On 18 August 2023 the Danish hosting providers CloudNordic and AzeroCloud, both owned by Certiqa Holding, were hit by ransomware that encrypted server disks along with the primary and secondary backup systems. Several hundred Danish companies were affected. The providers declined to pay and stated that the majority of customers had lost all data.
The companies described the likely path: during a migration between data centres, servers that had previously been on separate networks were cabled into the internal network used to administer all systems, and some machines were already infected before the move.
The Isolation Was The Control
A backup that can be reached from the environment it protects is not a backup; it is a second copy on the same fate-shared network. The separation was doing the work, and the migration removed it as an incidental consequence of cabling.
We have recorded the same collapse at 25-0917, where one store held every customer’s firewall configuration, and at 22-1222, where the vault backups were reachable from the environment that held the keys. What makes this case unusually clean is that nobody decided to remove the isolation. It was lost during a move.
Refusal, With Nothing Left To Trade
This corpus consistently supports non-payment and consistently records who pays for it. At 22-1024 an insurer refused and its customers’ medical claims were published; at 22-0903 a school district refused and student assessments were.
Here the position is different again. With every copy encrypted, payment was the only path to recovery rather than merely the path to silence — and the providers still declined, and the customers lost the data. That is the honest limit case for the advice, and the desk records it as such rather than filing it as another vindication.
Hosting Pools The Failure
Several hundred businesses lost their data simultaneously because they had made the same sensible decision: not to run their own infrastructure.
We filed that trade at 22-1202, where a hosted Exchange service was retired rather than restored, and at 26-0704. Outsourcing an operational burden concentrates it. The customer’s own diligence has no bearing on the outcome, and there is no version of customer-side best practice that survives the provider losing every copy.
Compiled from contemporaneous reporting of the providers’ own statements to customers, listed below. No ransomware operation is named — none was authoritatively identified. No figure is asserted for data volume or for how many customers ultimately recovered anything. Graded high on the account as given; it rests substantially on the providers’ own description of their network. Corrections: corrections@forensicpost.com.
- Cloud hosting firms hit by devastating ransomware attackHelp Net Security
- Danish hosting firms lose all customer data in ransomware attackData Center Dynamics