A massive distributed denial-of-service (DDoS) attack has crippled Norway’s shared government digital services since Monday, leaving a trail of disruption and speculation in its wake. The assault on the Norwegian Digitalization Agency’s (Digdir) infrastructure has targeted public-facing services, forcing users to endure frustrating errors, slow server responses, and unusually long login times.
The impact is widespread, with many services operated by Digdir and its partners experiencing outages or reduced functionality. ID-porten, a digital identification system used by millions of Norwegians, remains partially inaccessible, while eSignering, an electronic signature platform, is still affected. These disruptions have not only inconvenienced citizens but also businesses that rely on the services, such as Altinn, Norway’s central digital platform for communication between government agencies and their constituents.
The investigation into the attack, led by Digdir director Frode Danielsen, has found no evidence of a security breach or compromise of personal data. However, this is not the first time Digdir has been targeted: two previous DDoS attacks occurred in June and August 3. The Norwegian National Security Authority (NSM) and the Norwegian Data Protection Authority (Datatilsynet) have been notified, but so far, there is no official attribution for the attack.
The lack of transparency surrounding the incident highlights a worrying trend: as cyberattacks become more sophisticated, they often evade detection until it’s too late. Once attackers gain valid credentials, prevention scores plummet, leaving organizations struggling to contain the damage. This phenomenon is evident in the Blue Report 2026, which measured defenses technique by technique across 338 million simulations run in customer production environments.
The impact of this attack extends beyond Norway’s borders, as services that rely on Digdir but are not directly targeted also experience disruptions. Skatteetaten, Norway’s tax administration agency, has displayed a notice about login issues on its website, urging users to try again later. The incident serves as a stark reminder of the importance of robust cybersecurity measures and the need for organizations to stay vigilant in the face of increasingly sophisticated threats.
As we navigate this complex landscape, it’s essential to remember that DDoS attacks are not just random events but often strategically targeted at critical infrastructure. In light of this attack, users should exercise caution when accessing online services, especially those related to government and public administration. For organizations, this incident underscores the importance of investing in advanced threat detection and mitigation tools, as well as maintaining open communication channels with affected stakeholders.
In conclusion, the massive DDoS attack on Norway’s government digital services is a stark reminder of the evolving nature of cyber threats. As we move forward, it’s essential to prioritize cybersecurity, foster collaboration between organizations, and invest in cutting-edge technologies that can detect and mitigate these types of attacks. By doing so, we can reduce the impact of future incidents and protect our critical infrastructure from the ever-present threat of DDoS attacks.
Source: Bleeping Computer — 2026-08-25