RealCyberNews
Back to latest
criticalMarch 19, 2019 · 4 min read

The Ransomware Attack That Became a Case Study in Doing It Right

Norsk Hydro got hit by ransomware that shut down plants worldwide. What made this incident different wasn't the attack — it was the response.

By RealCyberNews Editorial Team

Share

In March 2019, ransomware hit Norsk Hydro, one of the world’s largest aluminum producers, forcing plants across Europe and the US to switch to manual operations overnight. Most ransomware stories end with a quiet payment and a vague statement. This one didn’t — and that’s why it’s still cited years later.

What happened

LockerGoga ransomware spread through Norsk Hydro’s networks, encrypting files and forcing the company to isolate plants and switch to manual, non-digital processes to keep aluminum production running at all. For a company of that scale, “manual operations” meant employees resorting to paper and phone calls to coordinate work that normally ran through computer systems.

The decision that made this incident different

Norsk Hydro refused to pay the ransom. More unusually, the company held daily public press briefings throughout the recovery, openly discussing what was affected, what recovery looked like, and what the financial impact was — eventually estimated at over $70 million. Most companies treat ransomware incidents as reputational damage to be minimized through silence; Norsk Hydro treated transparency itself as the response.

Why refusing to pay worked here

Paying a ransom doesn’t guarantee working decryption tools, doesn’t stop the attackers from having already stolen data, and funds the same group’s next attack. Norsk Hydro instead relied on backups and a methodical, if slower and more expensive, manual recovery — a real-world example of the trade-off between “pay and hope” and “rebuild and control the story.”

What this means beyond one company

This incident is frequently taught in cybersecurity and crisis-management courses specifically because the technical attack was unremarkable — LockerGoga was a known ransomware family — while the organizational response was not. For any organization running industrial or infrastructure systems, the lesson isn’t just “have backups,” it’s that transparent, decisive communication during a crisis can preserve trust that silence and a quiet payout would not.

Worried this affects you?

Check whether your email address has shown up in this breach — or any other — in seconds.

Run a free breach check →