Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Norsk Hydro

Norsk Hydro Vendor Cyber Rating & Cyber Score

hydro.com

Hydro is a leading industrial company that builds businesses and partnerships for a more sustainable future. We develop industries that matter to people and society. Since 1905, Hydro has turned natural resources into valuable products for people and businesses, creating a safe and secure workplace for our 31,000 employees in more than 140 locations and 40 countries. Today, we own and operate various businesses and have investments with a base in sustainable industries. Hydro is through its businesses present in a broad range of market segments for aluminium, energy, metal recycling, renewables and batteries, offering a unique wealth of knowledge and competence. Hydro is committed to leading the way towards a more sustainable future,


Norsk Hydro A.I CyberSecurity Scoring

Norsk Hydro
Company Information
Website:http://www.hydro.com
Employees number:13,095
Number of followers:374,060
NAICS:212
Industry Type:Mining
Homepage:hydro.com
Norsk Hydro Risk Score (AI oriented)
Between 650 and 699
logo
Norsk HydroMining
Updated:
01/04/2026
658/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Norsk Hydro Global Score (TPRM)
xxxx
logo
Norsk HydroMining
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Norsk Hydro
Norsk HydroWeak
Current Score
658B (WEAK)
01000
4 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
675Before Incident
MAY 2026
664Before Incident
APRIL 2026
663Before Incident
MARCH 2026
661Before Incident
FEBRUARY 2026
643Before Incident
JANUARY 2026
643Before Incident
DECEMBER 2025
631Before Incident
NOVEMBER 2025
629Before Incident
OCTOBER 2025
626Before Incident
SEPTEMBER 2025
622Before Incident
AUGUST 2025
619Before Incident
JULY 2025
615Before Incident
MARCH 2023
475Before Incident
Cyber Attack
01 Mar 2023Norsk Hydro
Norsk Hydro

Norsk Hydro Ransomware Attack

445After Incident
CRITICAL-30
NOR442050724
In March, Norsk Hydro, one of the world's largest aluminum companies, experienced a significant cyberattack that shut down production lines across its 170 plants, and led to a switch from computer to manual operations at some of its facilities. The attackers used a malware called 'LockerGoga' to encrypt files on thousands of servers and PCs, affecting all 35,000 employees in 40 countries. The financial impact of the attack reached approximately $71 million. The breach occurred due to an employee opening an infected email, leading to a severe compromise of the company's IT infrastructure. Despite the extensive damage, Norsk Hydro chose not to pay the ransom and instead worked on restoring their data from backups and improving their cybersecurity posture with the help of Microsoft's cybersecurity team.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial
IMPACT
Financial Loss: $71 millionSystems Affected: Thousands of servers and PCsDowntime: Switch from computer to manual operationsOperational Impact: Shutdown of production lines across 170 plants
DATA BREACH
Data Encryption: Files encrypted
MARCH 2021
483Before Incident
Ransomware
01 Mar 2021Norsk Hydro
Norsk Hydro

Norsk Hydro Ransomware Attack

194After Incident
CRITICAL-289
NOR416051424
Norsk Hydro, a global aluminum company, experienced a severe ransomware attack that ceased operations at some of its 170 plants. The breach impacted all 35,000 employees across 40 countries by locking files on thousands of servers and PCs. Initiated by an infected email from a customer, the breach allowed hackers to plant LockerGoga ransomware, leading to financial damages nearing $71 million. The company's transparency and decision not to pay the ransom were acclaimed by security experts, and they leaned on Microsoft's cybersecurity team for recovery and restoration.
INCIDENT DETAILS -
TYPE
Ransomware Attack
MOTIVATION
Financial Gain
IMPACT
Financial Loss: $71 millionThousands of servers and PCsOperational Impact: Ceased operations at some of its 170 plants
DATA BREACH
Data Encryption: Files locked by ransomware
JUNE 2019
539Before Incident
Ransomware
16 Jun 2019Norsk Hydro
Norsk Hydro

Indictment of Ukrainian National Volodymyr Viktorovich Tymoshchuk for Ransomware Attacks Using LockerGoga, MegaCortex, and Nefilim

268After Incident
CRITICAL-271
NOR5602456091025
In 2019, Norsk Hydro, a Norwegian aluminum manufacturing giant, fell victim to a LockerGoga ransomware attack orchestrated by Ukrainian national Volodymyr Viktorovich Tymoshchuk. The attack crippled the company’s global operations, forcing a shift to manual processes across 170 sites in 40 countries. Production lines halted, IT systems were encrypted, and employees resorted to pen-and-paper methods, causing operational chaos and financial losses estimated at $75 million in the first week alone. The attack disrupted supply chains, delayed shipments, and required a months-long recovery effort, including full IT infrastructure rebuilds. While no customer or employee data was confirmed stolen, the business outage and reputational damage were severe. The incident also exposed vulnerabilities in critical industrial control systems, prompting industry-wide cybersecurity overhauls. Tymoshchuk’s ransomware strain was designed to maximize disruption, encrypting files and locking users out of systems until ransom demands—reportedly in the millions of dollars—were met. The attack remains one of the most financially damaging ransomware incidents against a single corporation, illustrating the existential threat such cyberattacks pose to industrial sectors.
INCIDENT DETAILS -
TYPE
ransomwarecyber extortionunauthorized access
MOTIVATION
financial gain (extortion)
IMPACT
Financial Loss: $100+ million (estimated, including $104M from LockerGoga alone)Systems Affected: hundreds of organizations (U.S. and Europe)complete disruption of business operations (varies by victim)Norsk Hydro: weeks of recoveryOperational Impact: severe (encryption of critical systems, halted production)Brand Reputation Impact: high (publicized attacks on major firms like Norsk Hydro)potential lawsuits from victimsregulatory fines (if applicable)Identity Theft Risk: high (if PII was exfiltrated)Payment Information Risk: high (if financial data was exfiltrated)
DATA BREACH
corporate datapotentially PII/financial data (varies by victim)Sensitivity Of Data: high (industrial/proprietary data, possible PII)Personally Identifiable Information: likely (in some cases)
MARCH 2019
792Before Incident
Ransomware
01 Mar 2019Norsk Hydro
Norsk Hydro

LockerGoga, MegaCortex, and Nefilim Ransomware Campaigns Linked to Fugitive Tymoshchuk Volodymyr Viktorovych

522After Incident
CRITICAL-270
NOR1832118091625
Norsk Hydro, a Norwegian aluminium and renewable energy company, was one of the most high-profile victims of the LockerGoga ransomware attack in March 2019, orchestrated by the cybercriminal group linked to Tymoshchuk Volodymyr Viktorovych (alias Deadforz). The attack crippled Hydro’s global operations, forcing the shutdown of smelting plants, production lines, and IT systems across 170 sites in 40 countries. Employees reverted to manual processes, causing massive operational disruptions, delayed shipments, and financial losses estimated at $40–71 million in the first week alone. The ransomware encrypted critical files, halting automated production and supply chain coordination.Hydro refused to pay the ransom, instead investing in full system restoration—a process that took weeks to months for complete recovery. The attack exposed vulnerabilities in industrial control systems (ICS) and highlighted the catastrophic risk of ransomware on manufacturing sectors. While no direct data breach of customer or employee records was confirmed, the operational paralysis threatened Hydro’s market position and triggered industry-wide alarms about cyber-physical risks in heavy industries. The incident remains a benchmark for ransomware’s potential to disrupt global supply chains and served as a catalyst for stricter cybersecurity regulations in critical infrastructure sectors.
INCIDENT DETAILS -
TYPE
ransomware attackextortionorganized cybercrime
MOTIVATION
financial gainextortiondisruption of business operations
IMPACT
Financial Loss: $18 billion (estimated global damages)Systems Affected: 250+ companies (primarily in the US) and additional international victimsnetwork cripplingbusiness disruptiondata leakage threatspotential lawsuits from victimsregulatory penalties
DATA BREACH
sensitive corporate datapotentially PIISensitivity Of Data: High (threats of data leakage used for extortion)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Norsk Hydro ?
?
What was Norsk Hydro's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Norsk Hydro's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Norsk Hydro's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Norsk Hydro's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Norsk Hydro's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Norsk Hydro's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Norsk Hydro's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Norsk Hydro's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Norsk Hydro's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Norsk Hydro's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Norsk Hydro's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Norsk Hydro's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Norsk Hydro ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Norsk Hydro's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?