Skip to content
Back to incidents
Supply chain 13 December 2020

Supply chain – Multiple Danish organisations (SolarWinds)

Company

Multiple Danish organisations (SolarWinds)

Sector

Public and private sector

Actor

APT29 (Cozy Bear)

## Description

Multiple Danish organisations were compromised via the SUNBURST backdoor embedded in SolarWinds Orion updates. The actual intrusions occurred 8–9 months before discovery in December 2020. Danish victims were identified from DGA lists extracted from passive DNS data.

Affected organisations: COWI, SAS, Vestforbrændingen, Vallensbæk Kommune, Statens IT, BEC, Danmarks Nationalbank

Danmarks Nationalbank was also compromised. This is one of the most extensive supply chain attacks in history.

## References