Norsk Hydro ASA
Postboks 980 Skøyen
0240 OSLO
Your reference Our reference Date
20/01770-4 12.05.2021
Closure of case - Norsk Hydro ASA
We refer to your data breach notification, received on 21 March 2019, pertaining to a data
breach which was discovered on 18 March 2019. We also refer to the additional information
you provided on 26 March 2019 and 21 June 2019.
Based on the information available to us, the case can be summarised as follows:
The data breach was caused by a targeted, sophisticated and malicious attack.
The attack culminated with the introduction of ransomware to your systems. As a
consequence, the availability of personal data was adversely and severely impacted.
The forensic investigations confirm that the attacker’s motivation was to hamper your
operations to get ransom for encrypted files.
In order to perform the attack, the attacker accessed user names and passwords of the
Active Directory. Forensic investigations carried out by yourselves as well as the
Norwegian National Security Agency does not indicate that the confidentiality of
personal data was affected beyond this.
When investigations were ongoing and the extent of the data breach was still unclear,
you communicated information regarding the data breach to employees and external
stakeholders through various channels.
You have since the attack implemented measures in cooperation with the Norwegian
National Security Agency and other external experts in order to ensure the resilience
of your systems against similar attacks in the future, hereunder:
o Measures to manage access and reduce the risk of lateral movement and
escalation of privileges
o Measures to detect and respond to unauthorized access
o Overall strengthening cyber securities capabilities throughout the organization,
illustrated by setting cyber security as a key achievement of 2020, requiring
Postal address: Office address: Phone: Ent.reg: Home page:
P.O. Box 458 Sentrum Trelastgata 3 +47 22 39 69 00 974 761 467 www.datatilsynet.no/en/
N-0105 OSLO N-0191 OSLO
mandatory training of IT users, establishment and training of a cyber-crisis
team, setting cyber risk management as part of your enterprise risk
management process, etc.
Taking into account the above, the Norwegian Data Protection Authority does not see a need
to pursue this matter further. We therefore close the case.
Kind regards
Eirik Gulbrandsen
Senior Engineer
Jade Bui
juridisk rådgiver
This letter has electronic approval and is therefore not signed
2