Skip to content
NetarxImpact Database
Vendor / Supply Chain ImpersonationNo AI reportedReported

Norsk Hydro LockerGoga attack traced to weaponised email from a trusted customer

Norsk Hydro ASA · Manufacturing · Norway · March 19, 2019

Business impact
$71,000,000
Lost revenue, earnings impact, remediation cost, a settlement or damages sought. Not money stolen.
Microsoft's account of the incident states the financial impact would eventually approach $71 million; Hydro's own quarterly disclosures gave figures in a similar range and the company was partly insured.

What happened

Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware on 19 March 2019, encrypting thousands of servers and PCs and forcing plants worldwide onto manual operation. Microsoft's account of the response states that in December 2018 attackers had weaponised an email attachment sent from a trusted customer's employee to a Hydro employee, installing a trojan roughly three months before the ransomware was launched. Hydro refused to pay and published unusually detailed updates throughout the recovery.

How the deception worked

The attackers first compromised a customer's mailbox, then used that genuine business relationship to send a document attachment to a Hydro employee. Because the sender was a real, expected correspondent, the attachment was opened and installed a trojan. Over the following months the intruders escalated into Active Directory, obtained domain-level control and then pushed LockerGoga across the estate, which encrypted files and, in some variants, changed local account passwords and logged users out. Hydro's 35,000 employees across 40 countries lost access to IT systems; some smelters ran on paper procedures for weeks.

AI involvement · No AI reported

No AI element reported.

The control that would have caught it· our reading, not a claim from the sources

Attachments from known senders still need detonation and macro controls, and tiered Active Directory administration prevents a single infected desktop from becoming domain-wide ransomware deployment.

Sources (3)

  1. Hackers hit Norsk Hydro with ransomware. The company responded with transparency
    Microsoft Source·news.microsoft.comOpen ↗
  2. Norsk Hydro responds to ransomware attack with transparency
    Microsoft Security Blog·microsoft.comOpen ↗
  3. Hydro Hit by LockerGoga Ransomware via Active Directory
    BankInfoSecurity·bankinfosecurity.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.