 16 Danish energy organizations. Initial reporting said 11 were successfully compromised.
May 22, 2023 A second wave was observed, involving additional tools and suspected exploitation of newly disclosed Zyxel vulnerabilities.
May 24, 2023 Zyxel publicly disclosed CVE-2023-33009 and CVE-2023-33010. The timing became important in later analysis of the second wave.
May 24–25, 2023 Additional Danish energy organizations were targeted with further exploit activity and payloads.
Around May 30, 2023 Public exploit code led to a sharp increase in attack attempts against Danish critical infrastructure, according to subsequent reporting.
November 14, 2023 SektorCERT’s account became public through reporting on the incident.
January 11–12, 2024 Forescout published follow-up analysis challenging the assumption that the two waves were one Sandworm-led operation.

Sources: SektorCERT’s incident report, SecurityWeek’s initial reporting, and Forescout’s later analysis.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How did the attackers get in?

The primary initial-access mechanism was exploitation of internet-facing Zyxel firewall appliances. The most important vulnerability in the first wave was CVE-2023-28771, a pre-authentication operating-system command-injection flaw.

In plain language, a vulnerable appliance could be made to execute commands remotely before an attacker had logged in. SecurityWeek reported a CVSS score of 9.8. Zyxel described the flaw as remotely exploitable through specially crafted network packets without authentication.

The affected product families included several Zyxel firewall lines, including:

  • ATP firewalls
  • USG FLEX firewalls
  • VPN-series devices
  • ZyWALL and USG devices

The second wave was initially linked by SektorCERT to CVE-2023-33009 and CVE-2023-33010. Forescout later argued that some victims may instead have been compromised through continued exploitation of CVE-2023-28771. The public evidence therefore does not support presenting one uncontested exploit chain for every affected organization.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This distinction matters because vulnerability disclosure dates and exploit activity can help determine whether an operation was a carefully planned campaign against selected targets or part of a wider effort scanning the internet for exposed devices.

What did attackers do after compromising the firewalls?

Reported activity included:

  • Executing commands on vulnerable firewalls.
  • Retrieving firewall configurations and usernames.
  • Obtaining complete control of some affected firewall devices.
  • Deploying Mirai-related malware, including a Moobot-like variant in later analysis.
  • Using some compromised appliances in distributed-denial-of-service attacks against entities in the United States and Hong Kong.
  • Reaching industrial-control environments at some organizations.

Mirai is associated with malware campaigns that compromise internet-connected devices and use them in botnets. Its presence is significant because it supports the possibility that at least some of the activity was opportunistic or criminal rather than a bespoke operation designed solely to sabotage Denmark’s energy infrastructure.

At the same time, “opportunistic” does not mean harmless. A compromised firewall can expose routing information, credentials, remote-access settings, and paths into sensitive networks. The attacker’s original motive may be DDoS or botnet expansion, while the compromise still creates a route toward operational technology.

Was Sandworm responsible?

SektorCERT’s initial assessment

SektorCERT said at least one attack contained activity associated with Sandworm, a Russian state-sponsored group linked to the GRU. Its report raised the possibility of state-actor involvement, but it did not establish that Sandworm carried out the entire campaign or compromised all 22 organizations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Forescout’s later analysis

Forescout subsequently reported no direct link to Sandworm and suggested that the two apparent waves may have been unrelated. Its analysis assessed that:

  • The first wave showed some characteristics of a targeted operation but lacked a direct Sandworm connection.
  • The second wave looked more like broad exploitation and Mirai botnet building.
  • Danish critical infrastructure may have been caught in a wider campaign rather than selected as the sole target.
  • Specific targeting of critical infrastructure could not be completely ruled out for the first wave.

The most defensible conclusion is that attribution remains contested. It is accurate to say that SektorCERT reported possible Sandworm-associated activity and that Forescout later found no direct link. It is not accurate to say that Russia definitively hacked all 22 organizations or that the Kremlin attacked Denmark’s power grid.

Why the incident was significant even without a confirmed blackout

The attack demonstrated how a common perimeter device can become a shared attack surface across critical infrastructure. A utility may have carefully protected its control systems while leaving an internet-facing firewall vulnerable to pre-authentication command execution. If that firewall connects the external environment to corporate or operational networks, its compromise can undermine assumptions about the boundary.

The incident also illustrated five broader risks:

  1. Concentrated exposure: Multiple operators using the same appliance family can be affected by one vulnerability.
  2. Fast exploitation: Attackers acted around the time vulnerabilities were disclosed and exploited public code soon afterward.
  3. Credential exposure: Firewall configurations and usernames can help attackers plan further access.
  4. OT proximity: A network-device compromise may provide visibility into or access toward industrial-control environments.
  5. Resilience pressure: Operators may need to disconnect from the internet while continuing essential operations.

For executives and policymakers, the financial lesson is equally direct: the cost of an incident is not limited to lost electricity sales. Emergency response, forensic work, equipment replacement, regulatory reporting, customer communications, business interruption, and recovery can all create material costs even when service continues.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Zyxel USGFLEX200H Firewall | 50 Users | 1 Year Gold Security Pack
  • GOLD SECURITY PACK INCLUDED (1 YEAR): Anti-malware, sandboxing, IPS 2,500 Mbps, web filtering, DNS/IP/URL reputation, app patrol, AI SecuPilot, full UTM active from day one for up to 100 users
  • OFFLINE-CAPABLE SETUP AND UPDATES: Configure via Nebula portal wizard; update firmware offline via FTP on the local network, while the web interface remains fully accessible without internet after each update
  • RACK-MOUNT FANLESS DESIGN: with SPI 6,500 Mbps firewall throughput, 2,500 Mbps IPS, 1,200 Mbps VPN, the firewall supports up to 100 users, 600,000 concurrent sessions, 100 IPSec tunnels, 50 SSL VPN users, and 32 VLANs
  • MULTI-GIG FLEXIBLE PORTS: 6 x 1G plus 2 x 2.5G RJ-45 ports assignable as WAN or LAN, WAN load balancing, active-backup failover, 32 VLAN interfaces, Link Aggregation, and Device HA
  • NEBULA MANAGEMENT AND VPN: Centralized policy control, threat monitoring, and SD-VPN orchestration; supporting IKEv2/IPSec, SSL, Tailscale VPN, 100 IPSec tunnels, 50 SSL VPN users, and up to 40 managed APs
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What “island mode” means

Several affected operators disconnected their internet connections and operated in “island mode” while responding. This is a containment and resilience measure: the organization separates critical operations from external connectivity so attackers have fewer routes to maintain access or issue commands.

Island mode is not simply pulling a cable. Before an incident, operators should define:

  • Which systems can be disconnected safely.
  • How remote sites will be monitored without normal connectivity.
  • How field personnel will verify equipment status.
  • How staff will authenticate if centralized identity services are unavailable.
  • How vendors and regulators will communicate during isolation.
  • What evidence must be collected before reconnection.
  • How clean firmware, configurations, and credentials will be restored.

An isolation plan that has never been tested may leave an operator technically disconnected but operationally blind.

Lessons for utilities and critical-infrastructure operators

1. Treat perimeter appliances as critical assets

Asset inventories should include firewalls, VPN concentrators, remote-access gateways, cellular and wireless gateways, vendor-maintained appliances, legacy equipment, and devices managed by third parties. A firewall is an IT asset in many inventories, but its compromise can affect OT security and business continuity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Patch according to exploitability

Internet-exposed appliances with pre-authentication command execution require emergency treatment, regardless of whether they are categorized as “just” network equipment. Response should include exposure checks, emergency patching, temporary access restrictions, vendor escalation, and a post-patch compromise assessment.

For affected Zyxel products, vendor guidance reported by SecurityWeek included patching, limiting management access to trusted IP addresses, disabling unused WAN services, considering geo-IP filtering, and disabling UDP ports 500 and 4500 when unnecessary. These are defense-in-depth measures, not universal substitutes for applying supported firmware updates. See the reported Zyxel hardening guidance.

3. Investigate after patching

Patching a compromised device does not prove that the attacker is gone. Teams should examine administrator accounts, configuration changes, port-forwarding rules, VPN settings, firmware integrity, outbound connections, and adjacent systems. Credentials exposed in a stolen configuration should be rotated, including service credentials and secrets embedded in appliance settings.

4. Monitor the network device itself

Endpoint detection tools may not see malicious activity occurring on a firewall. Monitoring should cover:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Configuration changes and newly created administrator accounts.
  • Unexpected firmware or binary downloads.
  • Unusual outbound connections and DNS or NTP behavior.
  • Changes to VPN settings and port-forwarding rules.
  • Traffic associated with botnet infrastructure.
  • Unexpected reboots, lockups, or loss of management access.

5. Segment OT from IT and the perimeter

Segmentation should limit what a compromised firewall, corporate workstation, vendor account, or jump server can reach. Operators should verify that remote substations, engineering workstations, production sites, and control networks do not rely on a single perimeter control or shared administrative identity.

6. Prepare for third-party access

Managed-service providers and equipment vendors may have privileged paths into the same environment. Those connections need inventory, approval controls, strong authentication, logging, time limits, and a safe emergency-disconnect procedure.

Common mistakes when responding

  • Patching without investigating: Altered accounts or rules may remain after the update.
  • Assuming no outage means low impact: Reconnaissance and credential theft can create future risk.
  • Treating the firewall as isolated: It may contain routes, secrets, and remote-access information.
  • Waiting for attribution: Immediate containment does not depend on knowing whether the actor is Russian, criminal, or unknown.
  • Making internet disconnection the whole plan: Isolation requires offline monitoring and a tested restoration process.
  • Restoring an unverified backup: A backup may preserve attacker-created accounts or modified rules.
  • Scanning OT recklessly: Security assessments must respect safety constraints and the fragility of legacy control systems.

What remains unknown

Public reporting does not fully establish:

  • The identities of every affected organization.
  • Whether the same actor controlled both attack waves.
  • The exact extent of industrial-control access at each victim.
  • Whether Sandworm directly participated.
  • Whether any attacker retained persistence after containment.
  • The precise operational and financial impact on each organization.

Those gaps are reasons to qualify the story, not reasons to dismiss it. The confirmed facts already show that a widely deployed, internet-facing appliance can become a common entry point into critical infrastructure.

What this means for organizations reviewing their own exposure

Operators should begin with their own inventory and response capability rather than with attribution. Confirm which perimeter devices are publicly reachable, whether management interfaces are restricted, whether supported firmware is installed, and whether logs are centralized and retained.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If an appliance may have been compromised, replacement or rebooting alone is insufficient. The organization should preserve evidence, validate firmware and configuration integrity, rotate exposed credentials, review adjacent network activity, and confirm that segmentation still works. Utilities without in-house 24/7 monitoring or OT incident-response expertise may need specialist assistance, but providers should be evaluated for industrial-environment experience and the ability to work safely during isolation.

The Bottom Line

Bottom line: The May 2023 incident was a major compromise of Danish energy organizations through vulnerable Zyxel firewalls, not a proven nationwide Russian attack or blackout. Its clearest lesson is that internet-facing network appliances belong inside the critical-infrastructure security and resilience program: patch them urgently, monitor them directly, isolate safely, and investigate compromise rather than assuming an update restores trust.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.