Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Hackers hit oil, gas, defense companies in Norway

A single group of hackers using spearphishing has stolen industrial drawings, contracts and more from at least 10 oil, gas and defense companies in Norway, according to a published report.

Targeted e-mails sent while the companies were engaged in negotiations for large contracts contained malware that enabled the attackers to steal then exfiltrate the information, according to a report by the BBC.

SLIDESHOW: 10 scariest hacks from Black Hat and Defcon

Perhaps more firms were victimized, the Norwegian national security agency NSM says, but they haven't come forward, according to the BBC report.

User names, passwords, industrial drawings and contracts were among the data stolen, it says.

Based on code within the malware, methods used to target individual email accounts and how the data was extracted leads the NSM to think that one group perpetrated all the attacks, the BBC says.

The spearphishing was aimed at carefully chosen individuals and appeared to be legitimate, the report says.

This is the first time Norway has announced such a widespread espionage attack, but it wants the incidents to serve as warnings to others. The NSM is also encouraging other businesses that might have been targeted to come forward, the report says.

It is likely that many firms have been hit but don't know about it yet, NSM says.

The attacks were discovered by what NSM describes as vigilant users who reported them to IT staff within their companies. The companies then told NSM.

Read more about wide area network in Network World's Wide Area Network section.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: BBC, LAN
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: BBC, cybercrime, Defcon, intrusion, legal, security, spearphishing
Latest Blog Posts
Whitepapers
  • Award-winning unified information security from Clearswift.
    Fully integrated web and email gateway security solution, providing - protection from inbound threats, policy based encryption, and data loss prevention.
    Learn more »
  • Selecting an Application Lifecycle Management Vendor: An Ovum Report
    Leading industry analyst firms across the world include IBM Rational in their research efforts and provide opinions on our ALM solutions. Find out how Ovum confirmed IBM Rational as the clear leader on both axes of the assessment; Market Impact and Technology, along with a clear leadership in market presence.
    Learn more »
  • Unified Monitoring™ A Business Perspective
    The enterprise computing landscape has changed dramatically. Virtualisation, outsourcing, SaaS, and cloud computing are creating fundamental changes, and ushering in an era in which enterprises distribute increasingly critical IT assets and applications across multiple service providers.This paper explores today’s computing trends and their monitoring implications in detail. In addition, it reveals how a new monitoring paradigm architecture, that uniquely addresses the monitoring realities of today’s and tomorrow’s enterprises—whether they rely on internal platforms, external service providers, or a combination of both.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments