{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-norsk-hydro-lockergoga-attack-traced-to-weaponised-email-from-a-trusted"},"incident":{"title":"Norsk Hydro LockerGoga attack traced to weaponised email from a trusted customer","date":"2019-03-19","date_precision":"day","victim_org":"Norsk Hydro ASA","sector":"Manufacturing","country":"Norway","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption"],"loss_usd":71000000,"loss_note":"Microsoft's account of the incident states the financial impact would eventually approach $71 million; Hydro's own quarterly disclosures gave figures in a similar range and the company was partly insured.","records_affected":null,"threat_actor":"LockerGoga operators","summary":"Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware on 19 March 2019, encrypting thousands of servers and PCs and forcing plants worldwide onto manual operation. Microsoft's account of the response states that in December 2018 attackers had weaponised an email attachment sent from a trusted customer's employee to a Hydro employee, installing a trojan roughly three months before the ransomware was launched. Hydro refused to pay and published unusually detailed updates throughout the recovery.","how_it_worked":"The attackers first compromised a customer's mailbox, then used that genuine business relationship to send a document attachment to a Hydro employee. Because the sender was a real, expected correspondent, the attachment was opened and installed a trojan. Over the following months the intruders escalated into Active Directory, obtained domain-level control and then pushed LockerGoga across the estate, which encrypted files and, in some variants, changed local account passwords and logged users out. Hydro's 35,000 employees across 40 countries lost access to IT systems; some smelters ran on paper procedures for weeks.","lessons":"Attachments from known senders still need detonation and macro controls, and tiered Active Directory administration prevents a single infected desktop from becoming domain-wide ransomware deployment.","confidence":"Reported","sources":[{"title":"Hackers hit Norsk Hydro with ransomware. The company responded with transparency","url":"https://news.microsoft.com/source/features/digital-transformation/hackers-hit-norsk-hydro-ransomware-company-responded-transparency/","publisher":"Microsoft Source"},{"title":"Norsk Hydro responds to ransomware attack with transparency","url":"https://www.microsoft.com/en-us/security/blog/2019/12/17/norsk-hydro-ransomware-attack-transparency/","publisher":"Microsoft Security Blog"},{"title":"Hydro Hit by LockerGoga Ransomware via Active Directory","url":"https://www.bankinfosecurity.com/hydro-hit-by-lockergoga-ransomware-via-active-directory-a-12207","publisher":"BankInfoSecurity"}],"entry_type":"incident","slug":"2019-norsk-hydro-lockergoga-attack-traced-to-weaponised-email-from-a-trusted","year":2019,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-norsk-hydro-lockergoga-attack-traced-to-weaponised-email-from-a-trusted"}}