Attacks in Norway
Overview of publicly known cyberattacks against Norwegian organisations, based on open sources.
Each entry is grounded in open sources — NSM bulletins, established media coverage, and the affected organisations' own disclosures. FM does not publish confidential information from client engagements.
| Date | Target | Sector | Type | Source |
|---|---|---|---|---|
| Lørenskog kommuneConfirmed Lørenskog municipality hit by serious cyberattack on Saturday 9 May. Schools, NAV and nursing homes lost access to core IT systems. Attacker left a ransom note. Kripos investigating. | Offentlig sektor (kommune) | Dataangrep med pengekrav | Lørenskog kommune +5 | |
| Fredrikstad og Hvaler kommuneConfirmed Fredrikstad and Hvaler municipalities had directory data on ~7,000 employees posted on a criminal forum 2 May. Employee search function abused to expose names, emails, phone numbers. | Offentlig sektor (kommune) | Datalekkasje via misbrukt Ansattsøk-funksjon | Fredrikstad kommune +2 | |
| Instructure (Canvas) og 37 norske utdanningsinstitusjonerConfirmed Canvas vendor Instructure leaked 3.65 TB. 37 Norwegian institutions affected including UiO, NTNU, OsloMet, NMBU, Innlandet, USN. ShinyHunters behind it. Ransom paid 11 May. | Utdanning | Datalekkasje og utpressing (ShinyHunters) | VG +5 | |
| Sats Norge (Sats ASA)Confirmed Sats Norway hit by data breach 14 March. 3,750 current and former employees affected via file server with HR and accounting data. Membership system not affected. Criminal group threatened to leak. | Trening / Handel og tjenester | Datainnbrudd med utpressing | SATS ASA +9 | |
| Wilhelmsen Ship Management (skip-system)Confirmed Crypto virus on selected onboard PCs of a vessel operated by Wilhelmsen Ship Management on 18 February. No land based systems affected. Lockbit 5.0 claimed responsibility via leak site. | Skipsfart / Transport | Ransomware (Lockbit 5.0 hevder ansvar) | Techwatch +2 | |
| 31 norske advokatfirmaer (samlerapport)Confirmed AdvokatWatch reported that 31 Norwegian law firms were affected by digital security breaches in 2025, tied to NSR warnings about Microsoft 365 account compromises. | Juridiske tjenester / Finans | Datainnbrudd / phishing (Microsoft 365) | AdvokatWatch +1 | |
| Lyd & BildeConfirmed Lyd & Bilde's websites compromised with a fake reCAPTCHA/ClickFix popup trying to trick visitors into running malicious PowerShell scripts. Both Norwegian and Swedish editions hit. | Media (norsk fagblad/nettsted) | ClickFix social engineering | Digi.no | |
| Statsforvalteren i Innlandet m.fl. (6 statsforvaltere)Confirmed Six county governor offices issued FOIA PDFs with unredacted national ID numbers and names in metadata. At least 150 people affected in Innlandet. Datatilsynet notified. | Offentlig sektor (statsforvaltere) | Datalekkasje (PDF-metadata, usladdet personinfo) | Digi.no +3 | |
| Flere norske bedrifter (SonicWall SSL VPN-kampanje)Confirmed Kripos warned in Jan 2026 that several Norwegian SMBs were hit by ransomware via old SonicOS SSL VPN bug. First known incident in Nov 2025. Akira suspected. Victims unnamed. | Flere bransjer (SMB) | Ransomware (Akira-mistanke) via SonicOS-sårbarhet | Politiet (Kripos) +1 | |
| VeterinærinstituttetConfirmed Unknown intruders accessed the Norwegian Veterinary Institute's computer systems. The case was reported to police. Security chief could not determine the cause. | Offentlig sektor / Forskning | Datainnbrudd (inngangsvektor uavklart) | Nationen | |
| Helsenorge (Norsk helsenett SF)Confirmed Technical fault on Helsenorge briefly exposed other patients' national ID numbers and names for about 50 minutes. Not external hacking. Norsk helsenett notified Datatilsynet. | Helse | Personvernhendelse / teknisk feil | VG +1 | |
| Dynamic Precision Norge AS (Kjeller)Confirmed Dynamic Precision in Kjeller, a Norwegian PCB manufacturer supplying defense and aerospace, hit by a data breach involving server encryption (ransomware). | Industri / Elektronikk (forsvarsleverandør) | Ransomware | Digi.no | |
| LovdataConfirmed Lovdata's websites suffered DDoS over several days in September. Attackers attempted to overload the systems to make the site unavailable. User data not targeted. | Offentlig / Juridisk (lovdatabase) | DDoS | Digi.no +4 | |
| Høyre (politisk parti)Confirmed The Conservative Party's websites hit by DDoS in final week of the parliamentary election campaign. NSM and the party attributed it to pro-Russian NoName057(16). | Politikk / Sivilsamfunn | DDoS (NoName057(16)) | VG/DN +3 | |
| Ringerike + flere kommuner og Østfold fylkeskommuneConfirmed Ringerike and several Norwegian municipalities plus Østfold county council had websites hit by DDoS. Pro-Russian NoName057(16) claimed responsibility, motivated by the election. | Offentlig sektor (kommune/fylkeskommune) | DDoS (NoName057(16)) | NRK Buskerud +2 | |
| Ikke navngitt selskap på Østlandet (PST-bekreftet)Confirmed PST confirmed a new data breach in Eastern Norway by the same pro-Russian group as the Bremanger dam. Physical processes affected without danger. Victim not publicly named. | Industri (uspesifisert) | Datainnbrudd / OT-påvirkning (prorussisk hacktivisme) | Aftenposten +2 | |
| Extend AS + Bergen/Drammen/Kristiansand/Ringsaker kommuner + NTNUConfirmed Trondheim software vendor Extend AS hit by ransomware. Four municipalities (Bergen, Drammen, Kristiansand, Ringsaker) and NTNU (~77,500 emails in test env) had data compromised via EQS. | IT-leverandør → Offentlig sektor / Utdanning | Supply chain ransomware | Digi.no +4 | |
| Narvik havnConfirmed Hackers encrypted two servers and exfiltrated ~10 GB from Narvik port, a NATO-strategic logistics hub. A previously unknown group published the data. Kripos and NSM notified. | Transport / Havn (NATO-strategisk) | Ransomware / datainnbrudd | Digi.no +4 | |
| Risevatnet-demningen, Bremanger (Breivika Eiendom)Confirmed Pro-Russian hackers opened a valve at the Risevatnet dam in Bremanger, releasing 500 L/s for nearly 4 hours. PST attributed in August to a pro-Russian group via weak password. | Energi / Kritisk infrastruktur (vannkraft) | OT-angrep (prorussisk hacktivisme) | Aftenposten +2 | |
| Logistikkfirma på Skjetten (ikke navngitt)Confirmed Freight and logistics firm in Skjetten near Lillestrøm hit by ransomware. Company (~30 employees, ~NOK 100M revenue) had to wipe its own servers to recover. Identity withheld. | Transport / Logistikk | Ransomware | Digi.no | |
| Genus AS (leverandør til politiet)Confirmed Genus, no-code platform vendor to the Norwegian police, hit by ransomware in January. Several GB of sensitive data incl. customer contracts with national ID numbers leaked on the dark web. | IT/Tech (no-code-plattform) | Ransomware med datatyveri | Digi.no +1 | |
| Unacast / Gravy Analytics (norsk-amerikansk)Confirmed Location data broker Unacast/Gravy Analytics hacked. About 146,000 Norwegian mobile devices likely affected; movement data leaked on a Russian hacker forum. Datatilsynet notified. | IT/Tech (lokasjonsdata-megler) | Datalekkasje (AWS-skylagring) | NRK Østfold +3 | |
| Gran kommuneConfirmed Gran municipality detected an intrusion on 17 December. Attackers had a foothold on an unpatched server and installed VNC, stopped before ransomware deployment. No known exfiltration. | Offentlig sektor (kommune) | Datainnbrudd / ransomware-forsøk (stanset) | NRK Innlandet +5 | |
| Tensio (nettselskap)Confirmed Personal data on Tensio employees (incl. national ID numbers and salaries) was inadvertently made public on an external site by a partner during a pension tender. Datatilsynet notified. | Energi (nettselskap) | Datalekkasje (feilpublisering hos partner) | Tensio | |
| Hå Rugeri AS (Nortura-datter)Confirmed Attackers took over the CEO's email at Hå Rugeri and sent a fake invoice to a supplier who paid EUR 73,686 (~NOK 868,000) to the wrong account. Reported to Datatilsynet and police. | Industri / Landbruk | BEC / CEO-svindel | Digi.no +2 | |
| ISAR Aerospace Norge AS (Andøya)Confirmed Norwegian police investigated a suspected data breach at ISAR Aerospace Norge on Andøya. A Hungarian former employee was arrested for downloading company data to an external drive. | Industri / Forsvar (romfart) | Innsidetrussel / datatyveri | Digi.no +2 | |
| Skanlog (Vinmonopolet rammet på forsyning)Confirmed Logistics firm Skanlog hit by LockBit 3.0 ransomware on 21 April. Deliveries to Vinmonopolet halted. Skanlog represented ~20% of Vinmonopolet's volume. | Transport / Logistikk → Varehandel | Ransomware (LockBit 3.0) | TV 2 +3 | |
| Avarn Security ASConfirmed Avarn Security AS confirmed it was hit by ransomware on 22 February 2024. IT teams worked to contain damage and restore operations; customers were notified. | Sikkerhet / Tjenester | Ransomware | NRK +1 | |
| APT28 / Fancy Bear router-operasjon (norske TP-Link-rutere som proxy)Confirmed PST, FBI and partners disrupted a Russian APT28 router botnet using vulnerable TP-Link devices as relays. About ten compromised routers in Norway were identified and patched. | Telekom / Infrastruktur (forbrukerruter) | Statlig nettverksoperasjon (rutere brukt som proxy) | VG +1 | |
| Sør-Varanger kommuneConfirmed Police notified Sør-Varanger that login credentials had been resold on the dark web for $10. The attack was stopped in early reconnaissance with help from Atea. | Offentlig sektor (kommune) | Datainnbrudd (rekognosering, stanset) | Sør-Varanger kommune +1 | |
| Norske Boligbyggelag (NBBL)Confirmed NBBL trade body and subsidiaries (incl. insurance arms) hit by ransomware. NBBL refused to pay ransom. Reported to Datatilsynet and police. | Bolig / Finans | Ransomware | NBBL +4 | |
| Tietoevry (Moelven Industrier ASA rammet i Norge)Confirmed Akira ransomware hit a Tietoevry data center in Sweden on the night of 20 January. Norwegian customers including Moelven Industrier were indirectly impacted via shared services. | IT/Tech (driftsleverandør) | Ransomware (Akira) | Digi.no +3 |
Have corrections or additional sources? Email [email protected].