News
5. Jan 2022

Cyber-attack against Strætó

Like previously reported, Strætó was a victim of a hostile cyber-attack from foreign hackers who managed to break into Strætó servers and steal data.

Information updated on 5 January, 2022. 


The attackers have threatened to publish the data if Strætó does not pay a requested fee. In accordance with the guidelines of the Icelandic Network Security Team (netöryggissveit Íslands), Strætó will not comply with such demands The Data Protection Authority (Persónuvernd) has been notified of the matter and Strætó is in constant contact with the institution as a result.

An investigation by Advania and the network security company Syndis is still ongoing and extensive measures have been taken to block the access of the parties in question and limit the impact of the data breach.  These include blocking access to specified IP numbers and specified access to Strætó’s systems, as well as restarting the passwords of individuals who have access to the systems in question.

The systems that the attackers have gained access to are the following:

  • Strætó’s payroll system where there is contact information, account information and salary information for current and former Strætó employees.
  • Strætó’s human resources system where there is contact information, employment contracts and other data related to Strætó’s former and current employees.
  • Strætó case file where you can find inquiries from the public, contact information of suppliers, partners and contractors, as well as copies data for job applications.
  • Strætó network where you can find information about audio recordings of calls that were made 90 days before the cyber-attack.

There is no indication that the attackers have or can misuse this information, but it cannot be ruled out that the data will be made public.

Strætó regrets that this cyber-attack has taken place and is working hard to complete the investigation and further information will appear here on Strætó’s website as the investigation progresses.

It should be noted that Strætó processes personal information as a so-called processor on behalf of other parties, so-called guarantors. Regarding the possible access of the attacker to that information, the responsible parties will notify the parties concerned of such security breach, as appropriate.

Further information on this security breach is provided by Strætó’s privacy representative, Sigurður Már Eggertsson, via the email personuvernd@straeto.is