For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/attacks.md.
Threat landscape

Attacks in Norway

Overview of publicly known cyberattacks against Norwegian organisations, based on open sources.

Registered incidents

62


+33 in 2026, across 11 quarters

Latest quarter

20

+150%
vs previous quarter

Most affected sector

Public sector

16 of 62 cases

Most common type

DDoS


Share of all cases 23%

2024 Q1 to 2026 Q3. 2026 Q3 is still running, 20 so far. These are the incidents this overview has registered, not a national total.

Each entry is grounded in open sources: NSM bulletins, established media coverage, and the affected organisations' own disclosures. FM CyberSecurity does not publish confidential information from client engagements.

Date Target Sector Type Source
Ikke navngitt selskap i kritisk infrastruktur (E-tjenesten)

The Norwegian Intelligence Service said a state actor had full access to the admin systems of a Norwegian critical-infrastructure company for a long period. The company never noticed.

Multiple sectors (kritisk infrastruktur) State operation (avdekket ved tilrettelagt innhenting) VG +1
Norsk digital infrastruktur (brukt som mellomledd mot Ukraina)

The Norwegian Intelligence Service said state actors have run cyber operations against Ukrainian targets through Norwegian digital infrastructure to hide where the attacks came from.

IT and technology (ekom) → Telecom State operation (Norge brukt som transitt) VG +1
Lazy Boyz AS Confirmed

Akira listed Oslo dealer Lazy Boyz (Harley-Davidson, Royal Enfield) on its leak site on 15 September, threatening to publish staff data, financials and contracts. The company confirmed the attack.

Services and retail (motorsykkelforhandler) Ransomware (hevder ansvar) Akira Lazy Boyz AS (Facebook) +2
Stortinget

Stortinget.no became unstable around 15:00 on Monday 14 September and was back to normal by 16:23. Server Killers announced the attack on Telegram. Feide was hit the same day.

Public sector (nasjonalforsamling) DDoS (hevder ansvar) Server Killers VG +2
Easee AS

An attacker had access to Easee's CFO mailbox from 7 May to 11 June. Staff ID numbers, salary, bank and health data plus the shareholder register may have been read. Found via invoice fraud.

Industry (elbilladere) → Energy Phishing / BEC (kompromittert e-postkonto, fakturasvindel) NRK Rogaland
Norsk Tipping AS Confirmed

Norsk Tipping hit by a DDoS attack at 19:00 on Wednesday 9 September, causing login problems. A second traffic surge came Thursday morning; systems were back up Thursday afternoon. Actor unknown.

Gaming and entertainment (statseid) DDoS VG +4
Fremskrittspartiets Ungdom (FpU) Confirmed

FpU's website was hacked on Monday 7 September and its content altered. Traffic was temporarily redirected to frp.no while the incident was investigated. No actor identified.

Civil society Defacement VG +1
Utlendingsdirektoratet (UDI) Confirmed

UDI websites went down on Friday 4 September. Server Killers claimed responsibility; UDI says internal systems were unaffected. Part of a wave against Norwegian public services.

Public sector (statlig etat) DDoS (hevder ansvar) Server Killers Digi.no +2
Dustin Norge (Dustin Group) Confirmed

Dustin shut its web shops in six countries on 3 September. FulcrumSec published 6.2 TB of source code and a register of 1M+ accounts on 14 September, naming Nav and Statnett among the customers.

IT and technology (IT-forhandler) Data breach (med utpressing) FulcrumSec Kode24 +6
Akershus universitetssykehus (Ahus) – Kompetansebroen Confirmed

Intruders gained admin rights in Ahus' Kompetansebroen portal. Data on some 100,000 users may be exposed, and about 50 patient-submitted messages were found in the system. Datatilsynet notified.

Health Data breach Kompetansebroen (Ahus) +3
Sikt og universitets- og høgskolesektoren (Feide m.fl.) Confirmed

DDoS on the higher-education sector on 2 and 4 September took down Feide and sites at UiO, NTNU, OsloMet and others. Feide was hit again on 14 September. Server Killers claimed it.

Education (UH-sektoren) DDoS (hevder ansvar) Server Killers Sikt (driftsmelding) +8
Sikt – Kunnskapssektorens tjenesteleverandør (Feide, Educloud, Samordna opptak, UiO) Confirmed

DDoS against Sikt on Saturday 29 August left Feide, Educloud, Samordna opptak, fsweb and UiO intermittently unavailable. Server Killers claimed it; no sign of research data exposure.

Education (UH-sektoren) DDoS (hevder ansvar) Server Killers Sikt (driftsmelding) +3
Digitaliseringsdirektoratet (Digdir) via Vivicta Confirmed

DDoS on hosting partner Vivicta from 03:38 on 24 August took down ID-porten, MinID, Altinn and Maskinporten. It ran for over three days; Digdir declared services healthy on 27 August.

Public sector (kritisk infrastruktur) DDoS (hevder ansvar) Server Killers Digdir (statusside) +10
Cars Software AS

A Russian hacker group claims names and phone numbers of 160,000+ Cars Software customers were taken, allegedly from a 10-year-old backup. Police, Datatilsynet and Telenor Cyberdefence involved.

IT and technology (programvarehus) Data breach Digi.no +2
Studentsamskipnaden i Gjøvik, Ålesund og Trondheim (Sit) Confirmed

System provider notified Sit on 14 August that outsiders may have accessed its customer database. Up to 780 students affected; names, emails, national ID numbers, addresses. Likely SMS pumping.

Education Data breach Sit (pressemelding) +3
Document.no Confirmed

Intrusion into the publishing system overnight into 7 August. Attackers claimed subscriber logs and plaintext passwords and said they were Anonymous. Document doubts that claim.

Media (nettavis) Data breach (innbrudd i publiseringssystem) VG +1
Digitaliseringsdirektoratet (Digdir) Confirmed

DDoS on hosting partner Vivicta the night of 3 August took down ID-porten, MinID, Altinn and several health services. Normal operations restored 4 August. No indication of a data breach.

Public sector (kritisk infrastruktur) DDoS Digdir (egen statusmelding) +3
Norsk Tipping AS

Three DDoS attacks in one week (2, 4 and 7 August) took Oddsen and the websites down for periods. Telenor filtered the traffic and all incidents were reported to police. No data theft.

Gaming and entertainment (statseid) DDoS NRK Innlandet +2
Ryde Technology AS Confirmed

Unauthorized access the night of 2 August exposed 4.5 million accounts, 1.6 million in Norway. On 18 August the data was offered for sale on a criminal forum. Datatilsynet notified.

Transport (mobilitet) Data breach (dataeksfiltrering) Ryde (egen redegjørelse) +3
Nedre Romerike vann- og avløpsselskap (NRVA) Confirmed

Maps of the water and sewage network, risk assessments and contingency plans covering 180,000 residents leaked after the Lørenskog attack. Operations and water quality unaffected.

Public sector (vann og avløp) Data leak (via angrepet på Lørenskog kommune) Digi.no +1
Alpha IT (IT-leverandør, Trondheim) Confirmed

Data from Trondheim IT provider Alpha IT was published on the dark web, with real-estate firm Ragde Eiendom among named customers. Up to 15 companies affected. PST passed the case to Kripos.

IT and technology (IT-leverandør) Data breach (via leverandørkjeden) Digi.no +4
Digitaliseringsdirektoratet (Digdir) via Vivicta Confirmed

DDoS on hosting partner Vivicta from Saturday 20 June until Sunday morning made several of Digdir's shared services unavailable. The same partner was hit again on 3 August.

Public sector (kritisk infrastruktur) DDoS Digi.no +1
Norsk Tjenestemannslag (NTL) Confirmed

Norwegian union NTL (LO, 59,000+ members) hit by ransomware on 16 June; central IT systems taken offline. Sensitive personal data may be compromised. Datatilsynet and NSM notified.

Civil society (fagforening) Ransomware (mulig datatyveri) NTL (pressemelding via NTB) +2
Norsk Tipping AS Confirmed

Norsk Tipping hit by DDoS three times in one week (2, 3 and 5 June). Games and websites slowed/unavailable; Telenor filtered the traffic each time. No data theft indicated; perpetrator unknown.

Gaming and entertainment (statseid) DDoS VG +7
Gran kommune (innsynssak-lekkasje) Confirmed

Gran municipality leaked personal data on 27 residents, mainly national ID numbers, due to flawed manual FOIA handling. 18 cases affected. Discovered when a new scanning tool was deployed.

Public sector (kommune) Data leak (feil i håndtering av innsynssaker) NRK Innlandet
Lørenskog kommune Confirmed

Ransomware found 9 May; attacker got in 7 April via an infected download. A Deloitte review in September found a 26-day gap between the first alert and action taken. 1.8 TB was published in July.

Public sector (kommune) Ransomware (inngang via infisert nedlasting) Lørenskog kommune +13
Fredrikstad og Hvaler kommune Confirmed

Fredrikstad and Hvaler municipalities had directory data on ~7,000 employees posted on a criminal forum 2 May. Employee search function abused to expose names, emails, phone numbers.

Public sector (kommune) Data leak (misbrukt Ansattsøk-funksjon) Fredrikstad kommune +2
Instructure (Canvas) og 37 norske utdanningsinstitusjoner Confirmed

Canvas vendor Instructure leaked 3.65 TB. 37 Norwegian institutions affected including UiO, NTNU, OsloMet, NMBU, Innlandet, USN. ShinyHunters behind it. Ransom paid 11 May.

Education Data leak (med utpressing) ShinyHunters VG +5
Sats Norge (Sats ASA) Confirmed

Sats Norway hit by data breach 14 March. 3,750 current and former employees affected via file server with HR and accounting data. Membership system not affected. Criminal group threatened to leak.

Services and retail (treningskjede) Data breach (med utpressing) SATS ASA +10
Den kulturelle skolesekken (DKS) / Kulturtanken Confirmed

DKS portal data leak via vendor Netpower. Anonymous actor claims 1.39M rows stolen with names, addresses, emails and messages on performers, planners and school staff. No pupil data.

Public sector (kultur) Data leak (via leverandøren Netpower) Kulturtanken / DKS +4
Wilhelmsen Ship Management (skip-system) Confirmed

Crypto virus on selected onboard PCs of a vessel operated by Wilhelmsen Ship Management on 18 February. No land based systems affected. Lockbit 5.0 claimed responsibility via leak site.

Transport (skipsfart) Ransomware (hevder ansvar) LockBit 5.0 Techwatch +2
Ikke navngitte norske virksomheter (Salt Typhoon) Confirmed

In its 2026 national threat assessment, PST disclosed that Chinese actor Salt Typhoon compromised vulnerable network devices at Norwegian organisations. Victims were not named.

Multiple sectors State operation (sårbare nettverksenheter) Salt Typhoon PST (Nasjonal trusselvurdering 2026) +1
Telia Norge AS Confirmed

Breach found November 2025; Payoutsking published 2.5 TB in February. Around 500,000 private customers, 3,000 business customers and staff in 17 municipalities hit. Kripos is investigating.

Telecom (mobil og bredbånd) Data leak (publisert på dark web) Payoutsking Telia Norge +10
31 norske advokatfirmaer (samlerapport) Confirmed

AdvokatWatch reported that 31 Norwegian law firms were affected by digital security breaches in 2025, tied to NSR warnings about Microsoft 365 account compromises.

Legal services (finans) Data breach (phishing mot Microsoft 365) AdvokatWatch +1
Lyd & Bilde Confirmed

Lyd & Bilde's websites compromised with a fake reCAPTCHA/ClickFix popup trying to trick visitors into running malicious PowerShell scripts. Both Norwegian and Swedish editions hit.

Media (fagblad) Phishing / BEC (ClickFix) Digi.no
Enea (leverandør til Ice og Telia)

Criminals threatened to leak 79 GB from Swedish supplier Enea, which sells software to mobile operators worldwide. Ice confirmed it was affected and Telia was assessing the consequences.

IT and technology (telekomprogramvare) → Telecom Data breach (via leverandørkjeden) INC Ransom Digi.no +1
Statsforvalteren i Innlandet m.fl. (6 statsforvaltere) Confirmed

Six county governor offices issued FOIA PDFs with unredacted national ID numbers and names in metadata. At least 150 people affected in Innlandet. Datatilsynet notified.

Public sector (statsforvaltere) Data leak (PDF-metadata med usladdet personinfo) Digi.no +3
Flere norske bedrifter (SonicWall SSL VPN-kampanje) Confirmed

Kripos warned in Jan 2026 that several Norwegian SMBs were hit by ransomware via old SonicOS SSL VPN bug. First known incident in Nov 2025. Akira suspected. Victims unnamed.

Multiple sectors (SMB) Ransomware (via SonicOS-sårbarhet) Akira (mistanke) Politiet (Kripos) +1
Veterinærinstituttet Confirmed

Unknown intruders accessed the Norwegian Veterinary Institute's computer systems. The case was reported to police. Security chief could not determine the cause.

Public sector (forskning) Data breach (inngangsvektor uavklart) Nationen
Helsenorge (Norsk helsenett SF) Confirmed

Technical fault on Helsenorge briefly exposed other patients' national ID numbers and names for about 50 minutes. Not external hacking. Norsk helsenett notified Datatilsynet.

Health Privacy incident (teknisk feil) VG +1
Dynamic Precision Norge AS (Kjeller) Confirmed

Dynamic Precision in Kjeller, a Norwegian PCB manufacturer supplying defense and aerospace, hit by a data breach involving server encryption (ransomware).

Industry (elektronikk, forsvarsleverandør) Ransomware Digi.no
Lovdata Confirmed

Lovdata's websites suffered DDoS over several days in September. Attackers attempted to overload the systems to make the site unavailable. User data not targeted.

Public sector (lovdatabase) → Legal services DDoS Digi.no +4
Høyre (politisk parti) Confirmed

The Conservative Party's websites hit by DDoS in final week of the parliamentary election campaign. NSM and the party attributed it to pro-Russian NoName057(16).

Civil society (politikk) DDoS NoName057(16) VG/DN +3
Ringerike + flere kommuner og Østfold fylkeskommune Confirmed

Ringerike and several Norwegian municipalities plus Østfold county council had websites hit by DDoS. Pro-Russian NoName057(16) claimed responsibility, motivated by the election.

Public sector (kommune og fylkeskommune) DDoS NoName057(16) NRK Buskerud +2
Ikke navngitt selskap på Østlandet (PST-bekreftet) Confirmed

PST confirmed a new data breach in Eastern Norway by the same pro-Russian group as the Bremanger dam. Physical processes affected without danger. Victim not publicly named.

Industry OT attack (datainnbrudd med OT-påvirkning, prorussisk hacktivisme) Aftenposten +2
Extend AS + Bergen/Drammen/Kristiansand/Ringsaker kommuner + NTNU Confirmed

Trondheim software vendor Extend AS hit by ransomware. Four municipalities (Bergen, Drammen, Kristiansand, Ringsaker) and NTNU (~77,500 emails in test env) had data compromised via EQS.

IT and technology (IT-leverandør) → Public sector, Education Ransomware (via leverandørkjeden) Digi.no +4
Narvik havn Confirmed

Hackers encrypted two servers and exfiltrated ~10 GB from Narvik port, a NATO-strategic logistics hub. A previously unknown group published the data. Kripos and NSM notified.

Transport (havn, NATO-strategisk) Ransomware Digi.no +4
Risevatnet-demningen, Bremanger (Breivika Eiendom) Confirmed

Pro-Russian hackers opened a valve at the Risevatnet dam in Bremanger, releasing 500 L/s for nearly 4 hours. PST attributed in August to a pro-Russian group via weak password.

Energy (vannkraft) OT attack (prorussisk hacktivisme) Aftenposten +2
Logistikkfirma på Skjetten (ikke navngitt) Confirmed

Freight and logistics firm in Skjetten near Lillestrøm hit by ransomware. Company (~30 employees, ~NOK 100M revenue) had to wipe its own servers to recover. Identity withheld.

Transport (logistikk) Ransomware Digi.no
Genus AS (leverandør til politiet) Confirmed

Genus, no-code platform vendor to the Norwegian police, hit by ransomware in January. Several GB of sensitive data incl. customer contracts with national ID numbers leaked on the dark web.

IT and technology (no-code-plattform) Ransomware (med datatyveri) Digi.no +1
Unacast / Gravy Analytics (norsk-amerikansk) Confirmed

Location data broker Unacast/Gravy Analytics hacked. About 146,000 Norwegian mobile devices likely affected; movement data leaked on a Russian hacker forum. Datatilsynet notified.

IT and technology (lokasjonsdata-megler) Data leak (åpen AWS-skylagring) NRK Østfold +3
Gran kommune Confirmed

Gran municipality detected an intrusion on 17 December. Attackers had a foothold on an unpatched server and installed VNC, stopped before ransomware deployment. No known exfiltration.

Public sector (kommune) Data breach (ransomware-forsøk, stanset) NRK Innlandet +5
Tensio (nettselskap) Confirmed

Personal data on Tensio employees (incl. national ID numbers and salaries) was inadvertently made public on an external site by a partner during a pension tender. Datatilsynet notified.

Energy (nettselskap) Data leak (feilpublisering hos partner) Tensio
Hå Rugeri AS (Nortura-datter) Confirmed

Attackers took over the CEO's email at Hå Rugeri and sent a fake invoice to a supplier who paid EUR 73,686 (~NOK 868,000) to the wrong account. Reported to Datatilsynet and police.

Industry (landbruk) Phishing / BEC (CEO-svindel) Digi.no +2
Nordea Norge Confirmed

Nordea was hit by a wave of denial-of-service attacks from mid-September 2024. One ran for about 25 days and gave Norwegian customers trouble with online and mobile banking. No data taken.

Finance (bank) DDoS Nordea (egen melding) +2
ISAR Aerospace Norge AS (Andøya) Confirmed

Norwegian police investigated a suspected data breach at ISAR Aerospace Norge on Andøya. A Hungarian former employee was arrested for downloading company data to an external drive.

Industry (forsvar og romfart) Insider threat (datatyveri) Digi.no +2
Skanlog (Vinmonopolet rammet på forsyning) Confirmed

Logistics firm Skanlog hit by LockBit 3.0 ransomware on 21 April. Deliveries to Vinmonopolet halted. Skanlog represented ~20% of Vinmonopolet's volume.

Transport (logistikk) → Services and retail Ransomware LockBit 3.0 TV 2 +3
Avarn Security AS Confirmed

Avarn Security AS confirmed it was hit by ransomware on 22 February 2024. IT teams worked to contain damage and restore operations; customers were notified.

Services and retail (sikkerhetstjenester) Ransomware NRK +1
APT28 / Fancy Bear router-operasjon (norske TP-Link-rutere som proxy) Confirmed

PST, FBI and partners disrupted a Russian APT28 router botnet using vulnerable TP-Link devices as relays. About ten compromised routers in Norway were identified and patched.

Telecom (forbrukerrutere) State operation (rutere brukt som proxy) VG +1
Sør-Varanger kommune Confirmed

Police notified Sør-Varanger that login credentials had been resold on the dark web for $10. The attack was stopped in early reconnaissance with help from Atea.

Public sector (kommune) Data breach (rekognosering, stanset) Sør-Varanger kommune +1
Norske Boligbyggelag (NBBL) Confirmed

NBBL trade body and subsidiaries (incl. insurance arms) hit by ransomware. NBBL refused to pay ransom. Reported to Datatilsynet and police.

Finance (bolig) Ransomware NBBL +4
Tietoevry (Moelven Industrier ASA rammet i Norge) Confirmed

Akira ransomware hit a Tietoevry data center in Sweden on the night of 20 January. Norwegian customers including Moelven Industrier were indirectly impacted via shared services.

IT and technology (driftsleverandør) Ransomware Akira Digi.no +3

Have corrections or additional sources? Email [email protected].

Questions or inquiry? [email protected] Contact us →