Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
30APR

Norway joins the Salt Typhoon victim list

3 min read
08:16UTC

Norway's Police Security Service (PST) confirmed on 23 April that Norway is a Salt Typhoon victim, taking the public country count past nine.

TechnologyDeveloping
Key takeaway

PST's Salt Typhoon disclosure signals a Nordic-led wave of public attribution to come.

Norway's Police Security Service, PST, publicly confirmed Norway as a victim of the Salt Typhoon telecoms compromise on the day of the sixteen-agency advisory, taking the public country count past nine 1. PST timed the disclosure to the publication of the sixteen-agency joint advisory, using the document as the occasion to surface domestic caseload that had previously sat behind a classification boundary.

Salt Typhoon is the China-nexus actor that CISA and the FBI have tracked across 200+ telecoms operators in 80+ countries since the campaign first surfaced. The Norwegian disclosure does not add a different actor or instrument; it adds a jurisdiction inside a NATO-aligned Five Eyes-adjacent partner. PST is the first non-Five Eyes intelligence service to confirm Salt Typhoon victim status this calendar year.

PST's timing carries the operational signal. Norway is signalling that other participating Five Eyes-adjacents, the Netherlands, Germany, Spain, Sweden, Japan among the sixteen signatories, may follow with their own confirmations now that the headline document is in print. For procurement and risk Teams at telecoms operators across the Nordic and German-speaking markets, the read is that public exposure tracking is about to expand. The same coalition coordination that delivered the E-Note seizure is now being applied to attribution publication, with PST as the leading edge.

Deep Analysis

In plain English

Salt Typhoon is the name for a Chinese hacking campaign targeting telecoms companies, the firms that run phone calls and internet connections, across at least nine countries. PST, Norway's domestic security service, confirmed on 23 April that Norwegian telecoms networks were among the victims. Norway carries NATO Arctic communications through its cables and satellite ground stations, so the hackers may have sought transit data from allied military circuits rather than ordinary Norwegian phone calls.

Deep Analysis
Root Causes

Norway occupies a structurally attractive position for Salt Typhoon's telecoms-exploitation campaign: Telenor operates the Svalbard satellite ground station, the primary civilian satellite communications gateway for Arctic-region traffic, and Norwegian telecoms backhaul carries NATO northern-flank military communications under civilian contracts.

Salt Typhoon's primary intelligence value in a Norwegian network is therefore not Norwegian domestic communications but transit data from Arctic surveillance, submarine cable landing points, and allied military voice and data circuits that share civilian telecoms infrastructure.

The underlying structural cause is the absence of a mandatory disclosure framework for telecoms-sector breaches in Norway equivalent to the NIS2-derived obligations in EU member states. PST's confirmation was a voluntary choice; Norwegian law did not require it. That structural gap means Norway's disclosure signals PST's political judgment, not a legal trigger.

What could happen next?
  • Consequence

    PST's disclosure creates political precedent for the other fourteen advisory signatories to confirm or deny domestic Salt Typhoon victim status; Germany, Japan and Spain are the three with confirmed advisory involvement and no public national confirmation yet.

    Short term · 0.75
  • Risk

    Telecoms operators across Nordic and Baltic markets face elevated supervisory scrutiny from national cyber and intelligence agencies now that PST has set the public disclosure bar.

    Short term · 0.8
  • Precedent

    The PST timing model, national victim confirmation on the same day as a multilateral advisory, may become a standard diplomatic tool for Five Eyes-adjacent agencies to surface caseload without requiring a standalone national announcement.

    Medium term · 0.7
First Reported In

Update #2 · FIRESTARTER puts Cisco below the patch line

NCSC UK· 30 Apr 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.