The day an aluminum giant went back to paper and pen
In March 2019, Norsk Hydro, one of the world's largest aluminum producers, publicly reported that it had been hit by the LockerGoga ransomware, in an episode widely covered by the international security press (BleepingComputer). Ransomware is the category of attack that encrypts files and entire systems and then demands payment for the recovery key, paralyzing those who depend on them to produce and generate revenue.
Os números divulgados pela própria companhia dão a dimensão do evento. Cerca de 22 mil computadores foram afetados, em aproximadamente 170 unidades distribuídas por 40 países, o que levou ao isolamento de redes e à parada ou redução de linhas produtivas. A decisão de desconectar ambientes inteiros trocou produtividade imediata por controle da situação, um dilema que todo decisor enfrenta quando o incidente já está em curso.
To keep part of its operations running, Norsk Hydro reported having fallen back on manual processes, with employees using paper, printed spreadsheets, and instructions posted on bulletin boards. The company chose not to pay the ransom and disclosed the case openly, releasing periodic updates to the market on the progress of the recovery and on the accumulated financial costs.
The reported loss fell in the range of NOK 550 million to NOK 650 million, about US$ 71 million, with estimated losses of nearly US$ 40 million in the first week alone (SecurityWeek). For comparison, the average global cost of a data breach was US$ 4.88 million, according to IBM's Cost of a Data Breach 2024 report. The internal details of the incident were never made public in depth, and any remote diagnosis would be speculation. The value of the case lies in what it reveals about the fragility of entire operations in the face of a single digital event.
How incidents of this magnitude typically spread
Although the internal details of the incident are not public, attacks like this one generally exploit known vectors, and the first of them is phishing paired with social engineering. The practical scenario tends to be mundane: a finance professional receives a message that mimics a regular supplier, opens the attachment with the supposed duplicate copy of an invoice, and unwittingly grants the first foothold inside the corporate network. Verizon's Data Breach Investigations Report 2024 notes that 68% of the breaches analyzed involved a human element, such as operational error or falling for a well-crafted scam.
The second recurring vector combines compromised credentials with poorly configured remote access. Passwords reused across personal and corporate services circulate in old leaks, and a remote access portal exposed to the internet without MFA (Multi-Factor Authentication) turns stale data into a valid key. For the attacker, signing in with the legitimate login of a user with administrative privileges costs little and rarely triggers traditional controls, because what appears in the logs is an authenticated and seemingly routine access.
The third vector is the absence of network segmentation, which defines the distance between a localized incident and a large-scale shutdown. When administrative workstations, file servers, domain controllers, and operations-related systems coexist in the same logical space, without internal authentication and routing barriers, malicious code travels from one machine to thousands in very short intervals. Companies with multiple plants and distributed teams carry this risk in multiplied form, because the convenience of a single network also benefits whoever has already made it inside.
What you can do to protect your infrastructure
The first layer is endpoint protection with EDR (Endpoint Detection and Response), a technology that observes the behavior of each device instead of relying solely on signatures of already cataloged threats. When a process begins encrypting files en masse or replicating itself to other machines, the tool automatically isolates the equipment and preserves the rest of the environment. Combined with continuous proactive monitoring, with correlated alerts reviewed by specialists, this layer shortens the interval between the first anomalous signal and effective containment, which is exactly where the size of the loss is determined. This is the combination that structures a managed cybersecurity operation.
The second layer is backup that is isolated, encrypted, and regularly tested. The practical principle is the 3-2-1 rule: three copies of the data, on two different types of media, with at least one beyond the reach of the production network, in immutable cloud storage or a disconnected repository. A backup that the attacker can see and encrypt along with the rest of the environment loses its function as a recovery plan, and that is why backup and disaster recovery strategies need to be validated through periodic restorations that are timed and documented, with evidence of intact data at the end of the test.
The third layer brings together continuous patch management, multi-factor authentication, and network segmentation. Security fixes applied in planned windows, with a complete asset inventory and prioritization by criticality, close the doors that automated campaigns scan relentlessly in search of outdated systems. MFA neutralizes much of the value of a leaked password, and segmentation ensures that a compromised environment does not communicate freely with all the others, turning a potentially devastating event into a contained and manageable problem.
The fourth layer addresses people and method. Ongoing user training, with periodic phishing simulations and individualized feedback, changes the behavior of whoever receives the malicious message before it can take effect. Add to that a documented incident response plan, with defined roles, up-to-date contacts, a priority order for systems, and drill testing, because deciding who disconnects what during a real crisis costs expensive hours of halted operations.
Questions every decision-maker should be asking right now
Three questions objectively expose an operation's real level of preparedness. Answer each one with concrete numbers, defined deadlines, and named owners.
- Would my backups really work in a disaster like this one? How long until my operation is back up and running?
- Does my team have the right tools to identify and block an attack like this immediately, before it causes full-scale damage? How am I investing in preparing my technical team?
- How long would my company survive without access to its systems and files?
Would my backups really work in a disaster like this one? How long until my operation is back up and running?
The honest answer only shows up in a restoration test, with the clock running and critical systems coming back in a controlled environment. An execution report with green status confirms that the copy was made, without proving that it is intact, current, and accessible when the production environment is unavailable. A backup isolated from the domain, encrypted and immutable, combined with restorations documented on a fixed calendar, turns a technical promise into an RTO (Recovery Time Objective) that you can confidently present to the board.
Does my team have the right tools to identify and block an attack like this immediately?
Traditional antivirus recognizes already-known threats, while containing an attack in progress requires EDR with automatic isolation and continuous proactive monitoring capable of correlating weak signals across multiple points on the network. Equally decisive is the preparedness of the technical team, supported by patch management with a predictable routine, periodic training, and incident response drills that reveal process gaps before the attacker does. Investing in the team means giving them tools, a documented method, and specialized backup support for the moments of greatest pressure.
How long would my company survive without access to its systems and files?
Put the cost per hour of downtime on paper, including interrupted revenue, idle payroll, contractual penalties, delivery delays, and the erosion of reputation with clients and partners. Norsk Hydro kept part of its production running with paper and printed spreadsheets, an extreme measure that few operations can sustain for weeks on end. When you compare that cost per hour with the investment in layered protection, tested backup, and an incident response plan, the risk calculation usually becomes clear within a few minutes of analysis.
If your company does not yet have an integrated layered protection strategy, consider undergoing a Strategic IT Assessment, with no strings attached, to identify vulnerabilities before they become headlines.
Frequently asked questions
What is ransomware and why can it shut down an entire operation?
Ransomware é um tipo de ataque que criptografa arquivos e sistemas e exige pagamento pela chave de recuperação. Ele paralisa operações inteiras porque se propaga por redes sem segmentação, alcançando estações, servidores e sistemas de produção em intervalos curtos. No caso da Norsk Hydro, cerca de 22 mil computadores em 170 unidades foram afetados, segundo comunicados da própria empresa.
Is cloud backup enough to recover from a ransomware attack?
Cloud backup only truly protects when it is isolated from production credentials, encrypted, and preferably immutable. Copies accessible through the same network and the same administrative accounts can be encrypted along with the original environment. Validation comes from periodic, timed restorations that prove data integrity and the real time to recovery.
How long does it take to restore operations after a ransomware attack?
The timeline depends on the volume of data, the quality of the copies, and whether a tested incident response plan exists. Companies with isolated backup and defined restoration priorities typically bring critical systems back within a few days, while environments without prior testing take weeks. Norsk Hydro released recovery updates to the market over the course of several months after March 2019.