Don’t do SECURITY. Do business SECURELY.

LockerGoga ransomware forces Norsk Hydro into manual operations

Norwegian aluminium producer Norsk Hydro is hit by LockerGoga ransomware, switching plants to manual operation and refusing to pay.

Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware, which disrupted IT systems across the company. Several plants switched to manual operations while the company restored systems from backups rather than paying the ransom.

What happened

  • The attack was detected on 19 March 2019 and particularly affected the extruded solutions business.
  • Norsk Hydro said it would not pay the ransom and chose to rebuild from backups.
  • The company communicated openly throughout, including regular public updates and webcasts.
  • It later estimated the financial impact in the first quarter at up to NOK 450 million (about US$52 million).

Why it mattered

The incident showed how ransomware could halt heavy industry, and Norsk Hydro’s transparency became a widely cited example of good crisis communication. Its costs, recovery timeline, and decision not to pay were closely followed by other manufacturers assessing their own exposure.

Lessons for organisations

Keep offline, tested backups and rehearse restoring critical systems. Incident response plans should include manual workarounds and a communications plan for customers, staff, and investors. Segmenting IT from operational technology can help keep production running when office systems are hit. Clear, regular updates to customers and staff also help protect trust during recovery.

Sources: TechCrunch, Insurance Journal

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights