What did a data breach teach Asfalttikallio, Finland’s second‑largest asphalt contractor? How was the incident handled together with Elisa’s cyber security team, and what happened afterwards? Asfalttikallio’s Technical Director Ville Hirvilammi shares the experience.
The breach of Asfalttikallio’s email accounts occurred just before Midsummer – through a very human mistake.
“One of our employees received what appeared to be a legitimate request for quotation from a real customer and entered their credentials to access the materials. However, the message was not genuine – it was a phishing attempt, and the attackers obtained the email account credentials,” explains Ville Hirvilammi, Technical Director at Asfalttikallio.
The breach came to light when Hirvilammi himself first received a suspicious email from one of Asfalttikallio’s own employees. Shortly after, a contact person from a major customer called to say they were receiving strange messages from Asfalttikallio and had placed the company’s emails on a blacklist.
“There was nothing else to do but humbly say that we would investigate the matter and call back once it was fixed. It was extremely embarrassing,” Hirvilammi recalls.
This leads to the first key lesson Hirvilammi learned: If a data breach occurs, be open, humble and act fast.
“I immediately called our IT specialists, and they had already taken action – blocking the compromised user accounts and resetting passwords. But we couldn’t be completely sure what else might have happened.”
Transparency pays off, as customers can also help in cleaning up the aftermath of a breach.
“One customer gave me valuable advice to immediately report the breach to the Finnish National Cyber Security Centre and the Data Protection Ombudsman. In the rush, I wouldn’t have thought of that myself. We received excellent guidance from the Cyber Security Centre,” Hirvilammi says.
A thorough investigation uncovers what really happened
Asfalttikallio also quickly asked for help from Elisa’s cyber security team to investigate the breach.
“After the initial response, we decided to investigate the incident thoroughly so we could truly understand what had happened and what we could learn from it to ensure it wouldn’t happen again.”
The investigation revealed that a total of seven email accounts had been compromised and that the attackers were searching for billing information to carry out invoice fraud.
“We were lucky that this wasn’t a more serious case involving data encryption and ransom demands. In total, seven user accounts had been under the attackers’ control – some for only minutes, others for several days. It was frightening, but it also taught us a great deal,” Hirvilammi says.
In addition to the breach investigation, Elisa conducted a security audit for Asfalttikallio.
“I can recommend it to everyone. It provides a clear picture of the current state of security and highlights areas that can and should be improved. Even though we were hit by a breach, our overall security level was actually quite good,” Hirvilammi notes.
This brings us to the second key lesson Hirvilammi learned: Accept all help and trust the professionals.
“ICT and cyber security are not our core business. In these areas, it makes sense for us to rely on top-tier professionals.”
Why did Asfalttikallio become a victim of a data breach?
“I believe there are many companies like ours in Finland. We have focused on our core business – producing asphalt, surviving intense competition and growing. We had also completed two major acquisitions, and in such situations, IT or cyber security is not necessarily at the top of the priority list,” Hirvilammi explains. At its peak, Asfalttikallio employs over 600 people annually. In 2021–2022, the company acquired the asphalt businesses of both NCC and Skanska, tripling its size.
Following the incident, the security of the company’s IT environment has been comprehensively improved, with particular emphasis on personnel training in cooperation with Elisa’s cyber security team.
“Human factors are the biggest vulnerability. We have significantly increased security training for our staff, and it is now provided on a regular basis.”
Cyber security as an integral part of system development
“Digitalisation across the industry is lagging behind other sectors, and we intend to make a major leap forward. Cyber security must be an integral part of all system development and digitalisation efforts, because at the same time the attack surface grows,” Hirvilammi explains.
One example is the advanced weighing technology at asphalt plants, which measures both outgoing asphalt and incoming waste, with data transferred automatically over the network.
“Because these advanced scales are connected to the internet, their cyber security must be at an excellent level,” Hirvilammi says.
Hirvilammi is highly satisfied with the expertise and support provided by Elisa’s cyber security specialists.
“Elisa’s approach has been extremely professional. I feel that we are currently in very good hands when it comes to cyber security.”
Learn more about Elisa’s Cyber Security Services
Photo: Asfalttikallio
Related articles
How Good Collaboration Helps Atria to Improve Cyber Security
How Caruna Keeps Cyber Criminals Out of the Power Grid
At Mehiläinen, Continuous Cybersecurity Development Is at the Core of Operations
Avainsanat





