Norsk Hydro ransomware attack forced aluminum plants onto manual operations
- Organization
- Norsk Hydro ASA
- Exploit
- Ransomware
- Industry
- Manufacturing
Norsk Hydro ASA, one of the world's largest aluminum producers, was hit by an extensive ransomware attack that struck overnight and was confirmed by the company on March 19, 2019.
The Norwegian group said IT systems in most of its business areas were affected. It isolated plants in Europe and the United States to stop the malware spreading and switched to manual procedures wherever possible. Extruded Solutions and Rolled Products saw temporary stoppages at several plants because production systems could not connect, while primary metal plants, remelters and the bauxite, alumina and energy businesses kept producing with a much higher degree of manual operation. Hydro said no safety incidents resulted and that it had notified and was being supported by the relevant authorities.
Researchers identified the malware as LockerGoga, a strain first seen in January 2019 that encrypted files and locked users out of their accounts, which complicated recovery. It was deployed manually across victim networks, most likely using stolen domain administrator credentials and Microsoft Active Directory management tools. Norway's national security authority confirmed the attack.
Hydro declined to pay a ransom and rebuilt from backups. It held daily press conferences and published rolling status updates, an unusually open response that security practitioners praised at the time. In the immediate aftermath the company said it was too early to indicate the operational and financial impact.