GRU-backed Z-Pentest cyberattack on Tureby Alkestrup Waterworks: pipe bursts and water outages in Køge, Denmark
- Event Year
- 2024
- Reliability
- Confirmed
- Country
- Denmark
- Industry
- Water and Wastewater Systems
- Attack Type
- Targeted Attack
Description
In late 2024, the pro-Russian hacking group Z-Pentest accessed the human-machine interface of Tureby Alkestrup Waterworks in Køge, Denmark through an internet-exposed VNC service protected by a weak or default password. Using open-source scanning tools to identify the exposed device and password brute-forcing to authenticate, the attackers manipulated water pressure controls through the HMI, causing three water mains to burst. Approximately 50 households in Køge lost water service for seven hours; approximately 450 additional households lost supply for one hour. Jan Hansen, head of the waterworks, confirmed the attack and acknowledged that the utility had switched to a cheaper and less secure cybersecurity setup in the period preceding the intrusion.
Denmark's Defence Intelligence Service (DDIS) publicly attributed the attack to Z-Pentest on December 19, 2025, the first time Danish authorities formally attributed a cyberattack causing physical infrastructure damage to a Russian-linked actor. CISA advisory AA25-343A (December 9, 2025), issued jointly with the FBI, NSA, and international partner agencies, documents Z-Pentest's operating methodology: scanning for internet-facing VNC services on default ports 5900 to 5910, brute-forcing weak or default passwords, and issuing commands directly through the HMI without deploying any malware. The advisory identifies water and wastewater systems as a primary target sector. The US Department of Justice confirmed on December 10, 2025 that CyberArmyofRussia_Reborn (CARR), the organization from which Z-Pentest's founding members split in September 2024, was 'founded, funded, and directed' by Russian military intelligence (GRU).
Impact
Three water mains burst in Køge, Denmark. Approximately 50 households lost water supply for seven hours; approximately 450 additional households experienced outages of approximately one hour. No injuries were reported and no water quality issue was identified. Financial cost to the utility has not been disclosed publicly.
Sources
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a
- https://www.justice.gov/opa/pr/justice-department-announces-actions-combat-two-russian-state-sponsored-cyber-criminal
- https://www.euronews.com/2025/12/19/denmark-blames-russia-for-cyberattacks-on-water-utility-and-election-websites
- https://www.bleepingcomputer.com/news/security/denmark-blames-russia-for-destructive-cyberattack-on-water-utility/
- https://securityaffairs.com/185885/hacking/russia-was-behind-a-destructive-cyber-attack-on-a-water-utility-in-2024-denmark-says.html