← Norsk Hydro

2019 Norsk Hydro — LockerGoga ransomware; global plants switch to manual ops (transparency-focused response)

2019 Unknown records affected Share on X

Data compromised

Corporate emphasized operational disruption; exfiltration narratives varied by outlet—treat as mixed IT file loss without uniform PII census

Technical writeup

Norsk Hydro rolled manual production after 19 Mar 2019 Windows ransomware later widely associated with LockerGoga, stressing OT segmentation limited physical harm while IT rebuilds spanned weeks. Executive communications and Microsoft feature stories highlighted unusually open customer/investor updates for a heavy-industry ransomware wave.

Root cause

Human-operated ransomware deployment across enterprise IT (initial access vectors documented in tertiary analyses)

References