Oslo: Norway's domestic security agency on Wednesday accused pro-Russian hackers of carrying out a cyberattack in April that briefly compromised a dam's control system in the western municipality of Bremanger. Speaking at the Arendalsuka political festival, Police Security Service (PST) chief Beate Gangas stated that the incident at the Risavatnet dam is indicative of an increase in cyber operations against Western targets aiming to produce 'noticeable or visible results.'
According to Anadolu Agency, the breach on April 7 was detected by Breivika Eigedom, the company that owns the dam, after unauthorized access was reported on a remote-control panel regulating one of the dam's valves. This access lasted for nearly four hours, during which attackers were able to adjust the water flow in the minimum flow pipe. The valve was opened to its maximum, releasing 497 liters per second more water than the minimum requirement during the period.
Bjarte Steinhovden, the dam's technical manager, mentioned that the breach likely resulted from a weak password. Initially, the National Criminal Investigation Service (Kripos) investigated the incident before PST took over to determine if it was part of a state-backed influence operation.
Kripos subsequently discovered a video featuring the dam's control panel, which bore a static watermark identifying a pro-Russian cybercriminal group. This footage appeared on Telegram the same day as the breach. Kripos prosecutor Terje Nedreb¸ Michelsen noted that this group comprises several actors involved in cybercriminal activities and is linked to various cyberattacks on companies in Western countries over recent years.