
What happened
Hydro's own account states the company was hit by an extensive cyber-attack in the early hours of 19 March 2019, affecting its global organisation. The UK National Cyber Security Centre names the tool as LockerGoga ransomware and records that Hydro was forced into manual operation at some plants and had to stop production at others. Hydro's Extruded Solutions business absorbed the heaviest damage, while its other divisions kept running close to normal output using manual workarounds. The company says its teams worked around the clock with outside help, reviewed every PC and server for malware, and rebuilt encrypted systems from back-ups. Contemporaneous reporting of a company briefing held the day after the attack describes Hydro telling reporters it would not pay the ransom, saying it did not know or need to know the amount demanded because it held recent, usable back-ups. Hydro's own retrospective puts the estimated total cost of the incident at around 800 million Norwegian kroner, a preliminary figure made while recovery was still under way.
Confidence and limits
Hydro's updates and its company-history page establish the date, the scale of disruption and the recovery method it used; the UK regulator's case reference corroborates the ransomware family and the shift to manual operation. The refusal to pay ransom rests on reporting of a press briefing rather than a Hydro document stating it directly, so that detail is attributed to reporting, not to the company's own record. Hydro's cost estimate was preliminary and should not be read as a final, audited total.
Why it mattered
Hydro's public, near-real-time updates during an active ransomware incident were unusual for a company of its size, and the response was widely cited afterward as a model for transparency. The case also showed that offline, tested back-ups combined with a willingness to run manually for days can keep essential production going without meeting an extortion demand, a combination of preparation rather than any single technical control.
Defensive takeaway
Check that critical operations have a manual fallback staff have actually rehearsed, not only a plan on paper, and that backups sit somewhere a network-wide infection cannot reach.
- Could our critical processes keep running on manual procedures for several days without core IT systems?
- Are our backups verified, current, and stored where ransomware spreading across the network could not encrypt them too?
- Do we have a plan, and an authorised spokesperson, ready before an incident forces a rushed public statement?
Hydro's experience is one case, not a guarantee that transparency or manual fallback limits damage in every ransomware incident; the malware family, the target's sector and the state of its back-ups all shape the outcome. But the company's own record, corroborated by a national cyber authority, gives defenders a documented example to test their own assumptions against.
Confirm that critical production or service processes have a documented, rehearsed manual fallback, and that backups are stored offline where a network-wide ransomware event cannot reach them.
Hydro's own incident updates and its later company-history account establish the date, the scope of disruption and the manual-operations response, corroborated by the UK National Cyber Security Centre's reference to the case. The specific decision not to pay ransom is documented only in contemporaneous reporting of a company briefing, not in a Hydro statement we opened directly.
Sources & reading trail
Confirms the 19 March 2019 attack date, manual-operations response across business areas, and the company's own estimate of total cost.
company-primary · Source published: Not established · Retrieved: 16 September 2026
UK National Cyber Security Centre confirms the LockerGoga ransomware family and the shift to manual plant operation.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Contemporaneous reporting of a company briefing describing the decision not to pay ransom and reliance on backups.
reputable-original-reporting · Source published: 20 March 2019 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.