---
title: "Norwegian Dam Hack: Offline Security | Firevault"
description: "When unidentified attackers seized control of Norway's Risevatnet dam this April, they did it with nothing more exotic than a weak password."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security#webpage",
      "url": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security",
      "name": "Norwegian Dam Hack: Offline Security",
      "description": "When unidentified attackers seized control of Norway's Risevatnet dam this April, they did it with nothing more exotic than a weak password.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-learn.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Norwegian Dam Hack: Offline Security",
          "item": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Norwegian Dam Hack: Offline Security",
      "description": "When unidentified attackers seized control of Norway's Risevatnet dam this April, they did it with nothing more exotic than a weak password.",
      "url": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/og-cached/649ad906347d6f17.png",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2025-07-02T00:00:00.000Z",
      "dateModified": "2025-07-02T00:00:00.000Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/knowledge/norwegian-dam-hack-offline-security"
      },
      "inLanguage": "en-GB",
      "articleSection": "News",
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2025
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Overview

The Risevatnet IncidentWhy Critical Infrastructure Gets…The Password ProblemLessons for Data ProtectionBeyond Temporary IsolationThe Real QuestionConclusionMore

[Knowledge Vault](/learn/knowledge)/ News 

News · 2 July 2025 

# Norwegian Dam Hack: Offline Security

When unidentified attackers seized control of Norway's Risevatnet dam this April, they did it with nothing more exotic than a weak password.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fnorwegian-dam-hack-offline-security)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fnorwegian-dam-hack-offline-security&text=Norwegian%20Dam%20Hack%3A%20Offline%20Security%0A%0AWhen%20unidentified%20attackers%20seized%20control%20of%20Norway's%20Risevatnet%20dam%20this%20April%2C%20they%20did%20it%20with%20nothing%20more%20exotic%20than%20a%20weak%20password.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fnorwegian-dam-hack-offline-security)[](mailto:?subject=Norwegian%20Dam%20Hack%3A%20Offline%20Security&body=When%20unidentified%20attackers%20seized%20control%20of%20Norway's%20Risevatnet%20dam%20this%20April%2C%20they%20did%20it%20with%20nothing%20more%20exotic%20than%20a%20weak%20password.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fnorwegian-dam-hack-offline-security)

News #OSSOffline Secure Storage® 

**On this page**[01 The Risevatnet Incident](#section-0)[02 Why Critical Infrastructure Gets…](#section-1)[03 The Password Problem](#section-2)[04 Lessons for Data Protection](#section-3)[05 Beyond Temporary Isolation](#section-4)[06 The Real Question](#section-5)[07 Conclusion](#section-6)

On this page

1.  [The Risevatnet Incident](#section-0)
2.  [Why Critical Infrastructure Gets Connected](#section-1)
3.  [The Password Problem](#section-2)
4.  [Lessons for Data Protection](#section-3)
5.  [Beyond Temporary Isolation](#section-4)
6.  [The Real Question](#section-5)
7.  [Conclusion](#section-6)

When unidentified attackers seized control of Norway's Risevatnet dam this April, they did it with nothing more exotic than a weak password. For four full hours, the facility's valves sat exposed to remote manipulation. It is a stark reminder that connectivity creates vulnerability.

## The Risevatnet Incident

In April 2025, attackers gained control of the Risevatnet dam's control systems in Norway. The attack vector was embarrassingly simple: a weak password on an internet-connected control interface. For four hours, the attackers had the theoretical ability to manipulate the dam's water flow controls.

Fortunately, no physical damage occurred. But the incident exposed a fundamental truth about connected infrastructure: the more critical the system, the more dangerous its connectivity becomes.

## Why Critical Infrastructure Gets Connected

The push to connect [critical infrastructure](/control-for-critical-infrastructure) comes from understandable motivations:

-   **Remote monitoring**: Operators can check system status without physical presence
    
-   **Efficiency**: Automated systems can respond faster than human operators
    
-   **Cost savings**: Fewer on-site personnel means lower operational costs
    
-   **Data collection**: Connected systems generate valuable operational data
    

These benefits are real. But they come with a hidden cost: every connection is a potential attack vector.

## The Password Problem

The Risevatnet attack used a weak password. This is depressingly common. Despite decades of security awareness training, organisations continue to protect critical systems with passwords like 'admin123' or 'password1'.

But here is the uncomfortable truth: even strong passwords are not enough. Given sufficient motivation and resources, attackers can eventually compromise any connected system. The question is not whether your password is strong enough. It is whether the system should be remotely accessible at all.

## Lessons for Data Protection

The Risevatnet incident was not about data, but the principle applies directly. Consider your organisation's most sensitive information:

-   **Strategic plans**: Is your five-year strategy really needed online 24/7?
    
-   **Customer records**: Do historical records need to be instantly accessible?
    
-   **Financial data**: Should your complete financial history be one breach away from exposure?
    
-   **Legal documents**: Does privileged information need to live on connected servers?
    

For each of these, ask: what is the actual cost of offline storage versus the risk of online exposure?

## Beyond Temporary Isolation

Some organisations believe they have solved this problem with isolated systems, computers not connected to the internet. But true isolation is surprisingly rare. Systems get temporarily connected for updates. USB drives bridge the gap. Maintenance windows create exposure.

Firevault goes further with physical disconnection. Our vaults are designed to be offline by default, with connection only occurring when the owner physically initiates it. There is no maintenance window, no update cycle, no temporary connection that could be exploited.

## The Real Question

The Risevatnet attack succeeded because a critical system was connected when it did not need to be. The attackers did not need sophisticated exploits, they needed a weak password and an internet connection.

Your organisation's data faces the same calculus. Every piece of information stored online is one vulnerability away from exposure. For the data that matters most, the question is not how to protect it online. It is whether it should be online at all.

## Conclusion

Norway's dam survived its four-hour compromise without physical damage. But the incident serves as a warning: connectivity creates vulnerability, and the most critical assets deserve the strongest protection.

For your most sensitive data, that protection is simple: take it offline. Firevault makes this practical, providing secure offline storage with [controlled access](/news/controlled-access-buyers-guide-offline-secure-storage) when you need it. The best defence against remote attacks is having nothing to remotely attack.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

Where Firevault fits

## Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your data sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Command**Access windows and retrieval under your control 

**Location**Held in a secure Firevault Bunker 

Keep reading

## You may also find these useful

[Explainer 

### Offline Secure Storage: everything you need to know

Offline Secure Storage® is dedicated physical storage that has no network path to it until an authorised out-of-band command creates one. This explainer sets out what it is, how it differs from air gaps, tape and immutable cloud storage, what the standards and insurers expect, how access actually works and how to choose the right instance.

](/learn/knowledge/offline-secure-storage-everything-you-need-to-know)[Explainer 

### Everything finance leaders should know about Offline Secure Storage

A CFO-level explainer on Offline Secure Storage®: how to build the loss model before the control decision, what cyber insurance genuinely transfers, how to treat the cost of a physically isolated copy, and the financial records that need to survive a compromised estate.

](/learn/knowledge/offline-secure-storage-for-finance-leaders)[Explainer 

### Everything technology leaders should know about Offline Secure Storage

A CIO, CTO and IT director explainer on Offline Secure Storage®: why recovery fails on dependencies rather than tooling, how physical Layer 1 isolation differs from logical air gaps and immutability, how access and restore actually work, and how to design a recovery architecture that survives a privileged compromise.

](/learn/knowledge/offline-secure-storage-for-technology-leaders)