A massive distributed denial-of-service campaign has disrupted Norway’s shared government digital infrastructure, intermittently knocking key public services offline and degrading access for citizens since early Monday.[1][2][9]
The Norwegian Digitalisation Agency (Digdir) said the attack began around 03:38 CEST on Monday and targeted infrastructure operated by its IT partner Vivicta, which hosts a suite of common services used across the public sector.[1][2] Core platforms including the national login gateway ID-porten, electronic signing service eSignering, and data-sharing and records services such as Altinn, MinID and E-innsyn experienced login failures and instability as traffic surged.[1][2][3][6] By mid-week, most systems had been stabilized, but Digdir warned that some services remained partially inaccessible and that residual disruptions could persist.[1][2][11]
Officials have described the event as the largest attack ever recorded against Digdir’s solutions, with traffic volumes fluctuating over more than 30 hours as attackers shifted intensity and tactics.[2][6] The incident marks at least the third significant DDoS event against the agency’s shared services in roughly nine weeks, following earlier campaigns in June and late August that also targeted Vivicta-hosted infrastructure and caused hours-long outages for ID-porten and related platforms.[3][6][10][11]
A pro-Russian hacker group calling itself Server Killers has claimed responsibility for the operation, posting a message on Telegram declaring “cyber war” on Norway after the country renewed a multi-year security cooperation and financial support package for Ukraine.[4] Digdir and Norwegian authorities have acknowledged the claim but stopped short of formal attribution, emphasizing that, so far, the attack appears limited to denial-of-service traffic and that there is no evidence of unauthorized access to sensitive data or compromise of backend systems.[4][9]
The campaign relies on flooding government-facing infrastructure with junk internet traffic, overwhelming capacity and preventing legitimate users from connecting—a classic volumetric DDoS technique rather than an exploit of a specific software vulnerability or CVE.[1][2][6] That distinction matters for defenders: mitigation hinges on capacity and traffic management, including upstream filtering, rate limiting, and rapid rerouting, rather than patching a particular service.[1][2] Norwegian officials noted that critical services were kept running “practically all the time,” but with degraded performance and intermittent login problems, underscoring how modern DDoS attacks can be disruptive even when availability is only partially impacted.[4][5]
For public agencies and businesses that depend on Digdir’s platforms for authentication, data exchange and records access, the incident is a reminder to plan for outages in shared infrastructure and to maintain fallback processes for citizen login and document workflows.[2][9] Organizations are being urged to monitor Digdir’s status communications, validate that their own upstream providers have robust DDoS protection, and review contingency arrangements so essential services can continue if ID-porten or related gateways become unstable. While this week’s attack has not been linked to a specific vulnerability, its scale and repetition highlight that government-wide digital platforms are increasingly attractive targets for politically motivated actors testing national resilience.[1][2][4][6]
References
- Massive DDoS attack disrupts Norway’s government digital …
- Large DDoS attack knocks Norwegian public services offline
- Norway ID-Porten Outage: Mandatory Login Gateway Goes Down …
- Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services
- State agency under cyber attack | Norway’s News in English
- Cyberattack on government agency in Norway continues for third day
- Norwegian public services targeted by cyberattack
- Attacks in Norway – FM CyberSecurity
- DDoS against Norwegian government IT infrastructure – status
