WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) Threat Actors' Breach of Norwegian Dam Cause Valve to Open at Full Capacity
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Threat Actors’ Breach of Norwegian Dam Cause Valve to Open at Full Capacity

TLP:CLEAR

Author: Chase Snow

Created: Thursday, June 26, 2025 - 15:38

Categories: Cybersecurity, OT-ICS Security, Security Preparedness

Summary: Open-source reporting has revealed that in April, unidentified threat actors compromised the systems of a Norwegian dam and opened its water valve to full capacity. The valve ran at full capacity for four hours before being detected. Energiteknik, a Norwegian news outlet, has mentioned that the attack didn’t put anyone in danger as it barely moved water output over the dam’s minimum water flow requirement. The water poured 497 liters per second over the minimum, though officials have said the riverbed could have handled up to 20,000 liters per second.

Analyst Note: While it’s unclear who the attackers are behind this incident, in recent years it has not been uncommon for threat actors to breach industrial systems and manipulate water levels or modify values at random. Especially during the current geopolitical climate, incidents such as these appear connected to larger international conflicts. As Risky Business News indicates “Pro-Palestinian hacktivists have repeatedly hacked Israeli water treatment facilities since 2020 and attempted to modify water chlorine levels unsuccessfully.”

Industrial systems connected to the internet are highly targeted during times of intense geopolitical tensions. Members are encouraged to ensure sensitive systems have minimal connection to the public internet as much as possible, especially as we continue to watch the conflict with Iran unfold.

WaterISAC is unaware of any additional information regarding this incident at this time.

Original Source: https://news.risky.biz/risky-bulletin-hackers-breach-norwegian-dam-open-valve-at-full-capacity/

Additional Reading:

  • (TLP:AMBER) WaterISAC Advisory – DHS Releases New NTAS Bulletin, Warns of “Heightened Threat Environment” in U.S. Following Strikes on Iran
  • (TLP:AMBER) Threat Advisory – Russian-linked Threat Actors Targeting Water Utilities

Mitigation Recommendations:

  • Fundamental 2 | Minimize Control System Exposure | WaterISAC’s 12 Cybersecurity Fundamentals for Water and Wastewater Utilities

Related WaterISAC PIRs: 6, 7, 9, 12

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) IOC Associated with Volt Typhoon Performed Network Enumeration on Utah Infrastructure

Jun 18, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Email Impersonation Remains a Persistent Risk for Water Utilities

Jun 18, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar