Attacks in Norway
Overview of publicly known cyberattacks against Norwegian organisations, based on open sources.
Each entry is grounded in open sources: NSM bulletins, established media coverage, and the affected organisations' own disclosures. FM CyberSecurity does not publish confidential information from client engagements.
| Date | Target | Sector | Type | Source |
|---|---|---|---|---|
| Document.no Confirmed Intrusion into the publishing system overnight into 7 August. Attackers claimed subscriber logs and plaintext passwords and said they were Anonymous. Document doubts that claim. | Media (nettavis) | Data breach (innbrudd i publiseringssystem) | VG +1 | |
| Digitaliseringsdirektoratet (Digdir) Confirmed DDoS on hosting partner Vivicta the night of 3 August took down ID-porten, MinID, Altinn and several health services. Normal operations restored 4 August. No indication of a data breach. | Public sector (kritisk infrastruktur) | DDoS | Digdir (egen statusmelding) +3 | |
| Norsk Tipping AS Three DDoS attacks in one week (2, 4 and 7 August) took Oddsen and the websites down for periods. Telenor filtered the traffic and all incidents were reported to police. No data theft. | Gaming and entertainment (statseid) | DDoS | NRK Innlandet +2 | |
| Ryde Technology AS Confirmed Unauthorized access the night of 2 August exposed 4.5 million accounts, 1.6 million in Norway: names, addresses, birth dates, emails and partial card numbers. Datatilsynet notified. | Transport (mobilitet) | Data breach (dataeksfiltrering) | Ryde (egen redegjørelse) +2 | |
| Nedre Romerike vann- og avløpsselskap (NRVA) Confirmed Maps of the water and sewage network, risk assessments and contingency plans covering 180,000 residents leaked after the Lørenskog attack. Operations and water quality unaffected. | Public sector (vann og avløp) | Data leak (via angrepet på Lørenskog kommune) | Digi.no +1 | |
| Alpha IT (IT-leverandør, Trondheim) Confirmed Data from Trondheim IT provider Alpha IT was published on the dark web. Up to 15 customer companies may be affected, including Ragde Eiendom. NSM in dialogue, Kripos notified. | IT and technology (IT-leverandør) | Data breach (via leverandørkjeden) | Digi.no +2 | |
| Digitaliseringsdirektoratet (Digdir) via Vivicta Confirmed DDoS on hosting partner Vivicta from Saturday 20 June until Sunday morning made several of Digdir's shared services unavailable. The same partner was hit again on 3 August. | Public sector (kritisk infrastruktur) | DDoS | Digi.no +1 | |
| Norsk Tjenestemannslag (NTL) Confirmed Norwegian union NTL (LO, 59,000+ members) hit by ransomware on 16 June; central IT systems taken offline. Sensitive personal data may be compromised. Datatilsynet and NSM notified. | Civil society (fagforening) | Ransomware (mulig datatyveri) | NTL (pressemelding via NTB) +2 | |
| Norsk Tipping AS Confirmed Norsk Tipping hit by DDoS three times in one week (2, 3 and 5 June). Games and websites slowed/unavailable; Telenor filtered the traffic each time. No data theft indicated; perpetrator unknown. | Gaming and entertainment (statseid) | DDoS | VG +7 | |
| Gran kommune (innsynssak-lekkasje) Confirmed Gran municipality leaked personal data on 27 residents, mainly national ID numbers, due to flawed manual FOIA handling. 18 cases affected. Discovered when a new scanning tool was deployed. | Public sector (kommune) | Data leak (feil i håndtering av innsynssaker) | NRK Innlandet | |
| Lørenskog kommune Confirmed Attacked 9 May with a ransom note. In July the actor published 1.8 TB of stolen data, including child welfare cases and patient records. Kripos is investigating. | Public sector (kommune) | Data breach (pengekrav og publiserte data) | Lørenskog kommune +8 | |
| Fredrikstad og Hvaler kommune Confirmed Fredrikstad and Hvaler municipalities had directory data on ~7,000 employees posted on a criminal forum 2 May. Employee search function abused to expose names, emails, phone numbers. | Public sector (kommune) | Data leak (misbrukt Ansattsøk-funksjon) | Fredrikstad kommune +2 | |
| Instructure (Canvas) og 37 norske utdanningsinstitusjoner Confirmed Canvas vendor Instructure leaked 3.65 TB. 37 Norwegian institutions affected including UiO, NTNU, OsloMet, NMBU, Innlandet, USN. ShinyHunters behind it. Ransom paid 11 May. | Education | Data leak (med utpressing) ShinyHunters | VG +5 | |
| Sats Norge (Sats ASA) Confirmed Sats Norway hit by data breach 14 March. 3,750 current and former employees affected via file server with HR and accounting data. Membership system not affected. Criminal group threatened to leak. | Services and retail (treningskjede) | Data breach (med utpressing) | SATS ASA +9 | |
| Den kulturelle skolesekken (DKS) / Kulturtanken Confirmed DKS portal data leak via vendor Netpower. Anonymous actor claims 1.39M rows stolen with names, addresses, emails and messages on performers, planners and school staff. No pupil data. | Public sector (kultur) | Data leak (via leverandøren Netpower) | Kulturtanken / DKS +4 | |
| Wilhelmsen Ship Management (skip-system) Confirmed Crypto virus on selected onboard PCs of a vessel operated by Wilhelmsen Ship Management on 18 February. No land based systems affected. Lockbit 5.0 claimed responsibility via leak site. | Transport (skipsfart) | Ransomware (hevder ansvar) LockBit 5.0 | Techwatch +2 | |
| Ikke navngitte norske virksomheter (Salt Typhoon) Confirmed In its 2026 national threat assessment, PST disclosed that Chinese actor Salt Typhoon compromised vulnerable network devices at Norwegian organisations. Victims were not named. | Multiple sectors | State operation (sårbare nettverksenheter) Salt Typhoon | PST (Nasjonal trusselvurdering 2026) +1 | |
| Telia Norge AS Confirmed Breach discovered November 2025; Payoutsking published 2.5 TB on the dark web. Around 500,000 private customers and staff in 17 municipalities incl. Bergen affected: SSNs, traffic data, contracts. | Telecom | Data leak Payoutsking | Telia Norge +6 | |
| 31 norske advokatfirmaer (samlerapport) Confirmed AdvokatWatch reported that 31 Norwegian law firms were affected by digital security breaches in 2025, tied to NSR warnings about Microsoft 365 account compromises. | Legal services (finans) | Data breach (phishing mot Microsoft 365) | AdvokatWatch +1 | |
| Lyd & Bilde Confirmed Lyd & Bilde's websites compromised with a fake reCAPTCHA/ClickFix popup trying to trick visitors into running malicious PowerShell scripts. Both Norwegian and Swedish editions hit. | Media (fagblad) | Phishing / BEC (ClickFix) | Digi.no | |
| Statsforvalteren i Innlandet m.fl. (6 statsforvaltere) Confirmed Six county governor offices issued FOIA PDFs with unredacted national ID numbers and names in metadata. At least 150 people affected in Innlandet. Datatilsynet notified. | Public sector (statsforvaltere) | Data leak (PDF-metadata med usladdet personinfo) | Digi.no +3 | |
| Flere norske bedrifter (SonicWall SSL VPN-kampanje) Confirmed Kripos warned in Jan 2026 that several Norwegian SMBs were hit by ransomware via old SonicOS SSL VPN bug. First known incident in Nov 2025. Akira suspected. Victims unnamed. | Multiple sectors (SMB) | Ransomware (via SonicOS-sårbarhet) Akira (mistanke) | Politiet (Kripos) +1 | |
| Veterinærinstituttet Confirmed Unknown intruders accessed the Norwegian Veterinary Institute's computer systems. The case was reported to police. Security chief could not determine the cause. | Public sector (forskning) | Data breach (inngangsvektor uavklart) | Nationen | |
| Helsenorge (Norsk helsenett SF) Confirmed Technical fault on Helsenorge briefly exposed other patients' national ID numbers and names for about 50 minutes. Not external hacking. Norsk helsenett notified Datatilsynet. | Health | Privacy incident (teknisk feil) | VG +1 | |
| Dynamic Precision Norge AS (Kjeller) Confirmed Dynamic Precision in Kjeller, a Norwegian PCB manufacturer supplying defense and aerospace, hit by a data breach involving server encryption (ransomware). | Industry (elektronikk, forsvarsleverandør) | Ransomware | Digi.no | |
| Lovdata Confirmed Lovdata's websites suffered DDoS over several days in September. Attackers attempted to overload the systems to make the site unavailable. User data not targeted. | Public sector (lovdatabase) → Legal services | DDoS | Digi.no +4 | |
| Høyre (politisk parti) Confirmed The Conservative Party's websites hit by DDoS in final week of the parliamentary election campaign. NSM and the party attributed it to pro-Russian NoName057(16). | Civil society (politikk) | DDoS NoName057(16) | VG/DN +3 | |
| Ringerike + flere kommuner og Østfold fylkeskommune Confirmed Ringerike and several Norwegian municipalities plus Østfold county council had websites hit by DDoS. Pro-Russian NoName057(16) claimed responsibility, motivated by the election. | Public sector (kommune og fylkeskommune) | DDoS NoName057(16) | NRK Buskerud +2 | |
| Ikke navngitt selskap på Østlandet (PST-bekreftet) Confirmed PST confirmed a new data breach in Eastern Norway by the same pro-Russian group as the Bremanger dam. Physical processes affected without danger. Victim not publicly named. | Industry | OT attack (datainnbrudd med OT-påvirkning, prorussisk hacktivisme) | Aftenposten +2 | |
| Extend AS + Bergen/Drammen/Kristiansand/Ringsaker kommuner + NTNU Confirmed Trondheim software vendor Extend AS hit by ransomware. Four municipalities (Bergen, Drammen, Kristiansand, Ringsaker) and NTNU (~77,500 emails in test env) had data compromised via EQS. | IT and technology (IT-leverandør) → Public sector, Education | Ransomware (via leverandørkjeden) | Digi.no +4 | |
| Narvik havn Confirmed Hackers encrypted two servers and exfiltrated ~10 GB from Narvik port, a NATO-strategic logistics hub. A previously unknown group published the data. Kripos and NSM notified. | Transport (havn, NATO-strategisk) | Ransomware | Digi.no +4 | |
| Risevatnet-demningen, Bremanger (Breivika Eiendom) Confirmed Pro-Russian hackers opened a valve at the Risevatnet dam in Bremanger, releasing 500 L/s for nearly 4 hours. PST attributed in August to a pro-Russian group via weak password. | Energy (vannkraft) | OT attack (prorussisk hacktivisme) | Aftenposten +2 | |
| Logistikkfirma på Skjetten (ikke navngitt) Confirmed Freight and logistics firm in Skjetten near Lillestrøm hit by ransomware. Company (~30 employees, ~NOK 100M revenue) had to wipe its own servers to recover. Identity withheld. | Transport (logistikk) | Ransomware | Digi.no | |
| Genus AS (leverandør til politiet) Confirmed Genus, no-code platform vendor to the Norwegian police, hit by ransomware in January. Several GB of sensitive data incl. customer contracts with national ID numbers leaked on the dark web. | IT and technology (no-code-plattform) | Ransomware (med datatyveri) | Digi.no +1 | |
| Unacast / Gravy Analytics (norsk-amerikansk) Confirmed Location data broker Unacast/Gravy Analytics hacked. About 146,000 Norwegian mobile devices likely affected; movement data leaked on a Russian hacker forum. Datatilsynet notified. | IT and technology (lokasjonsdata-megler) | Data leak (åpen AWS-skylagring) | NRK Østfold +3 | |
| Gran kommune Confirmed Gran municipality detected an intrusion on 17 December. Attackers had a foothold on an unpatched server and installed VNC, stopped before ransomware deployment. No known exfiltration. | Public sector (kommune) | Data breach (ransomware-forsøk, stanset) | NRK Innlandet +5 | |
| Tensio (nettselskap) Confirmed Personal data on Tensio employees (incl. national ID numbers and salaries) was inadvertently made public on an external site by a partner during a pension tender. Datatilsynet notified. | Energy (nettselskap) | Data leak (feilpublisering hos partner) | Tensio | |
| Hå Rugeri AS (Nortura-datter) Confirmed Attackers took over the CEO's email at Hå Rugeri and sent a fake invoice to a supplier who paid EUR 73,686 (~NOK 868,000) to the wrong account. Reported to Datatilsynet and police. | Industry (landbruk) | Phishing / BEC (CEO-svindel) | Digi.no +2 | |
| ISAR Aerospace Norge AS (Andøya) Confirmed Norwegian police investigated a suspected data breach at ISAR Aerospace Norge on Andøya. A Hungarian former employee was arrested for downloading company data to an external drive. | Industry (forsvar og romfart) | Insider threat (datatyveri) | Digi.no +2 | |
| Skanlog (Vinmonopolet rammet på forsyning) Confirmed Logistics firm Skanlog hit by LockBit 3.0 ransomware on 21 April. Deliveries to Vinmonopolet halted. Skanlog represented ~20% of Vinmonopolet's volume. | Transport (logistikk) → Services and retail | Ransomware LockBit 3.0 | TV 2 +3 | |
| Avarn Security AS Confirmed Avarn Security AS confirmed it was hit by ransomware on 22 February 2024. IT teams worked to contain damage and restore operations; customers were notified. | Services and retail (sikkerhetstjenester) | Ransomware | NRK +1 | |
| APT28 / Fancy Bear router-operasjon (norske TP-Link-rutere som proxy) Confirmed PST, FBI and partners disrupted a Russian APT28 router botnet using vulnerable TP-Link devices as relays. About ten compromised routers in Norway were identified and patched. | Telecom (forbrukerrutere) | State operation (rutere brukt som proxy) | VG +1 | |
| Sør-Varanger kommune Confirmed Police notified Sør-Varanger that login credentials had been resold on the dark web for $10. The attack was stopped in early reconnaissance with help from Atea. | Public sector (kommune) | Data breach (rekognosering, stanset) | Sør-Varanger kommune +1 | |
| Norske Boligbyggelag (NBBL) Confirmed NBBL trade body and subsidiaries (incl. insurance arms) hit by ransomware. NBBL refused to pay ransom. Reported to Datatilsynet and police. | Finance (bolig) | Ransomware | NBBL +4 | |
| Tietoevry (Moelven Industrier ASA rammet i Norge) Confirmed Akira ransomware hit a Tietoevry data center in Sweden on the night of 20 January. Norwegian customers including Moelven Industrier were indirectly impacted via shared services. | IT and technology (driftsleverandør) | Ransomware Akira | Digi.no +3 |
Have corrections or additional sources? Email [email protected].