CSIDB logo
Incident

Nordlo

Incident posture

Attack window
Apr 2021
Location
Norway
Status
Historical
CIA posture
Available to members
Updated
2025-10-25 00:00

Linked entities

Victim
Nordlo
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Apr 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeting Nordlo, a provider of digitalization and managed IT services in Norway and Sweden, disrupted operations at Vakt og Alarm AS, which relies on the company's data center infrastructure. The incident caused critical failures in medical signal systems and security alarms across multiple care institutions, impacting welfare technology designed to support individuals with disabilities living independently. Service interruptions persisted beyond the initial attack, with restoration efforts ongoing to fully reinstate system functionality. The affected security firm serves numerous municipalities, primarily through its alarm and communication solutions for open care facilities.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

A ransomware attack targeted Nordlo, a Norwegian and Swedish provider of digitalization and managed IT services, on or around April 23, 2021. The attack originated at Nordlo’s office in Haugesund, Norway, and disrupted operations at Vakt og Alarm AS, a company colocated in Nordlo’s data center. Vakt og Alarm AS specialized in alarm, communication, and security solutions for care institutions and open care services, including medical signal systems and welfare technology designed to support individuals with disabilities living at home. The ransomware incident caused immediate technical failures in Vakt og Alarm’s systems, which were detected on April 23 when service disruptions began affecting their infrastructure.

The attack led to the failure of critical medical signal systems in multiple care institutions relying on Vakt og Alarm’s services. By April 24, systems remained partially offline, with full functionality not yet restored. Vakt og Alarm’s general manager, Lillian S. Lien, confirmed the ongoing challenges, noting Nordlo was working continuously to recover all affected systems. The outage impacted over 250 municipalities across Norway that used Vakt og Alarm’s products, including their flagship TMA security alarm systems deployed in both analog and digital configurations. Nordlo’s response focused on restoring operational capabilities for Vakt og Alarm, though no specific timeline for full recovery was disclosed in initial reports. The incident highlighted dependencies between managed service providers and critical infrastructure in the healthcare and social care sectors.

Sources

Sources available to members: 1 source.

CSIDB