{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:18:38.348Z","total":2,"returned":2,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Norsk Hydro LockerGoga attack traced to weaponised email from a trusted customer","date":"2019-03-19","date_precision":"day","victim_org":"Norsk Hydro ASA","sector":"Manufacturing","country":"Norway","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption"],"loss_usd":71000000,"loss_note":"Microsoft's account of the incident states the financial impact would eventually approach $71 million; Hydro's own quarterly disclosures gave figures in a similar range and the company was partly insured.","records_affected":null,"threat_actor":"LockerGoga operators","summary":"Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware on 19 March 2019, encrypting thousands of servers and PCs and forcing plants worldwide onto manual operation. Microsoft's account of the response states that in December 2018 attackers had weaponised an email attachment sent from a trusted customer's employee to a Hydro employee, installing a trojan roughly three months before the ransomware was launched. Hydro refused to pay and published unusually detailed updates throughout the recovery.","how_it_worked":"The attackers first compromised a customer's mailbox, then used that genuine business relationship to send a document attachment to a Hydro employee. Because the sender was a real, expected correspondent, the attachment was opened and installed a trojan. Over the following months the intruders escalated into Active Directory, obtained domain-level control and then pushed LockerGoga across the estate, which encrypted files and, in some variants, changed local account passwords and logged users out. Hydro's 35,000 employees across 40 countries lost access to IT systems; some smelters ran on paper procedures for weeks.","lessons":"Attachments from known senders still need detonation and macro controls, and tiered Active Directory administration prevents a single infected desktop from becoming domain-wide ransomware deployment.","confidence":"Reported","sources":[{"title":"Hackers hit Norsk Hydro with ransomware. The company responded with transparency","url":"https://news.microsoft.com/source/features/digital-transformation/hackers-hit-norsk-hydro-ransomware-company-responded-transparency/","publisher":"Microsoft Source"},{"title":"Norsk Hydro responds to ransomware attack with transparency","url":"https://www.microsoft.com/en-us/security/blog/2019/12/17/norsk-hydro-ransomware-attack-transparency/","publisher":"Microsoft Security Blog"},{"title":"Hydro Hit by LockerGoga Ransomware via Active Directory","url":"https://www.bankinfosecurity.com/hydro-hit-by-lockergoga-ransomware-via-active-directory-a-12207","publisher":"BankInfoSecurity"}],"entry_type":"incident","slug":"2019-norsk-hydro-lockergoga-attack-traced-to-weaponised-email-from-a-trusted","year":2019,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-norsk-hydro-lockergoga-attack-traced-to-weaponised-email-from-a-trusted"},{"title":"Garmin outage from WastedLocker ransomware; initial lure never publicly confirmed","date":"2020-07-23","date_precision":"day","victim_org":"Garmin Ltd.","sector":"Technology","country":"United States","primary_vector":"Watering Hole / Malvertising","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption","Extortion"],"loss_usd":null,"loss_note":"Garmin never confirmed a ransom payment or a loss figure; press reporting of a multimillion-dollar payment is unverified.","records_affected":null,"threat_actor":"Evil Corp (WastedLocker operators)","summary":"Garmin suffered a multi-day global outage beginning 23 July 2020 that took down Garmin Connect, flyGarmin and customer support; the company later confirmed it was a ransomware attack, identified by researchers as WastedLocker. Garmin has never disclosed how the attackers got in. WastedLocker campaigns by Evil Corp were documented by multiple vendors as being delivered through the SocGholish fake browser-update framework on compromised websites, which is a deception-based lure, but that vector has not been confirmed for Garmin specifically.","how_it_worked":"In the WastedLocker campaigns of 2020 as documented by researchers, users browsing legitimate but compromised news and business websites were served a fake browser or Flash update overlay. Accepting the prompt downloaded a JavaScript-based loader, after which operators escalated privileges, moved laterally with Cobalt Strike and PowerShell, disabled security tooling and deployed WastedLocker across servers. For Garmin, only the ransomware family and the operational impact were publicly established; the entry point was never disclosed by the company or by law enforcement, so the human-deception element in this specific case is inferred from the campaign pattern rather than confirmed.","lessons":"Blocking user-initiated software updates from browser prompts and enforcing application control on workstations removes the fake-update lure that this ransomware family relied on.","confidence":"Alleged","sources":[{"title":"Garmin outage caused by confirmed WastedLocker ransomware attack","url":"https://www.bleepingcomputer.com/news/security/garmin-outage-caused-by-confirmed-wastedlocker-ransomware-attack/","publisher":"BleepingComputer"},{"title":"WastedLocker explained: How this targeted ransomware extorts millions from victims","url":"https://www.csoonline.com/article/569859/wastedlocker-explained-how-this-targeted-ransomware-extorts-millions-from-victims.html","publisher":"CSO Online"},{"title":"LockerGoga and WastedLocker ransomware insight","url":"https://www.recordedfuture.com/blog/lockergoga-ransomware-insight","publisher":"Recorded Future"}],"entry_type":"incident","slug":"2020-garmin-outage-from-wastedlocker-ransomware-initial-lure-never-publicly-c","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-garmin-outage-from-wastedlocker-ransomware-initial-lure-never-publicly-c"}]}