Why the Norsk Hydro attack is a ‘blueprint’ for disruptive hacking operations

It’s been a year since malicious code tore through the computer network of Norwegian aluminum giant Norsk Hydro, forcing the company to shift some of its operations to manual mode and inflicting tens of millions of dollars in damage. The ransomware attack brought a global manufacturing powerhouse to its knees, and with it more questions than answers about the hackers’ motivation. Attackers targeted a company with good security practices, yet used code that would have made it difficult to collect their extortion fee. Norsk Hydro never paid, a spokesman said. Now, an investigation published Monday argues that the LockerGoga ransomware variant was designed to disrupt rather than to extort — to lock up the enterprise and throw away the key. Regardless of who was behind the Norsk Hydro attack, it provides a “worryingly effective blueprint” for state-backed hackers to hide behind malware associated with criminals to achieve their goals, says […]

The post Why the Norsk Hydro attack is a ‘blueprint’ for disruptive hacking operations appeared first on CyberScoop.

Continue reading Why the Norsk Hydro attack is a ‘blueprint’ for disruptive hacking operations

Norsk Hydro’s cyber insurance has paid just a fraction of its breach-related losses so far

Norsk Hydro received an insurance payout of $3.6 million following a highly publicized cyberattack earlier this year, the company revealed in its third quarter earnings report. The insurance payout represents about 6% of the $60 million to $71 million in costs created by the incident through the third quarter, the company said. The Norwegian aluminum and energy giant expects more compensation will come as more costs are totaled. Norsk Hydro, which had a market capitalization of $12 billion last year, said after the attack in March that its policy, led by AIG, was “solid.” The company said it was struck with a large ransomware attack that started in its U.S. facilities then spread. It wasn’t until summer when Norsk Hydro determined the situation was stable. Incident responders determined the ransomware strain was LockerGoga, which has haunted the industrial sector. Norsk Hydro did not pay the ransom demand, deciding instead to restore its systems from digital backups. The firm also […]

The post Norsk Hydro’s cyber insurance has paid just a fraction of its breach-related losses so far appeared first on CyberScoop.

Continue reading Norsk Hydro’s cyber insurance has paid just a fraction of its breach-related losses so far

Norsk Hydro Q1 2019 Profits Sank Following Ransomware Attack

The first quarter profits for Norsk Hydro sank after the Norwegian aluminum and renewable energy company fell victim to a ransomware attack. According to Reuters, Norsk Hydro’s gains fell to 559 million Norwegian crowns (approximately $64.3 milli… Continue reading Norsk Hydro Q1 2019 Profits Sank Following Ransomware Attack

Ransomware blitzkrieg has already cost Norsk Hydro $40 million

The ransomware attack on Norsk Hydro reported last week has so far cost the company NOK 300-350 million or around $40 million (€36 million). The company entered recovery mode on Tuesday, with some departments still operating manually. The Norwegi… Continue reading Ransomware blitzkrieg has already cost Norsk Hydro $40 million

Podcast: The High-Risk Threats Behind the Norsk Hydro Cyberattack

Threatpost talks to Phil Neray with CyberX about Tuesday’s ransomware attack on aluminum producer Norsk Hydro, and how it compares to past manufacturing attacks like Triton, WannaCry and more. Continue reading Podcast: The High-Risk Threats Behind the Norsk Hydro Cyberattack

Norwegian aluminum producer Norsk Hydro hit with large ransomware attack

The IT systems of Norsk Hydro, a top global aluminum producer, were hit with ransomware late Monday, forcing the company to temporarily suspend production at some plants, the company and Norwegian authorities said. The ransomware that struck the company is known as LockerGoga, a nascent strain that first surfaced in January, according to Norway’s federal cybersecurity agency (NSM in Norwegian). In a statement, the company, which had a market cap of over $12 billion last year, said it is “working to neutralize the attack, but so far does not know the full extent of the situation.” In a press conference, Norsk CFO Eivind Kallevik said the attack started in its U.S.-based plants, but did not specify any further details on how the malware spread. The company has aluminum remelting facilities in Henderson, Ky., and Commerce, Texas. It also has offices in Baltimore. Kallevik said the company has taken measures to […]

The post Norwegian aluminum producer Norsk Hydro hit with large ransomware attack appeared first on CyberScoop.

Continue reading Norwegian aluminum producer Norsk Hydro hit with large ransomware attack