Case file · NORSK HYDRO 2019

How the Norsk Hydro ransomware attack happened, and why the company refused to pay

Published 2026-09-29 · 4 min read · Missing control: MFA for admins and disciplined patching

When ransomware locked the computers of Norsk Hydro, one of the world's biggest aluminum makers, the company refused to pay, went back to pen and paper, and asked retired employees to come back and help run production by hand.[1] This case file covers how the attack got in months before anyone noticed, what it cost, and the controls the company put in place afterward.

What happened

In December 2018, an employee at Norsk Hydro opened an email attachment that appeared to come from a trusted customer. It quietly installed malicious software that gave outside attackers a foothold in the company's network.[1]

For roughly 3 months, the attackers worked their way in further and collected administrator logins. Then, in March 2019, they used those admin accounts to push ransomware across the company's systems at once. Thousands of servers and PCs were locked, affecting all 35,000 employees in 40 countries and 170 plants.[1]

Some plants switched to manual operation. Staff printed orders and tracked work on paper, and retirees who remembered how things were done before computers volunteered to help.[1] The company refused the ransom demand and chose to rebuild its systems and restore data from backups instead.[1]

How they got in

The first step was a trusted-looking email. Because it seemed to come from a real customer, it did not raise alarms, and one click was enough to give the attackers remote access.[1]

The damage came from what happened next. Over time, the attackers gained administrative credentials, the master keys that manage the whole network. With those, they could use the company's own central management systems to deliver ransomware to computers across the organization in one push.[1] The attackers never needed to break into each plant separately. One set of stolen admin powers reached everywhere.

How it was caught

The attack was impossible to miss once the ransomware ran, but the break-in itself had gone unnoticed for about 3 months.[1] Norsk Hydro brought in Microsoft's incident response team to help investigate and rebuild.[1]

The company also became known for how openly it handled the crisis. It held daily press conferences and webcasts, and set up a temporary website in the first week to keep customers, staff and investors informed while its own systems were down.[1]

In October 2021, Europol announced that police had targeted 12 people in raids in Ukraine and Switzerland, suspected of belonging to a network behind ransomware attacks on more than 1,800 victims in 71 countries since 2019. Europol said the group used the same ransomware family in the Norsk Hydro attack. The announcement described raids and seizures, not convictions.[2]

What it cost

Estimates of the damage were large. One report put the cost at more than $50 million, and a later account by Microsoft put it at about $71 million.[1][2] Production was disrupted on 2 continents.[2]

Refusing to pay did not make the attack cheap, but it meant the company rebuilt clean. Norsk Hydro's own security staff later made the point that paying a ransom does not fix the problem, because you still have to rebuild to be safe.[1]

The missing control

The missing control: multi-factor authentication on privileged accounts, paired with disciplined patching and updates. These were among the fixes Norsk Hydro itself put in place after the attack.[1]

The phishing email only opened a small door. What turned it into a company-wide shutdown was the attackers' ability to take over admin accounts and use them freely. Requiring a second sign-in step for admin access makes stolen passwords far less useful, and keeping systems updated removes many of the weak spots attackers use to climb from one ordinary computer to full control. Backups that the attackers could not reach are what let the company recover without paying.[1]

What to do in your business

Watch the case
Ransomware hit 170 sites, and Norsk Hydro refused to payDrops 2027-01-18
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Microsoft: Hackers hit Norsk Hydro with ransomware. The company responded with transparency
  2. TechCrunch: Europol targets hackers behind Norsk Hydro ransomware attack