01Summary
In mid-August 2025, Sandworm infiltrated OT networks at several Norwegian hydropower facilities. They achieved Level 2 and partial Level 1 access to SCADA systems but did not cause physical damage. Norwegian authorities described it as one of the most serious cyber incidents against national critical infrastructure in recent years.
02Background
Norway is one of Europe’s largest producers of renewable hydroelectric power. Its dams are critical for both domestic energy and electricity exports to Europe.
03Key revelations
- 01Successful penetration of highly secured European critical infrastructure.
- 02Growing Russian interest in pre-positioning inside energy systems.
04Technical analysis
The attackers used living-off-the-land techniques and exploited weak segmentation between IT and OT networks. They deployed custom tools for mapping and maintaining persistent access to PLCs and HMIs.
- Attack vector
- IT network compromise leading to OT pivoting
- Attack method
- Lateral movement into air-gapped OT environments
- Initial access
- Unknown (likely spear-phishing or supply chain)
- Lateral movement
- OT protocol abuse
- Persistence
- Custom backdoors in ICS environments
- Exfiltration
- Limited (reconnaissance focused)
- Tool / malware
- Custom ICS tooling
- Malware type
- Reconnaissance & Persistence
Vulnerabilities exploited
- Poor IT/OT network segmentation
05Threat actor
Sandworm (APT44) – Elite Russian GRU unit known for destructive attacks and critical infrastructure intrusions across Europe.
Aliases
- Voodoo Bear
- APT44
APT designations
- APT44
Attribution sources
- Norwegian National Security Authority (NSM)
- Microsoft Threat Intelligence
- Dragos
06Victims and impact
Additional victims
- Several regional hydropower plants
Countries affected
- Norway
07Data exposed
Data types
- SCADA Configurations
- Dam Control Schematics
- Operational Procedures
08Financial damage
Hundreds of millions in emergency security upgrades and operational reviews.
09Timeline
- 2025-08-14Initial intrusion detected.
- 2025-08-18Public disclosure by Norwegian authorities.
10Reaction and fallout
Public reaction
Significant concern across Scandinavia regarding energy security.
Political impact
Strengthened NATO cyber cooperation and increased defense spending on critical infrastructure.
Geopolitical consequences
Further deterioration of Russia-Norway/EU relations in cyberspace.
11Legal
International attribution and sanctions discussions.
12Aftermath
Policy changes
- Mandatory OT segmentation and zero-trust architecture for critical energy infrastructure.
Security improvements
- Nationwide emergency OT hardening program
13Significance and legacy
Significance
One of the most advanced confirmed intrusions into operational hydroelectric systems in Europe.
Legacy
Became a benchmark case for protecting renewable energy infrastructure from nation-state threats.
14Disclosure and media
- Authentication
- Government and vendor technical reports
Publishing organisations
- NRK
- Reuters
- Dragos
- Microsoft
15Field notes
- 01Norway produces over 90% of its electricity from hydropower, making it a high-value strategic target.
16Resolution
Access removed; extensive forensic investigation and remediation continues.
17Sources
Official documents
- Norwegian NSM Alert
References
- [1]Norwegian government statements
- [2]Dragos reports
- [3]Microsoft Threat Intelligence









