Massive DDoS attack disrupts Norway’s government digital services

Norway’s Government Digital Services Brought Down by Massive DDoS Attack

A massive distributed denial-of-service (DDoS) attack has struck Norway’s shared government digital infrastructure, disrupting services used by the public sector. The attack started on Monday at 03:38 CEST and targeted the infrastructure supporting various government services operated by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider, Vivicta.

Digdir operates Norway’s shared digital government infrastructure, including public-service logins, electronic IDs and signatures, secure digital mail, government forms, public-record access, and data exchange between agencies. As a result of the attack, users have encountered errors such as failed connections, slow server responses, and unusually long login times. Some services, like ID-porten and eSignering, remain partially inaccessible.

The investigation into the incident has shown no indication of a security breach affecting Digdir’s systems or any compromise of personal data. However, this is the third DDoS attack targeting Digdir in recent weeks, following incidents in June and August 3. The Norwegian National Security Authority (NSM) and the Norwegian Data Protection Authority (Datatilsynet) have been notified accordingly.

While there is currently no official attribution for the attack, Norwegian media has speculated about potential Russian involvement. What’s clear, however, is that this type of attack can have far-reaching consequences, not just for the targeted organization but also for services that rely on it. For example, Altinn, Norway’s central digital platform for communication between citizens, businesses, and government agencies, has published a warning about login issues and operational problems.

The fact that DDoS attacks like this one are becoming more frequent is a concern for governments and organizations worldwide. The attackers’ tactics and techniques can be sophisticated, making it essential to have robust security measures in place. While prevention scores can provide an initial layer of protection, they often drop sharply once attackers gain access using valid credentials.

In practical terms, what does this mean for users? First, it’s essential to stay informed about the status of government services. Digdir has published updates on its operating status page and incident report page. Second, when encountering errors or login issues, don’t panic – simply try again later. Finally, consider implementing additional security measures on your own devices and accounts, such as multi-factor authentication and regular software updates.

As we continue to rely more heavily on digital services, it’s crucial that governments and organizations invest in robust cybersecurity measures to prevent and mitigate the impact of DDoS attacks like this one. By staying vigilant and proactive, we can minimize the disruption caused by these types of incidents and ensure that our online interactions remain secure and reliable.


Source: Bleeping Computer — 2026-08-25