Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Norway’s Police Security Service (PST) said pro-Russian hackers were behind an April 2025 cyberattack on a dam in Bremanger. The attackers accessed remote controls and opened a water valve for around four hours. That public attribution does not establish that the Russian government ordered or directly conducted the attack.

What happened at the Bremanger dam?

In April 2025, attackers gained access to a control panel in the dam’s remote-control system, at the point where Risevatnet flows into the Riseelva in western Norway. They opened a valve, increasing the water flow. The valve stayed open for about four hours, according to The Associated Press.

Digi.no reported that the dam regulates water flowing to a fish-farming facility and that discharge rose by 497 litres per second, from 377 to 874 litres per second. Those figures are media-reported details, not independently confirmed engineering measurements published by PST.

Response and reported impact

Digi.no reported that personnel reached the dam within minutes and brought the flow under control. The reports said there was no flood danger or damage. No injuries were reported.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How access may have been obtained

The owner, Breivika Eiendom, reportedly attributed the intrusion to a poor password, according to Digi.no. That is the owner’s explanation as reported by the outlet; public reporting does not provide a full forensic account of the access path or the dam’s remote-access configuration.

What did PST say about who was responsible?

In August 2025, PST chief Beate Gangås said pro-Russian hackers were behind the incident, as reported by VG and AP. PST had taken over the investigation from Kripos, which initially handled it as a computer intrusion. The service said it would examine whether a foreign state was behind the attack as part of an influence operation.

The distinction matters: PST’s public attribution was to pro-Russian hackers. The cited public reporting does not identify the individual operators or establish that the Russian state directed or ordered the intrusion.

Police attorney Terje Nedrebø Michelsen said a three-minute video showing the dam control panel and a mark associated with a pro-Russian cybercriminal group was posted on Telegram on the day of the intrusion, according to Digi.no and AP. That reported association is part of the evidence discussed in coverage, but on its own it does not demonstrate a government chain of command.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does Norway’s 2026 threat assessment add?

PST’s National Threat Assessment 2026 says Russia, China, Iran, and North Korea conduct cyber operations in Norway directly or through proxy actors, and expects such activity to continue in 2026. It describes possible activity including intelligence collection, reconnaissance, influence operations, sabotage, and disruption.

The assessment also says Russian and Chinese actors exploited weaknesses in network devices such as routers to access Norwegian digital infrastructure in 2025. Separately, it says Russia is likely to use methods including influence operations, sabotage, recruitment, and intelligence activity involving civilian vessels, with attention to Norway’s support for Ukraine and the High North and Arctic. These are wider threat findings, not additional evidence about who ordered the Bremanger attack.

What is known—and what remains unproven?

Established in public reporting Not established by the cited public sources
Attackers accessed a remote valve-control panel and opened a valve in April 2025. The identity of the individual operators.
The valve remained open for around four hours; local personnel responded and controlled the flow. That the Russian government ordered or directly conducted the attack.
The owner reportedly blamed a poor password for the access weakness. A complete forensic explanation of how access was obtained or the system’s precise configuration.
PST chief Beate Gangås attributed the attack to pro-Russian hackers. A final public technical report resolving the operators’ command relationship or motive.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.