Norway

Country

Dragonforce Ransomware Locks Local Norwegian Newspaper Servers, Printing Halted

May 24, 2025

Norwegian regional newspaper Altaposten and its sister publication Ávvir were hit by a ransomware attack. The ransomware locked key IT resources, including the server shared by both newspapers, and prevented staff from accessing content and publishing normally. The media outlet’s owners refused to pay the ransom. Management stated it was more cost‑effective to discard the affected server and rebuild rather than follow the attackers’ instructions to retrieve decryption keys. The printed edition of Altaposten was canceled — the first time since the paper’s launch in 1969.

read more

Valve Opened in Norway Dam Attack

April 7, 2025

Hackers were able to get into the systems of a Norwegian dam this past April and open its water valve at full capacity.

The breach occurred at the Lake Risevatnet dam near the city of Svelgen in Southwest Norway. Attackers compromised a weak password on the web-accessible control panel and were able to open valves all the way at the dam. The valve ran at full capacity (497 m3/s above normal) for at least four hours before workers at the dam discovered the unauthorized change. The hack didn’t put anyone in danger, barely moving water output over the dam’s minimum water flow requirement, according to a report in the Norwegian energy news outlet Energiteknikk.

read more

Aircraft Unable to Receive GPS Signals in Baltic Sea, the Black Sea and Eastern Mediterranean.

March 22, 2024

Russia is suspected of launching a record-breaking 63-hour-long attack on GPS signals. The Baltic Sea, the Black Sea and the eastern Mediterranean – the regions where Russia’s military has been most active – have seen an increase in disruption to the Global Positioning System (GPS). This has left aircraft unable to receive GPS signals.

The incident, which affected hundreds of passenger jets, occurred amid rising tensions between Russia and the NATO military alliance more than two years since the start of Russia’s full-scale invasion of Ukraine.

read more

Key Systems Down at Norwegian Cruise Company Hurtigruten After Ransomware rattack

December 14, 2020

Norwegian cruise company Hurtigruten sustained a cyberattack earlier on Monday and several key systems are currently down, the company said in a statement. The company, which operates ferries along the Norwegian coast as well as cruises in the Arctic and Antarctic in normal times, said it did not expect the attack to lead to a “material financial effect”, it said.

No details have been shared of the strain of ransomware, but the company will be juggling whether to pay its extortionists a handsome fee in order to have its data decrypted or attempt to restore its systems from its own backups.

“This is a serious attack. Hurtigruten’s global IT infrastructure appears to be affected,” Ole-Marius Moe-Helgesen, the company’s head of IT, said in a statement, adding that the company had implemented “comprehensive measures” to limit the damage from the attack.

read more

SAS Scandinavian Airlines’ App Compromised by a Cyberattack

February 14, 2024

SAS Scandinavian Airlines was hit by a cyber attack on February 14th, compromising its app. The airline was said to be working on a solution, with reports saying that the problem was fixed to a large extent. Still, SAS warned that the attack may have targeted customer data following the breach.

read more

DDoS Attack Severely Distrupts Norwegian Data Protection Authority Datatilsynet

September 11, 2023

In September 2023, Norwegian Data Protection Authority Datatilsynet suffered a severe disruption when their website fell victim to a Distributed Denial of Service (DDoS) attack. Attributed to the Russian group NoName057(16), the incident caused physical damage, stressing hardware to the point of failure, emphasizing an unusual level of attack sophistication.

read more

Cyberattack Affects Platform used by 12 Government Ministries in Norway

July 24, 2023

The Norwegian government is warning that its ICT platform used by 12 ministries has suffered a cyberattack after hackers exploited a zero-day vulnerability in third-party software.

This platform is used by twelve ministries in the country, except for the Prime Minister’s Office, the Ministry of Defense, the Ministry of Justice, and the Ministry of Foreign Affairs. The hackers might have accessed and/or exfiltrated sensitive data from the ICT system, leading to a data breach.

Despite the compromised platform’s critical role in the government’s daily operations, the recent cyberattack will not necessitate a halt in work activities.

read more

Norwegian Energy Company Investigating Cyberattack at Brazil Subsidiary

February 15, 2023

Norwegian energy services company Aker Solutions said a subsidiary company in Brazil has been subjected to a cyber attack on its IT systems.Aker Solutions said it does not yet know the full extent of the situation, and that a dialogue is being established with the authorities in Brazil about the incident.

In addition, its global IT organisation is working to resolve the situation with external expertise. “The attack is currently directed at CSE, and the attackers claim that they have entered the IT systems, encrypted digital files and locked access to data,” said the company, led by chief executive Kjetel Digre.

CSE is a fully-owned Aker Solutions subsidiary with 450 employees in Brazil. Its main business is providing maintenance and modifications services to oil and gas installations offshore Brazil.

read more

Recycling, Mining Provider, Tomra, Hit in ‘Extensive’ Attack

July 16, 2023

Norwegian recycling and mining corporation Tomra suffered an “extensive cyberattack” Sunday which affected some of its data systems, company officials said.
“Tomra has been targeted by an extensive cyberattack directly affecting some of the company’s data systems,” the company said in a statement. “Relevant authorities have been informed, and all available internal and external resources have been mobilized to contain and neutralize the incident.
“The attack was discovered in the morning of July 16th (CET), and immediate actions were taken to stop it and mitigate consequences. We immediately disconnected some systems to contain the attack, and Tomra is currently assessing whether customers and employees might experience reduced stability in our services. Our primary focus now is to get all systems up and running again as fast as possible.”

read more