Russian cyberattacks in Denmark are now considered a sharper threat, Danish authorities said on 30 June, warning that Russian state-backed hackers may try to carry out destructive operations against essential services such as electricity, water and internet supply.
The Danish Resilience Agency (Styrelsen for Samfundssikkerhed) said the threat from destructive cyberattacks by Russian state hackers has increased, while keeping Denmark’s overall threat level for destructive cyberattacks at medium. The agency urged all organisations working with vital societal functions to strengthen their cybersecurity.
Russian cyberattacks in Denmark remain at medium threat level
The new assessment does not mean that Denmark has raised its overall national threat level for destructive cyberattacks. That level remains medium, a category introduced in June 2024 after Danish cyber authorities assessed that Russia had become more willing to use hybrid tools, including destructive cyber operations, against European NATO countries.
The Danish Resilience Agency said Denmark is at risk of attempts by Russian state hackers to carry out destructive cyberattacks “where the intention is to create more extensive consequences for vital societal functions than previously”.
The warning focuses on attacks designed not only to steal data or disrupt websites, but to damage systems, erase data or interfere with the digital infrastructure behind essential services. In practice, such operations could affect power supply, water distribution, telecommunications or other core functions used by citizens and businesses.
State hackers pose a different risk from pro-Russian groups
Danish authorities distinguish between Russian state-backed hackers and pro-Russian hacker groups. The latter have often used distributed denial-of-service attacks, known as DDoS attacks, to overload websites and create disruption. These attacks can be visible and politically motivated, but they usually have limited technical impact.
State hackers are assessed differently because they have the capacity to plan coordinated and targeted cyberattacks against critical infrastructure. According to the Danish Resilience Agency, this makes the threat “markedly” different from that posed by loosely organised pro-Russian actors.
Christine Engel Christensen, deputy director of the Danish Resilience Agency, said that some hostile actors “do not wish us well” and, in the worst case, may try to disturb “the core functions of our society, such as the supply of electricity, water and internet”.
The agency said the updated assessment is based on indications that Russian state hacker groups are likely showing a greater willingness to take risks in destructive cyber operations against European NATO countries.
Denmark coordinates with intelligence services
The Danish Resilience Agency said it is working closely with the Danish Defence Intelligence Service (Forsvarets Efterretningstjeneste, FE) and the Danish Security and Intelligence Service (Politiets Efterretningstjeneste, PET). It is also in contact with relevant authorities about the sharper threat picture.
The warning comes as Denmark and other Nordic countries continue to reassess their resilience against hybrid threats linked to Russia’s war against Ukraine. Since 2022, cyberattacks, sabotage, disinformation campaigns and pressure on critical infrastructure have become central parts of the European security debate.
Denmark is particularly exposed because of its role as a NATO member, its support for Ukraine and its position in Northern Europe and the Baltic Sea area. Danish authorities have repeatedly described cyber resilience as part of national preparedness, alongside energy security, civil protection and defence planning.
A wider European and NATO concern
The Danish assessment fits into a broader European pattern. NATO has warned that allies face hybrid threats from state and non-state actors using cyberattacks, sabotage, deception and information operations to undermine security. The alliance has also said that hybrid actions against one or more allies could, in certain circumstances, lead to the invocation of Article 5.
The European Union has taken a similar approach. EU institutions define hybrid threats as coordinated harmful activities that can include cyberattacks, economic coercion, information manipulation and attempts to undermine democratic decision-making. Since 2022, the EU has strengthened its work on critical infrastructure resilience, including sectors such as energy, water, transport and health.
For Denmark, the immediate message is operational rather than political: organisations responsible for essential services should review their defences, incident response plans and supply-chain risks. The focus is on preventing cyber incidents from becoming broader disruptions to society.
The sharper warning does not indicate that an attack is imminent. It does, however, show that Danish authorities now consider Russian cyber operations a more serious risk to the systems that keep everyday life running. In the Nordic and European context, cybersecurity is increasingly treated not as a technical issue alone, but as a core part of democratic and societal resilience.





