For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/attacks.md.
Threat landscape

Attacks in Norway

Overview of publicly known cyberattacks against Norwegian organisations, based on open sources.

Each entry is grounded in open sources — NSM bulletins, established media coverage, and the affected organisations' own disclosures. FM does not publish confidential information from client engagements.

DateTargetSectorTypeSource
Lørenskog kommuneConfirmed

Lørenskog municipality hit by serious cyberattack on Saturday 9 May. Schools, NAV and nursing homes lost access to core IT systems. Attacker left a ransom note. Kripos investigating.

Offentlig sektor (kommune)Dataangrep med pengekravLørenskog kommune +5
Fredrikstad og Hvaler kommuneConfirmed

Fredrikstad and Hvaler municipalities had directory data on ~7,000 employees posted on a criminal forum 2 May. Employee search function abused to expose names, emails, phone numbers.

Offentlig sektor (kommune)Datalekkasje via misbrukt Ansattsøk-funksjonFredrikstad kommune +2
Instructure (Canvas) og 37 norske utdanningsinstitusjonerConfirmed

Canvas vendor Instructure leaked 3.65 TB. 37 Norwegian institutions affected including UiO, NTNU, OsloMet, NMBU, Innlandet, USN. ShinyHunters behind it. Ransom paid 11 May.

UtdanningDatalekkasje og utpressing (ShinyHunters)VG +5
Sats Norge (Sats ASA)Confirmed

Sats Norway hit by data breach 14 March. 3,750 current and former employees affected via file server with HR and accounting data. Membership system not affected. Criminal group threatened to leak.

Trening / Handel og tjenesterDatainnbrudd med utpressingSATS ASA +9
Wilhelmsen Ship Management (skip-system)Confirmed

Crypto virus on selected onboard PCs of a vessel operated by Wilhelmsen Ship Management on 18 February. No land based systems affected. Lockbit 5.0 claimed responsibility via leak site.

Skipsfart / TransportRansomware (Lockbit 5.0 hevder ansvar)Techwatch +2
31 norske advokatfirmaer (samlerapport)Confirmed

AdvokatWatch reported that 31 Norwegian law firms were affected by digital security breaches in 2025, tied to NSR warnings about Microsoft 365 account compromises.

Juridiske tjenester / FinansDatainnbrudd / phishing (Microsoft 365)AdvokatWatch +1
Lyd & BildeConfirmed

Lyd & Bilde's websites compromised with a fake reCAPTCHA/ClickFix popup trying to trick visitors into running malicious PowerShell scripts. Both Norwegian and Swedish editions hit.

Media (norsk fagblad/nettsted)ClickFix social engineeringDigi.no
Statsforvalteren i Innlandet m.fl. (6 statsforvaltere)Confirmed

Six county governor offices issued FOIA PDFs with unredacted national ID numbers and names in metadata. At least 150 people affected in Innlandet. Datatilsynet notified.

Offentlig sektor (statsforvaltere)Datalekkasje (PDF-metadata, usladdet personinfo)Digi.no +3
Flere norske bedrifter (SonicWall SSL VPN-kampanje)Confirmed

Kripos warned in Jan 2026 that several Norwegian SMBs were hit by ransomware via old SonicOS SSL VPN bug. First known incident in Nov 2025. Akira suspected. Victims unnamed.

Flere bransjer (SMB)Ransomware (Akira-mistanke) via SonicOS-sårbarhetPolitiet (Kripos) +1
VeterinærinstituttetConfirmed

Unknown intruders accessed the Norwegian Veterinary Institute's computer systems. The case was reported to police. Security chief could not determine the cause.

Offentlig sektor / ForskningDatainnbrudd (inngangsvektor uavklart)Nationen
Helsenorge (Norsk helsenett SF)Confirmed

Technical fault on Helsenorge briefly exposed other patients' national ID numbers and names for about 50 minutes. Not external hacking. Norsk helsenett notified Datatilsynet.

HelsePersonvernhendelse / teknisk feilVG +1
Dynamic Precision Norge AS (Kjeller)Confirmed

Dynamic Precision in Kjeller, a Norwegian PCB manufacturer supplying defense and aerospace, hit by a data breach involving server encryption (ransomware).

Industri / Elektronikk (forsvarsleverandør)RansomwareDigi.no
LovdataConfirmed

Lovdata's websites suffered DDoS over several days in September. Attackers attempted to overload the systems to make the site unavailable. User data not targeted.

Offentlig / Juridisk (lovdatabase)DDoSDigi.no +4
Høyre (politisk parti)Confirmed

The Conservative Party's websites hit by DDoS in final week of the parliamentary election campaign. NSM and the party attributed it to pro-Russian NoName057(16).

Politikk / SivilsamfunnDDoS (NoName057(16))VG/DN +3
Ringerike + flere kommuner og Østfold fylkeskommuneConfirmed

Ringerike and several Norwegian municipalities plus Østfold county council had websites hit by DDoS. Pro-Russian NoName057(16) claimed responsibility, motivated by the election.

Offentlig sektor (kommune/fylkeskommune)DDoS (NoName057(16))NRK Buskerud +2
Ikke navngitt selskap på Østlandet (PST-bekreftet)Confirmed

PST confirmed a new data breach in Eastern Norway by the same pro-Russian group as the Bremanger dam. Physical processes affected without danger. Victim not publicly named.

Industri (uspesifisert)Datainnbrudd / OT-påvirkning (prorussisk hacktivisme)Aftenposten +2
Extend AS + Bergen/Drammen/Kristiansand/Ringsaker kommuner + NTNUConfirmed

Trondheim software vendor Extend AS hit by ransomware. Four municipalities (Bergen, Drammen, Kristiansand, Ringsaker) and NTNU (~77,500 emails in test env) had data compromised via EQS.

IT-leverandør → Offentlig sektor / UtdanningSupply chain ransomwareDigi.no +4
Narvik havnConfirmed

Hackers encrypted two servers and exfiltrated ~10 GB from Narvik port, a NATO-strategic logistics hub. A previously unknown group published the data. Kripos and NSM notified.

Transport / Havn (NATO-strategisk)Ransomware / datainnbruddDigi.no +4
Risevatnet-demningen, Bremanger (Breivika Eiendom)Confirmed

Pro-Russian hackers opened a valve at the Risevatnet dam in Bremanger, releasing 500 L/s for nearly 4 hours. PST attributed in August to a pro-Russian group via weak password.

Energi / Kritisk infrastruktur (vannkraft)OT-angrep (prorussisk hacktivisme)Aftenposten +2
Logistikkfirma på Skjetten (ikke navngitt)Confirmed

Freight and logistics firm in Skjetten near Lillestrøm hit by ransomware. Company (~30 employees, ~NOK 100M revenue) had to wipe its own servers to recover. Identity withheld.

Transport / LogistikkRansomwareDigi.no
Genus AS (leverandør til politiet)Confirmed

Genus, no-code platform vendor to the Norwegian police, hit by ransomware in January. Several GB of sensitive data incl. customer contracts with national ID numbers leaked on the dark web.

IT/Tech (no-code-plattform)Ransomware med datatyveriDigi.no +1
Unacast / Gravy Analytics (norsk-amerikansk)Confirmed

Location data broker Unacast/Gravy Analytics hacked. About 146,000 Norwegian mobile devices likely affected; movement data leaked on a Russian hacker forum. Datatilsynet notified.

IT/Tech (lokasjonsdata-megler)Datalekkasje (AWS-skylagring)NRK Østfold +3
Gran kommuneConfirmed

Gran municipality detected an intrusion on 17 December. Attackers had a foothold on an unpatched server and installed VNC, stopped before ransomware deployment. No known exfiltration.

Offentlig sektor (kommune)Datainnbrudd / ransomware-forsøk (stanset)NRK Innlandet +5
Tensio (nettselskap)Confirmed

Personal data on Tensio employees (incl. national ID numbers and salaries) was inadvertently made public on an external site by a partner during a pension tender. Datatilsynet notified.

Energi (nettselskap)Datalekkasje (feilpublisering hos partner)Tensio
Hå Rugeri AS (Nortura-datter)Confirmed

Attackers took over the CEO's email at Hå Rugeri and sent a fake invoice to a supplier who paid EUR 73,686 (~NOK 868,000) to the wrong account. Reported to Datatilsynet and police.

Industri / LandbrukBEC / CEO-svindelDigi.no +2
ISAR Aerospace Norge AS (Andøya)Confirmed

Norwegian police investigated a suspected data breach at ISAR Aerospace Norge on Andøya. A Hungarian former employee was arrested for downloading company data to an external drive.

Industri / Forsvar (romfart)Innsidetrussel / datatyveriDigi.no +2
Skanlog (Vinmonopolet rammet på forsyning)Confirmed

Logistics firm Skanlog hit by LockBit 3.0 ransomware on 21 April. Deliveries to Vinmonopolet halted. Skanlog represented ~20% of Vinmonopolet's volume.

Transport / Logistikk → VarehandelRansomware (LockBit 3.0)TV 2 +3
Avarn Security ASConfirmed

Avarn Security AS confirmed it was hit by ransomware on 22 February 2024. IT teams worked to contain damage and restore operations; customers were notified.

Sikkerhet / TjenesterRansomwareNRK +1
APT28 / Fancy Bear router-operasjon (norske TP-Link-rutere som proxy)Confirmed

PST, FBI and partners disrupted a Russian APT28 router botnet using vulnerable TP-Link devices as relays. About ten compromised routers in Norway were identified and patched.

Telekom / Infrastruktur (forbrukerruter)Statlig nettverksoperasjon (rutere brukt som proxy)VG +1
Sør-Varanger kommuneConfirmed

Police notified Sør-Varanger that login credentials had been resold on the dark web for $10. The attack was stopped in early reconnaissance with help from Atea.

Offentlig sektor (kommune)Datainnbrudd (rekognosering, stanset)Sør-Varanger kommune +1
Norske Boligbyggelag (NBBL)Confirmed

NBBL trade body and subsidiaries (incl. insurance arms) hit by ransomware. NBBL refused to pay ransom. Reported to Datatilsynet and police.

Bolig / FinansRansomwareNBBL +4
Tietoevry (Moelven Industrier ASA rammet i Norge)Confirmed

Akira ransomware hit a Tietoevry data center in Sweden on the night of 20 January. Norwegian customers including Moelven Industrier were indirectly impacted via shared services.

IT/Tech (driftsleverandør)Ransomware (Akira)Digi.no +3

Have corrections or additional sources? Email [email protected].

Questions or inquiry? [email protected] Contact us →