2025-06-30
Hackers Breached Norwegian Dam Controls in April
Hackers breached Norway's Lake Risevatnet dam control system in April, opening the facility's valve and increasing the water flow for four hours before the incident was detected. The increase in volume did not pose an immediate danger. Officials think the intruders exploited a weak password for the dam's web-based control panel and accessed the dam's operational technology (OT) environment. The dam's owner discovered the incident on April 7 and alerted authorities on April 10. The facility "primarily serves a fish farm and is not connected to Norway’s power grid."
Editor's Note
Seems like the dam got off easy. This is a case that highlights the importance of having good passwords, if not MFA, on the control interface, having access controls, not exposing it to the Internet, implementing active monitoring for the control system, and ensuring clear responsibility/ownership of those security practices. Make sure that you're actively finding and addressing gaps like these before the attackers do.

Lee Neely
Sounds like another case of relying on “security through obscurity” since there has been a lot of publicity around attacks against municipal water utilities. Even for a small incident like this one, the cost of prevention (requiring 2FA for all remote access) would have been less than dealing with the incident.

John Pescatore
Here we are in 2025 and weak passwords and lack of multifactor authentication are _still_ an issue. Someone must have known these passwords were weak; perhaps we need some form of whistleblower laws for insiders in the know to report weak passwords that pose a threat to the public. I know, I know — staffing and adjudicating such a thing would be onerous indeed. But current approaches just aren't working.

Ed Skoudis
A case where MFA could have prevented initial access and execution of the attack. Although a near miss, the incident is instructive for owner/operators of critical infrastructure and should be part of future table-top exercises.

Curtis Dukes
Read more in
HackRead: Norwegian Dam Valve Forced Open for Hours in Cyberattack
Risky: Risky Bulletin: Hackers breach Norwegian dam, open valve at full capacity