
Earlier this week, Norsk Hydro, a venerable Norwegian aluminum producer, was hit with a torrid ransomware attack that took down its entire network and operations worldwide. MSSP Alert reported the attack here. Rather than pay up, Hydro said it will rely on recent backups to stabilize and restore business critical systems and fill new orders.
Hydro said it does not know when operations will be normalized, and it's still too early to estimate the exact operational and financial impact of the attack. The company suspects that the attackers used the LockerGoga virus to hobble its infrastructure and encrypt files. External IT security partners, including Microsoft’s security team and Norway’s national security authorities, are working to bring the affected systems back to pre-attack status, Jo De Vliegher, who heads Hydro’s IT systems, said. While Hydro didn’t directly say that managed security service providers (MSSPs) were on the case, it did say that “other IT partners” had been called in. Presumably, that means MSSPs.
Norsk Hydro Disclosures
In the face of a cyber attack of that magnitude, some companies elect to parse out details or not to disclose much at all, perhaps choosing understandably not to make the toll any worse. Hydro, however, is to be credited for transparency and communications amid fallout from the attack. In a press conference and webcast held on Tuesday, March 19, along with an updated statement issued on Thursday, March 21, Hydro disclosed a fair amount of detail on the attack:
Norse Hydro: Business Recovery Status
As of March 21, operational status in the business areas: