---
title: "Norwegian Dam Hack: Offline Security | Firevault"
description: "When unidentified attackers seized control of Norway's Risevatnet dam this April, they did it with nothing more exotic than a weak password."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security#webpage",
      "url": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security",
      "name": "Norwegian Dam Hack: Offline Security",
      "description": "When unidentified attackers seized control of Norway's Risevatnet dam this April, they did it with nothing more exotic than a weak password.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-learn.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Norwegian Dam Hack: Offline Security",
          "item": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Norwegian Dam Hack: Offline Security",
      "description": "When unidentified attackers seized control of Norway's Risevatnet dam this April, they did it with nothing more exotic than a weak password.",
      "url": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/og-cached/649ad906347d6f17.png",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2025-07-02T00:00:00.000Z",
      "dateModified": "2025-07-02T00:00:00.000Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security"
      },
      "inLanguage": "en-GB",
      "articleSection": "News",
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2025
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

The Risevatnet IncidentWhy Critical Infrastructure Gets…The Password ProblemLessons for Data ProtectionBeyond Temporary IsolationThe Real QuestionConclusionMore

[Knowledge Vault](/learn/knowledge)/ News 

News · 2 July 2025 

# Norwegian Dam Hack: Offline Security

When unidentified attackers seized control of Norway's Risevatnet dam this April, they did it with nothing more exotic than a weak password.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fnorwegian-dam-hack-offline-security)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fnorwegian-dam-hack-offline-security&text=Norwegian%20Dam%20Hack%3A%20Offline%20Security%0A%0AWhen%20unidentified%20attackers%20seized%20control%20of%20Norway's%20Risevatnet%20dam%20this%20April%2C%20they%20did%20it%20with%20nothing%20more%20exotic%20than%20a%20weak%20password.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fnorwegian-dam-hack-offline-security)[](mailto:?subject=Norwegian%20Dam%20Hack%3A%20Offline%20Security&body=When%20unidentified%20attackers%20seized%20control%20of%20Norway's%20Risevatnet%20dam%20this%20April%2C%20they%20did%20it%20with%20nothing%20more%20exotic%20than%20a%20weak%20password.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fnorwegian-dam-hack-offline-security)

News #OSSOffline Secure Storage® 

Why it matters

## What this means for organisations holding critical data

When unidentified attackers seized control of Norway's Risevatnet dam this April, they did it with nothing more exotic than a weak password.

**On this page**[The Risevatnet Incident](#section-0)[Why Critical Infrastructure Gets…](#section-1)[The Password Problem](#section-2)[Lessons for Data Protection](#section-3)[Beyond Temporary Isolation](#section-4)[The Real Question](#section-5)[Conclusion](#section-6)

On this page

1.  [The Risevatnet Incident](#section-0)
2.  [Why Critical Infrastructure Gets Connected](#section-1)
3.  [The Password Problem](#section-2)
4.  [Lessons for Data Protection](#section-3)
5.  [Beyond Temporary Isolation](#section-4)
6.  [The Real Question](#section-5)
7.  [Conclusion](#section-6)

When unidentified attackers seized control of Norway's Risevatnet dam this April, they did it with nothing more exotic than a weak password. For four full hours, the facility's valves sat exposed to remote manipulation. It is a stark reminder that connectivity creates vulnerability.

## The Risevatnet Incident

In April 2025, attackers gained control of the Risevatnet dam's control systems in Norway. The attack vector was embarrassingly simple: a weak password on an internet-connected control interface. For four hours, the attackers had the theoretical ability to manipulate the dam's water flow controls.

Fortunately, no physical damage occurred. But the incident exposed a fundamental truth about connected infrastructure: the more critical the system, the more dangerous its connectivity becomes.

## Why Critical Infrastructure Gets Connected

The push to connect [critical infrastructure](/control-for-critical-infrastructure) comes from understandable motivations:

-   **Remote monitoring**: Operators can check system status without physical presence
    
-   **Efficiency**: Automated systems can respond faster than human operators
    
-   **Cost savings**: Fewer on-site personnel means lower operational costs
    
-   **Data collection**: Connected systems generate valuable operational data
    

These benefits are real. But they come with a hidden cost: every connection is a potential attack vector.

## The Password Problem

The Risevatnet attack used a weak password. This is depressingly common. Despite decades of security awareness training, organisations continue to protect critical systems with passwords like 'admin123' or 'password1'.

But here is the uncomfortable truth: even strong passwords are not enough. Given sufficient motivation and resources, attackers can eventually compromise any connected system. The question is not whether your password is strong enough. It is whether the system should be remotely accessible at all.

## Lessons for Data Protection

The Risevatnet incident was not about data, but the principle applies directly. Consider your organisation's most sensitive information:

-   **Strategic plans**: Is your five-year strategy really needed online 24/7?
    
-   **Customer records**: Do historical records need to be instantly accessible?
    
-   **Financial data**: Should your complete financial history be one breach away from exposure?
    
-   **Legal documents**: Does privileged information need to live on connected servers?
    

For each of these, ask: what is the actual cost of offline storage versus the risk of online exposure?

## Beyond Temporary Isolation

Some organisations believe they have solved this problem with isolated systems, computers not connected to the internet. But true isolation is surprisingly rare. Systems get temporarily connected for updates. USB drives bridge the gap. Maintenance windows create exposure.

Firevault goes further with physical disconnection. Our vaults are designed to be offline by default, with connection only occurring when the owner physically initiates it. There is no maintenance window, no update cycle, no temporary connection that could be exploited.

## The Real Question

The Risevatnet attack succeeded because a critical system was connected when it did not need to be. The attackers did not need sophisticated exploits, they needed a weak password and an internet connection.

Your organisation's data faces the same calculus. Every piece of information stored online is one vulnerability away from exposure. For the data that matters most, the question is not how to protect it online. It is whether it should be online at all.

## Conclusion

Norway's dam survived its four-hour compromise without physical damage. But the incident serves as a warning: connectivity creates vulnerability, and the most critical assets deserve the strongest protection.

For your most sensitive data, that protection is simple: take it offline. Firevault makes this practical, providing secure offline storage with [controlled access](/news/controlled-access-buyers-guide-offline-secure-storage) when you need it. The best defence against remote attacks is having nothing to remotely attack.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your data sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Command**Access windows and retrieval under your control 

**Location**Held in a secure Firevault Bunker 

Keep reading

## You may also find these useful

[Knowledge 

### End-of-Life Technology: CNI Cyber Risk

Nearly half of all network assets are ageing or obsolete. When technology can no longer be patched, it becomes a permanent open door for attackers. Physical disconnection addresses what patching cannot.

](/learn/knowledge/end-of-life-technology-cni-hidden-cyber-risk)[Knowledge 

### NCSC CNI Guide: Severe Cyber Threats

An authoritative guide aligned with NCSC recommendations for Critical National Infrastructure. How physical disconnection supports the four-objective framework for cyber resilience.

](/learn/knowledge/ncsc-cni-severe-cyber-threat-guide)[Knowledge 

### UK CNI Threat Landscape 2026

State actors, ransomware groups, and supply chain vulnerabilities converge on UK critical infrastructure. Understanding the threat informs the defence.

](/learn/knowledge/uk-cni-threat-landscape-2026)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Which offline secure storage solution is right for you?

Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up 

[![Firevault - physical control for critical data](/assets/logo-white-official-BKfZ19hm.png)](/)

International cyber resilience

## Protect what matters. Control what moves. 

Firevault is an international cyber resilience company specialising in Offline Secure Storage® and OT cyber security, helping organisations protect critical data and govern how systems connect and how data moves.

[hello@fire-vault.com](mailto:hello@fire-vault.com)United Kingdom 

Cyber security certified 

[

![Cyber Essentials Certified](https://fire-vault.com/__l5e/assets-v1/6f8f42a2-89e1-4c20-938f-3f34d30bc90c/cyber-essentials-2026.png)

![Cyber Essentials Plus Certified](https://fire-vault.com/__l5e/assets-v1/8a77bf2c-6711-4762-b093-c4d650153bc9/cyber-essentials-plus-2026.png)

](https://registry.blockmarktech.com/certificates/)

Start here

### Not sure what you need?

Use the OSS Concierge to find the right protection or control approach for your organisation.

[Find your starting point ](/find-my-oss)

01  · Data protection & storage

[](/offline-secure-storage)

[

### Offline Secure Storage®

](/offline-secure-storage)

Physically disconnected by default, identity verified and built on dedicated hardware, from 300GB personal storage to enterprise-scale infrastructure.

[OSS overview](/offline-secure-storage)[LUV](/luv)[Vault](/vault)[Storage](/storage)[Enterprise](/enterprise)[Bunkers](/bunkers)

02  · Network evolution and rapid protection

[](/control)

[

### Control

](/control)

Nine governance modules across FIRE and VAULT, composed into Control Blueprints around the outcome, environment and risk you need to manage.

[Control overview](/control)[Nine modules](/control/nine-modules)[Blueprints](/control-blueprints)[Firebreak](/control/modules/firebreak)[Control by industry](/control-for-industry)

### Knowledge

-   [Knowledge Vault ](/learn/knowledge)
-   [Buyer guides ](/learn/guides/by-role)
-   [Technical guides ](/learn/guides/technical)
-   [Firevault Playbooks ](/playbooks)
-   [White papers ](/learn/whitepapers)
-   [Learn and explainers ](/learn)
-   [Breach tracker ](/learn/breaches)
-   [FAQs ](/learn/faq)

### Firevault

-   [About Firevault ](/about)
-   [Security ](/security)
-   [Partners ](/partners)
-   [Press and media ](/press-media)
-   [Help Centre ](/help)
-   [Careers ](/careers)
-   [Invest in Firevault ](/investors)
-   [Contact ](/contact)

© 2026 Firevault Limited · Company No. 16320803 · VAT No. 490 8551 64 · Registered in England and Wales 

[Site Map](/sitemap)[Privacy Charter](/privacy-charter)[Terms](/terms)[Planet Pledge](/planet-pledge)[Vault Commitment](/vault-commitment)[LUV Commitment](/luv-commitment)[Cookie Policy](/cookies)

[](https://www.linkedin.com/company/firevault-limited)[](https://twitter.com/firevaultuk)

Get started

![Firevault](/favicon.svg)

Tell us what you need to protect. 

Privacy 

## You decide what we measure

Essential cookies keep this site working. Everything else is optional and off until you say otherwise. Read the [Privacy Charter](/privacy-charter) or the [Cookie Policy](/cookies).

Accept allEssential only

Manage options