
Sustained DDoS Attack Hits Norway's Government Login Systems

Norway's shared government digital infrastructure has been running degraded since the early hours of Monday. Attackers began flooding it with traffic at 03:38 CEST. The DDoS attack against Norway's public-sector login layer targeted systems run by Vivicta, the operations partner behind the Norwegian Digitalisation Agency, known as Digdir. Ten shared services either dropped offline or slowed to a crawl, and the effects reached well past the original target.
Digdir director Frode Danielsen confirmed that the agency found no evidence of a security breach or exposure of personal data. Attackers went after availability rather than access. The practical result was still severe. Millions of people and businesses lost their route into public services for large parts of two working days.
Which Services Went Down
The DDoS attack on Norway's shared infrastructure began overnight into Monday 24 August. It hit ID-porten, MinID, Maskinporten, Ansattporten, eFormidling, eInnsyn, the Contact and Reservation Register and the ELMA self-service solution. Altinn, eSignering and Digital postkasse also failed, because each of them depends on ID-porten for authentication.
Some of those services disappeared completely for short periods. For most of the outage they stayed partially available, but users hit failed connections, sluggish server responses and login attempts that took far longer than normal.
Digdir worked alongside Vivicta throughout on measures to shield the affected solutions. By midday Tuesday the agency described its services as stabilised, while confirming that several still suffered operational disruption and that the work would continue until the situation ended.
How the DDoS Attack Spread Across Norway's Public Sector
Digdir runs the plumbing beneath Norwegian digital government: public-service logins, electronic IDs and signatures, secure digital mail, government forms, public-record access, and data exchange between agencies. Anything that needs to verify a citizen or a business passes through that layer.
So the damage from the DDoS attack travelled across Norway's public sector. Skatteetaten, the tax administration, posted a notice about login problems and asked users to try again later. Altinn, the central platform connecting citizens, businesses and public bodies, published a similar warning and pointed people to Digdir's status page.
Norsk Helsenett reported trouble as well. HelseID logins routed through ID-porten failed, which disrupted online pharmacies and authentication against the national prescription service. Nobody attacked those systems directly. They broke because the service they depend on broke.
An Availability Problem With No Sign of Intrusion
Danielsen was direct about the distinction. The purpose of this kind of operation is to hit availability, and Digdir found no indication that anyone reached personal data or compromised its solutions. The agency notified the Norwegian National Security Authority and Datatilsynet, the data protection regulator, as part of its response.
That framing deserves attention, because the word cyberattack sends most readers straight to data theft. This DDoS attack against Norway produced no known breach and still halted ordinary business across the country. Prescriptions, tax filings and benefit applications all waited.
There is no analogue fallback for a country that has moved this much of public life online. When the login gateway fails, the queue simply grows until the traffic stops.
The Third DDoS Attack on Norway's Digital Government Since June
This was at least the third denial-of-service campaign against Digdir infrastructure in nine weeks. The earlier rounds landed in late June and in early August, and the August incident kept public services degraded for more than a full day.
Press officer Are Kvistad said the current flood ran two to three times larger than the previous one. The attack also changed shape as it went. Conditions improved through Monday morning, then deteriorated again in the evening, with the traffic resuming around 17:15 after a brief pause.
Repeat targeting at rising volume points to an actor with persistent capacity and a specific interest in the same victim. Cheap booter services make that kind of sustained pressure affordable. Attacks above 1 Tbps grew fivefold between the first and second quarters of this year.
Attribution Remains Open
Nobody has claimed the Norway DDoS attack, and no authority has named a suspect. Norwegian media have speculated about Russian involvement, but Digdir has declined to endorse any theory and says it has no indication of who is responsible.
Context does exist. Norway sits on NATO's northern flank, supplies a large share of Europe's gas, and backs Ukraine openly. NSM's national risk assessment in February warned that Russian intelligence services might attempt sabotage against Norwegian targets during 2026. The same assessment flagged dependence on external suppliers as a vulnerability in its own right.
Pro-Russian hacktivist groups have run comparable campaigns against European governments for years, coordinating through Telegram channels and volunteer participation platforms. Reading this incident against that backdrop is reasonable. Treating the backdrop as proof is not.
What Shared Infrastructure Operators Should Take From This
The lesson from this DDoS attack on Norway travels well beyond government IT. Consolidating authentication into one shared layer delivers real efficiency. It also creates a single point at which a traffic flood can suspend unrelated operations across dozens of organisations.
Three questions follow for anyone in a similar position. Can your upstream provider absorb volumetric traffic rather than blackholing an address range and calling that mitigation? Does a fallback path exist for when the shared authentication service fails? Have you mapped which of your own services would stop if a supplier you do not control goes dark?
Digdir kept most solutions partially available through an assault several times larger than anything it had faced before, which counts as a creditable outcome. Yet the agency also spent two days fighting the same battle it fought in June and again in August.
Subscribe to receive the latest blog posts to your inbox every week.