In late 2024, the pro-Russian hacking group Z-Pentest accessed the human-machine interface of Tureby Alkestrup Waterworks in Køge, Denmark through an internet-exposed VNC port protected by a weak or default password. The attackers manipulated water pressure controls through the HMI, bursting three water mains. Approximately 50 households in Køge lost water service for seven hours; approximately 450 additional households experienced outages of about one hour. Jan Hansen, head of the waterworks, confirmed the attack and acknowledged that the utility had recently switched to a cheaper, less secure cybersecurity setup.
On December 19, 2025, Denmark’s Defence Intelligence Service (DDIS) publicly attributed the attack to Z-Pentest, the first time Danish authorities formally attributed a cyberattack producing physical infrastructure damage to a Russian-linked actor. The coordinated CISA advisory AA25-343A, published December 9, 2025 jointly with the FBI, NSA, and international partners, describes Z-Pentest’s standard methodology: scan public IP ranges for VNC services on default ports 5900 to 5910, brute-force weak passwords, then manipulate process controls directly through the HMI interface without deploying malware. The advisory names water and wastewater systems as a primary sector targeted. On December 10, 2025, the US Department of Justice confirmed that CyberArmyofRussia_Reborn (CARR), the organization from which Z-Pentest’s founding members split in September 2024, was “founded, funded, and directed” by the GRU.
The Tureby incident is the first confirmed Z-Pentest operation in the RISI archive with documented physical-damage consequences outside the United States. The attack method, HMI access via internet-exposed VNC using weak or default credentials, matches the Los Angeles CARR meat plant incident from November 2024 and the broader campaign documented by CISA AA25-343A, which also links CARR to damage at US drinking water systems in the same period. The full incident record is available here.