EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyber-attack/2025-norway-hydro-dam-attack
059/430

File EL-0372CriticalOngoingCyber Attack / Critical Infrastructure Attack / ICS Intrusion

Norwegian Hydroelectric Dam Cyber Attack

Also filed as Norway Hydropower ICS Attack · Russian Hack on Norwegian Critical Infrastructure

Russian GRU-linked Sandworm group successfully breached multiple Norwegian hydroelectric dam control systems, gaining access to industrial control systems (ICS) responsible for power generation and water flow regulation.

  • #critical-infrastructure
  • #ics-scada
  • #hydroelectric
  • #russia
  • #espionage
Notoriety9/10
Event
14 Aug 2025
Disclosed
18 Aug 2025
Target
Statkraft & Multiple Norwegian Hydro Operators
Actor
Sandworm
Status
Ongoing

01Summary

In mid-August 2025, Sandworm infiltrated OT networks at several Norwegian hydropower facilities. They achieved Level 2 and partial Level 1 access to SCADA systems but did not cause physical damage. Norwegian authorities described it as one of the most serious cyber incidents against national critical infrastructure in recent years.

02Background

Norway is one of Europe’s largest producers of renewable hydroelectric power. Its dams are critical for both domestic energy and electricity exports to Europe.

03Key revelations

  1. 01Successful penetration of highly secured European critical infrastructure.
  2. 02Growing Russian interest in pre-positioning inside energy systems.

04Technical analysis

The attackers used living-off-the-land techniques and exploited weak segmentation between IT and OT networks. They deployed custom tools for mapping and maintaining persistent access to PLCs and HMIs.

Attack vector
IT network compromise leading to OT pivoting
Attack method
Lateral movement into air-gapped OT environments
Initial access
Unknown (likely spear-phishing or supply chain)
Lateral movement
OT protocol abuse
Persistence
Custom backdoors in ICS environments
Exfiltration
Limited (reconnaissance focused)
Tool / malware
Custom ICS tooling
Malware type
Reconnaissance & Persistence

Vulnerabilities exploited

  • Poor IT/OT network segmentation

05Threat actor

Sandworm (APT44) – Elite Russian GRU unit known for destructive attacks and critical infrastructure intrusions across Europe.

Aliases

  • Voodoo Bear
  • APT44

APT designations

  • APT44

Attribution sources

  • Norwegian National Security Authority (NSM)
  • Microsoft Threat Intelligence
  • Dragos

06Victims and impact

Additional victims

  • Several regional hydropower plants

Countries affected

  • Norway

07Data exposed

Data types

  • SCADA Configurations
  • Dam Control Schematics
  • Operational Procedures

08Financial damage

Hundreds of millions in emergency security upgrades and operational reviews.

09Timeline

  1. 2025-08-14Initial intrusion detected.
  2. 2025-08-18Public disclosure by Norwegian authorities.

10Reaction and fallout

Public reaction

Significant concern across Scandinavia regarding energy security.

Political impact

Strengthened NATO cyber cooperation and increased defense spending on critical infrastructure.

Geopolitical consequences

Further deterioration of Russia-Norway/EU relations in cyberspace.

11Legal

International attribution and sanctions discussions.

12Aftermath

Policy changes

  • Mandatory OT segmentation and zero-trust architecture for critical energy infrastructure.

Security improvements

  • Nationwide emergency OT hardening program

13Significance and legacy

Significance

One of the most advanced confirmed intrusions into operational hydroelectric systems in Europe.

Legacy

Became a benchmark case for protecting renewable energy infrastructure from nation-state threats.

14Disclosure and media

Authentication
Government and vendor technical reports

Publishing organisations

  • NRK
  • Reuters
  • Dragos
  • Microsoft

15Field notes

  1. 01Norway produces over 90% of its electricity from hydropower, making it a high-value strategic target.

16Resolution

Access removed; extensive forensic investigation and remediation continues.

17Sources

Official documents

  • Norwegian NSM Alert

References

  1. [1]Norwegian government statements
  2. [2]Dragos reports
  3. [3]Microsoft Threat Intelligence
Fact sheetEL-0372

Dates

Event
14 Aug 2025
Started
14 Aug 2025
Discovered
15 Aug 2025
Disclosed
18 Aug 2025
Ongoing
Yes

Target

Organisation
Statkraft AS
Type
Energy Company
Sector
Energy / Critical Infrastructure
Country
Norway
Gov. level
National

Actor

Name
Sandworm
Type
Nation State
Nationality
Russia
Nation-state
Russia
Affiliation
GRU
Motivation
Pre-positioning for potential sabotage and intelligence gathering on European critical infrastructure.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

Sensitivity
Critical
Published
No
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.