Norway's Police Security Service (PST) said the intrusion into the Norwegian Parliament (Stortinget) was likely carried out by APT28—also tracked as Fancy Bear and Microsoft's STRONTIUM—a threat group linked to Russia's GRU. Attackers gained access to email inboxes belonging to parliamentary employees and elected officials, while attempts to move from those accounts into internal parliamentary networks were unsuccessful. Norwegian authorities said the case was fully investigated and publicly attributed the operation to APT28, although PST said the evidence did not support a formal indictment.
The compromise was tied to weak email passwords and the lack of multi-factor authentication on affected accounts. Norwegian officials said the incident fit a broader APT28 campaign that began in 2019 and targeted organizations in Norway and other countries, aligning with Microsoft's reporting on STRONTIUM's evolving credential-harvesting activity, including large-scale brute-force and password-spraying attacks against cloud email services such as Office 365.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a report describing new STRONTIUM/APT28 credential-harvesting patterns, including large-scale brute-force activity and targeting of cloud email accounts. The report aligned with later Norwegian assessments of the Parliament intrusion.
A referenced Microsoft report said that from September 2019, APT28 began using brute-force and credential-harvesting attacks at larger scale, including targeting Office 365 accounts at more than 200 private and government organizations.
PST said the Norwegian Parliament intrusion was part of a broader APT28 campaign that began in 2019 and targeted organizations in Norway and abroad. The activity was described as consistent with APT28's shift toward large-scale credential-harvesting and Office 365-focused attacks.
Norway's Police Security Service said APT28, also known as Fancy Bear and linked to Russia's GRU, was most likely responsible for hacking the Norwegian Parliament's email accounts. PST said it did not have enough evidence to bring a formal indictment.
Foreign Minister Ine Eriksen Søreide said in October that initial clues suggested Russian hackers were most likely behind the attack on the Stortinget.
The Norwegian Parliament hack was disclosed on September 1. Public reporting said the incident involved unauthorized access to parliamentary email accounts.
Attackers gained access to the Norwegian Parliament's email system, including inboxes of employees and elected officials, and attempted unsuccessfully to pivot into internal parliamentary networks. Investigators said weak passwords and lack of two-factor authentication contributed to the intrusion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
microsoft.com
Open sourcezdnet.com
Open sourcepst.no
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.