TOMRA isolates systems after extensive cyberattack on Norwegian group
- Organization
- TOMRA Systems ASA
- Exploit
- Hacking
- Industry
- Industrial Technology
TOMRA Systems ASA, the Norwegian maker of reverse vending machines and sorting equipment for the recycling, food and mining sectors, disclosed on July 17, 2023 that it had been targeted by what it described as an extensive cyberattack detected the previous morning.
The company disconnected affected systems to contain the intrusion and said they would stay offline until it was safe to bring them back. Internal IT services and back office applications went down, office locations were taken offline and staff worked remotely. TOMRA Recycling and TOMRA Food ran with limited digital service functionality, and older reverse vending machines in Europe and Asia were affected while units in Australia and North America kept operating.
In a July 20 update, TOMRA said the intruder had compromised user accounts and obtained access that allowed movement between sites, with the activity linked to its Montreal location. The company reported no evidence that data had been encrypted and no evidence that its clients, customers or partners were at risk.
TOMRA engaged Deloitte's cyber response team, said it remained in contact with relevant authorities and migrated reverse vending machine services to a separate cloud platform so European machines could be reconnected. No group claimed responsibility and the company did not confirm any ransom demand.