Desk live·
ForensicPost
Ransomware/Availability/File 23-0818b

CloudNordic Lost Customer Data After Backups Were Encrypted Alongside Production

CloudNordic and AzeroCloud were encrypted on 18 August 2023 — primary storage and both backup tiers together. The companies refused to pay and told several hundred Danish customers their data was gone.

Constructed geometry · not a chart of case data
JurisdictionDenmarkCopenhagenthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCloudNordic and AzeroCloud
ActorUnattributed
S. Rosler12 min readConfidence: high2 sources reviewed

On 18 August 2023 the Danish hosting providers CloudNordic and AzeroCloud, both owned by Certiqa Holding, were hit by ransomware that encrypted server disks along with the primary and secondary backup systems. Several hundred Danish companies were affected. The providers declined to pay and stated that the majority of customers had lost all data.

The companies described the likely path: during a migration between data centres, servers that had previously been on separate networks were cabled into the internal network used to administer all systems, and some machines were already infected before the move.

The Isolation Was The Control

A backup that can be reached from the environment it protects is not a backup; it is a second copy on the same fate-shared network. The separation was doing the work, and the migration removed it as an incidental consequence of cabling.

We have recorded the same collapse at 25-0917, where one store held every customer’s firewall configuration, and at 22-1222, where the vault backups were reachable from the environment that held the keys. What makes this case unusually clean is that nobody decided to remove the isolation. It was lost during a move.

Refusal, With Nothing Left To Trade

This corpus consistently supports non-payment and consistently records who pays for it. At 22-1024 an insurer refused and its customers’ medical claims were published; at 22-0903 a school district refused and student assessments were.

Here the position is different again. With every copy encrypted, payment was the only path to recovery rather than merely the path to silence — and the providers still declined, and the customers lost the data. That is the honest limit case for the advice, and the desk records it as such rather than filing it as another vindication.

Hosting Pools The Failure

Several hundred businesses lost their data simultaneously because they had made the same sensible decision: not to run their own infrastructure.

We filed that trade at 22-1202, where a hosted Exchange service was retired rather than restored, and at 26-0704. Outsourcing an operational burden concentrates it. The customer’s own diligence has no bearing on the outcome, and there is no version of customer-side best practice that survives the provider losing every copy.

How we reported this

Compiled from contemporaneous reporting of the providers’ own statements to customers, listed below. No ransomware operation is named — none was authoritatively identified. No figure is asserted for data volume or for how many customers ultimately recovered anything. Graded high on the account as given; it rests substantially on the providers’ own description of their network. Corrections: corrections@forensicpost.com.

Sources
  1. Cloud hosting firms hit by devastating ransomware attackHelp Net Security
  2. Danish hosting firms lose all customer data in ransomware attackData Center Dynamics
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary