Cybercrime

Recycling Giant Tomra Takes Systems Offline Following Cyberattack

Norwegian recycling giant Tomra says internal systems have been taken offline to contain an extensive cyberattack.

Norwegian recycling giant Tomra says internal systems have been taken offline to contain an extensive cyberattack.

Norwegian recycling giant Tomra has taken some of its systems offline after falling victim to what it describes as “an extensive cyberattack”.

A multinational company, Tomra manufactures waste collection and sorting products, including reverse vending machines and food sorters. The company operates close to 100,000 recycling systems worldwide.

On Monday, Tomra announced that some of its data systems were impacted by a cyberattack that was discovered on July 16, and that it immediately disconnected some systems to contain the incident.

In an update on Tuesday, the company announced that it had disconnected additional systems, and that it would keep all impacted systems offline until the incident is resolved.

“No new hostile activities have been detected,” the company announced.

“Our primary aim is to continue to deliver our services to customers, reducing the impact this attack has on them. The attack currently has limited impact on Tomra’s customer operations. Most of Tomra’s digital services are designed to operate offline for a certain amount of time but may have reduced functionality in the interim,” Tomra said.

Advertisement. Scroll to continue reading.

The company announced that its internal IT services and some back office applications remain offline, with an impact on its supply chain management. With major office locations offline, employees have been asked to work remotely.

Tomra’s reverse vending machines (RVMs) in Australia and North America remain fully operational, RVMs in Europe and Asia continue to work in offline mode, but some older models are no longer operating.

The company’s recycling and food sorter systems are operating as usual, with some limited functionality due to digital services being offline.

“We continue to work tirelessly to resolve the situation, and remain in dialogue with relevant authorities. We have not received any contact from those who are behind the attack,” the company said.

While Tomra has not shared details on the type of cyberattack it experienced, it is likely that file-encrypting ransomware was involved. Taking systems offline is a typical incident response step in the event of ransomware.

Related: Critical Infrastructure Services Firm Ventia Takes Systems Offline Due to Cyberattack

Related: Gas Stations Impacted by Cyberattack on Canadian Energy Giant Suncor

Related: Food Distributor Sysco Says Cyberattack Exposed 126,000 Individuals

Related Content

Cybercrime

Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.

Data Breaches

The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.

Data Breaches

FulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online.

Data Breaches

The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials.

Ransomware

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Cybercrime

Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.

Data Breaches

An extortion group stole personal, financial, and medical information from the hospital’s network.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version