hw_7cccadab5f7e3e92
Russian-linked hackers open a flood-gate at a dam in Bremanger, western Norway.
In April 2025 Norwegian authorities discovered that cyber-attackers—believed to be linked to Russian actors—had remotely opened flood-gates at a dam in Bremanger for approximately four hours, releasing about 500 litres of water per second. The incident targeted an infrastructure indirectly tied to the national hydropower/river system (though the dam was primarily used for aquaculture), making it a critical infrastructure asset for civil use. Western Norway’s terrain and remote hydro-installations are part of the national electricity and water-management grid, and such remote infrastructure is harder to monitor and secure. Norway’s domestic intelligence agency publicly attributed the event to Russian-linked hackers and emphasised that the purpose was more about signalling and testing readiness than causing casualties. The dynamic aligns with grey zone logic—low-threshold infrastructure disruption serving as a coercive tool below the threshold of armed attack. In addition to the dam itself, the incident raised questions about the resilience of Norway’s control-systems in remote installations, reinforcement of ICS/SCADA security, and surveillance of adversary cyber-capabilities. The Norwegian government responded by elevating its threat assessment, reviewing water-infrastructure cyber-defences strategically, and increasing cooperation with Nordic and NATO cyber-partners.
E/M/R/S scores
- EExistence0/4 · Not assessed
- MIntent0/4 · Not assessed
- RRussian actor link0/4 · Not assessed
- SRussian state responsibility0/4 · Not assessed
Facts
No facts
Sources
-
- Role
- discovery_lead
- Date
- 2025-04-06T22:00:00Z
In April 2025 Norwegian authorities discovered that cyber-attackers—believed to be linked to Russian actors—had remotely opened flood-gates at a dam in Bremanger for approximately four hours, releasing about 500 litres of water per second. The incident targeted an infrastructure indirectly tied to the national hydropower/river system (though the dam was primarily used for aquaculture), making it a critical infrastructure asset for civil use. Western Norway’s terrain and remote hydro-installations are part of the national electricity and water-management grid, and such remote infrastructure is harder to monitor and secure. Norway’s domestic intelligence agency publicly attributed the event to Russian-linked hackers and emphasised that the purpose was more about signalling and testing readiness than causing casualties. The dynamic aligns with grey zone logic—low-threshold infrastructure disruption serving as a coercive tool below the threshold of armed attack. In addition to the dam itself, the incident raised questions about the resilience of Norway’s control-systems in remote installations, reinforcement of ICS/SCADA security, and surveillance of adversary cyber-capabilities. The Norwegian government responded by elevating its threat assessment, reviewing water-infrastructure cyber-defences strategically, and increasing cooperation with Nordic and NATO cyber-partners.