How the Norsk Hydro ransomware attack happened, and why the company refused to pay
When ransomware locked the computers of Norsk Hydro, one of the world's biggest aluminum makers, the company refused to pay, went back to pen and paper, and asked retired employees to come back and help run production by hand.[1] This case file covers how the attack got in months before anyone noticed, what it cost, and the controls the company put in place afterward.
What happened
In December 2018, an employee at Norsk Hydro opened an email attachment that appeared to come from a trusted customer. It quietly installed malicious software that gave outside attackers a foothold in the company's network.[1]
For roughly 3 months, the attackers worked their way in further and collected administrator logins. Then, in March 2019, they used those admin accounts to push ransomware across the company's systems at once. Thousands of servers and PCs were locked, affecting all 35,000 employees in 40 countries and 170 plants.[1]
Some plants switched to manual operation. Staff printed orders and tracked work on paper, and retirees who remembered how things were done before computers volunteered to help.[1] The company refused the ransom demand and chose to rebuild its systems and restore data from backups instead.[1]
How they got in
The first step was a trusted-looking email. Because it seemed to come from a real customer, it did not raise alarms, and one click was enough to give the attackers remote access.[1]
The damage came from what happened next. Over time, the attackers gained administrative credentials, the master keys that manage the whole network. With those, they could use the company's own central management systems to deliver ransomware to computers across the organization in one push.[1] The attackers never needed to break into each plant separately. One set of stolen admin powers reached everywhere.
How it was caught
The attack was impossible to miss once the ransomware ran, but the break-in itself had gone unnoticed for about 3 months.[1] Norsk Hydro brought in Microsoft's incident response team to help investigate and rebuild.[1]
The company also became known for how openly it handled the crisis. It held daily press conferences and webcasts, and set up a temporary website in the first week to keep customers, staff and investors informed while its own systems were down.[1]
In October 2021, Europol announced that police had targeted 12 people in raids in Ukraine and Switzerland, suspected of belonging to a network behind ransomware attacks on more than 1,800 victims in 71 countries since 2019. Europol said the group used the same ransomware family in the Norsk Hydro attack. The announcement described raids and seizures, not convictions.[2]
What it cost
Estimates of the damage were large. One report put the cost at more than $50 million, and a later account by Microsoft put it at about $71 million.[1][2] Production was disrupted on 2 continents.[2]
Refusing to pay did not make the attack cheap, but it meant the company rebuilt clean. Norsk Hydro's own security staff later made the point that paying a ransom does not fix the problem, because you still have to rebuild to be safe.[1]
The missing control
The missing control: multi-factor authentication on privileged accounts, paired with disciplined patching and updates. These were among the fixes Norsk Hydro itself put in place after the attack.[1]
The phishing email only opened a small door. What turned it into a company-wide shutdown was the attackers' ability to take over admin accounts and use them freely. Requiring a second sign-in step for admin access makes stolen passwords far less useful, and keeping systems updated removes many of the weak spots attackers use to climb from one ordinary computer to full control. Backups that the attackers could not reach are what let the company recover without paying.[1]
What to do in your business
- Require two-factor for admin accounts. Anyone who can manage your network, email system or cloud accounts should need a second step at every sign-in.
- Keep admin and daily use separate. Staff with admin rights should use a normal account for email and browsing, and a separate admin account only when needed.
- Turn on automatic updates. Set computers, servers and key software to update on a schedule, and check monthly that it is really happening.
- Protect and test backups. Keep at least one backup offline or otherwise out of reach of your network logins, and practice restoring from it.
- Plan to work on paper. Write down how your business would take orders, pay staff and serve customers for a week with no computers. The companies that recover fastest planned for it.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.