How Are We Attacked?
We've gone through what digital security entails. However, just as technology develops and becomes more advanced, the methods used by people with malicious intent to collect personal and sensitive data for their own gain become even more sophisticated. That said, how are businesses and enterprises, as well as private individuals, actually attacked?
Insight
What are we protecting ourselves against?
The most common cyberattacks against Norwegian businesses are viruses and malicious software (also known as malware), as well as phishing and social manipulation.
Additionally, digital extortion (for example through so-called ransomware) is also among the most common cyberattacks on Norwegian businesses, and the methods used are increasingly sophisticated. This is reported by the NSM in the report Risk 2026.
According to a survey from the Norwegian Business Security Council, serious security incidents cost businesses 85,000 kroner on average in 2020.
Security incidents can have many and complex causes. Businesses often attribute them to bad luck or coincidences, human error, a lack of security focus among the employees, and that existing procedures are not being followed. As we can see, people—not machines—are the common denominator with regard to these causes.
Despite the fact that businesses, and people in general, are becoming increasingly more aware of digital threats, the general level of ICT security, both in the private and public sector, is too low, according to NSM. Threat actors exploit this for purposes such as opportunistic gains, spreading disinformation, surveillance, and damaging infrastructure.
AI enables criminals to run cyber attacks that are faster, more targeted, and more convincing, such as highly realistic phishing emails and fake audio or video. At the same time, security teams are using AI to spot unusual activity and respond more quickly, turning cyber security into an “AI versus AI” battle.
Let's take a closer look at various cyberattack methods.
Malicious software (malware)
Malware is a collective term for program code that, without the user's permission, performs actions with the user's systems or information. There are many different types of malware—among the best known are viruses, ransomware, trojans, and worms .
The spread of malware often occurs through mass mailing or personalised email, that is, so-called phishing or spear-phishing, or through compromised websites that have been subjected to cyberattacks.
Spreading malware can be used to commit various forms of online crime. For example, data breaches, espionage, and financial crimes linked to ransomware.
Viruses
Simply put, a virus is program code that is inserted into an existing program file—also referred to as a host. The name naturally comes from biology, and digital viruses have much in common with the ones we know from the physical world.
The virus copies itself into other files on the computer when the program file is run, and spreads further to other machines when the infected program files are shared.
Viruses are typically spread through emails, file downloads, social media, and memory sticks, and there are also viruses that send out emails themselves with infected files, thereby contributing to the files being shared further.
Computer viruses can slow down or crash your device, delete or corrupt files, steal passwords and personal data, or let criminals take remote control of the machine. In serious cases they can lock you out of your own system, spread to other devices on your network, damage business operations, or be used to install more harmful malware like ransomware or spyware.
Signs of a virus include a suddenly much slower computer, frequent crashes, strange pop‑ups, changed browser settings, or programs and files behaving oddly. If you suspect infection, update and run a full scan with reputable antivirus software (check what is available for your operating system type—can also read reviews of the software) and follow its instructions to remove any threats.
Ransomware
In recent years, there have been several high-profile security incidents that have affected various actors and digital infrastructures. In particular, there have been many examples of so-called ransomware.
This is a type of attack where the cybercriminals lock the victim out of their own systems, or prevent them from accessing their own files. In other words, they hold the digital systems and data hostage, and demand a ransom to return them.
Often, it is a case of data being encrypted—the data is essentially shuffled around to the point of being unrecognisable, so it essentially becomes worthless—and the owner must pay up to be able to decrypt it.
Examples of ransomware attacks
Click to read about three examples of ransomware attacks.
Trojans
A Trojan (or Trojan horse) is a program that hides in a legitimate program, and is therefore installed without the user’s knowledge. It usually accompanies the program at download and installation, for example through file-sharing clients and browser extensions.
Criminals can enter the computer through this program and carry out unwanted actions, such as stealing information and transferring money.
Here we say that a backdoor is created on the computer. Through such a backdoor, cybercriminals can potentially register the computer in bot networks, that is, a network of virus-infected machines, which can then be used to send out spam, denial of service attacks, and other types of cyberattacks—without the owner of the computer knowing about it.
Campaigns using families like ZeuS/SpyEye/Dridex/Emotet/TrickBot have targeted Norwegian online‑banking customers to steal BankID credentials and empty accounts. Norwegian companies and municipalities have reported incidents where a seemingly harmless file (e.g., a job application document or software update) turned out to be a trojan that opened a backdoor into internal networks.
These are regularly mentioned in reports from Kripos, Økokrim, and NCSC/NSM as major threats.
Computer worms
A computer worm is a type of virus—the difference is that a computer worm does not depend on a host to spread.
Simply put, computer worms are software that enters a system by exploiting specific security weaknesses. The worm then looks for connected machines and systems. If it finds a new weakness, it multiplies and infects the new system.
Most work incidents are part of global worm outbreaks.
In 2010, the computer worm named Stuxnet enabled someone—there is a widespread belief that the US and Israel were behind—to gain access to control systems at a nuclear plant in Iran, causing great damage to nuclear centrifuges.
In 2017, the WannaCryransomware worm exploited a flaw in Windows which affected organizations in many countries. It locked people’s Windows computers and demanded money to unlock their files. It spread automatically across networks like a contagious disease, quickly hitting hospitals, companies, and governments around the world and making many machines unusable until they were cleaned or restored from backup.
Insight
Vulnerabilities in critical infrastructure
Stuxnet proved that digital attacks can successfully be directed towards physical installations and cause material damage.
In 2007, even before Stuxnet became known, an experiment was carried out at the Idaho National Laboratory in the USA, where a control system was digitally manipulated and caused a diesel generator to explode.
Physical installations and infrastructure can also be indirectly affected by ransom attacks (as with the Colonial Pipeline hacking), by locking out owners and depriving them of control over their own systems.
All of these are examples of digitalisation introducing new vulnerabilities, and that it is important to take digital security very seriously, not least in relation to critical infrastructure such as power and water supply.
Social manipulation
Social manipulation involves “using psychological means to attack users of IT systems,” according to the Great Norwegian Encyclopedia.
By playing on emotions such as fear, greed and curiosity—often in combination with short deadlines—scammers try to get you to give up account information, passwords, social security numbers and other sensitive information. They often pretend to be someone you know and trust.
As obvious scams are usually caught by security systems and furthermore set off most people’s warning lights, the scammers have become much more sophisticated. It is increasingly common to receive emails and SMS messages that are targeted toward specific individuals, with details taken from their Facebook or LinkedIn profiles or their employer's website, making it seem very believable.
Furthermore, AI lets attackers create very convincing fake emails, messages, and phone calls that sound natural, use correct language, and can even mimic a specific person’s style. It also helps them quickly tailor scams to each target using personal details from social media or data leaks, and run live, interactive conversations through chatbots that adjust their story as you respond.
It's easy to think that you should not click on links in an email saying you've won a new iPhone that you need to claim within 24 hours. That said, when the email appears to be from your boss or your bank, it can be much harder to distinguish scams from genuine interactions.
Social manipulation is used in phishing and many other forms of fraud and cybercrime.
Phishing
The most well-known form of social manipulation is what is called phishing (aptly pronounced “fishing”).
You've definitely seen it yourself: You receive an email or message that appears to be from a genuine source, asking you to click a link—either to claim a prize, take advantage of an exclusive offer, or to receive a shipment. Once you click on the link, you are asked to provide personal information or enter payment information.
The purpose of phishing is to trick you into revealing sensitive information or to spread malware. Threat actors rely on mass mailings of messages, hoping that someone takes the bait. However, they can also approach you as an individual, particularly using generative AI.
AI-driven phishing attacks use generative AI to create highly personalized and realistic emails, SMS messages, phone communication, or social media outreach to achieve a desired result. In most cases, the goals of these attacks are the same as that of a social engineering attack: to access sensitive information, gain access to a system, receive funds, or prompt a user to install a malicious file on their device.
AI also makes it possible to use real-time communication in a highly sophisticated way, making it hard to separate the fake communication from that with a human being. The use of AI also provides the opportunity for attackers to approach a countless number of people simultaneously.
Phishing attackers trick you into giving up data they can use for profit or other crimes, such as identity theft.
CEO fraud
Messages that appear to come from your boss, or others in management where you work, are an increasingly common tactic of social manipulation. This is referred to as CEO fraud.
Such an attack can be very elaborate and cunning: The scammers may have studied how your boss usually expresses themselves—and may even have “stolen” their voice, which is reproduced in a phone call using so-called deepfake technology.
The scammers will then typically come up with a very urgent request, too time-sensitive to be communicated through the normal channels; for example to urgently transfer a large sum of money to a “customer”, which of course in reality is the scammers' bank account.