Norway âs Digital Government Infrastructure Hit by a new DDoS Attack
Norway âs shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizens, businesses and public agencies. The incident began at 03:38 CEST on Monday, August 24, and targeted infrastructure operated by the Norwegian Digitalisation Agency, Digdir, together with its service provider Vivicta.
The timing matters because this isnât an isolated event. Digdir says itâs the third DDoS attack against its services in a short period, following incidents in June and on August 3.
âThe Norwegian Directorate for Digitalisation (Digdir) has been subjected to a denial of service attack (DDoS attack) that has been ongoing since 03:38 on the night of Monday, August 24.â reads the statement published by Digdir Agency. âThis is the third time in a short time that this type of attack has been directed at Digdirâs solutions. Digdir is working closely with our subcontractor Vivicta. NSM and the Norwegian Data Protection Authority have also been notified of the case.â
That status update refers to the test environment, but the underlying attack also affected production services. Digdir reported that several shared services became completely unavailable for short periods, while others remained accessible but suffered connection failures, slow responses and longer-than-usual login times.
Digdir operates several pieces of Norwayâs shared public-sector infrastructure. Among them are ID-porten, MinID, Maskinporten, eFormidling, eInnsyn, the Contact and Reservation Register, Ansattporten and other services used by government agencies and external applications.
That makes an attack on Digdir more significant than an ordinary website outage. When a shared authentication service goes down, the disruption can propagate to services that arenât themselves under attack.
Thatâs exactly what happened. Altinn, Norwayâs central platform for communication between citizens, businesses and government, was also affected, while other public services relying on ID-porten experienced login problems. Earlier attacks this summer produced similar effects, including disruption to access to Helsenorge, NAV and Skatteetaten.
The technical distinction is important: the attackers didnât need to break into every downstream service. They could create disruption simply by overwhelming a shared dependency.
And thatâs often the uncomfortable reality of modern public infrastructure. The weakest point isnât necessarily the service citizens see on their screens. It can be the common authentication, messaging or data-exchange layer underneath it.
Digdir has stressed that the incident is about availability, not evidence of a successful intrusion. The agency also says it has found no indication that personal data was exposed. Digdir has notified Norwayâs National Security Authority, NSM, and the Data Protection Authority, Datatilsynet, as part of its response.
âThere are no indications that the attack has led to a security breach or that personal data has been compromised, says Director Frode Danielsen at Digdir.â continues the statement.
That distinction deserves attention because cyberattack doesnât automatically mean âdata theftâ. In this case, the confirmed impact is service disruption, while there is currently no evidence that attackers compromised Digdirâs systems or accessed personal information.
The operational consequences are still serious. Public-sector users may see failed connections, slow responses or authentication problems even though the underlying applications themselves havenât been compromised.
The June incident already demonstrated how much disruption a DDoS attack against Digdirâs infrastructure can cause. That attack targeted ID-porten through Vivictaâs network infrastructure and temporarily affected services including ID-porten, MinID, Maskinporten, eInnsyn and eFormidling.
Another attack followed on August 3. Digdir restored normal operations the following day, but the agency said the incident had again affected several shared services and that it would review the event together with Vivicta and other partners.
Now thereâs a third incident. That repetition is more interesting from a defensive perspective than the raw duration of any single outage.
Digdir and Vivicta are clearly able to mitigate the attacks and restore services. The harder question is whether repeated attacks against the same shared infrastructure can keep generating enough operational friction to become a recurring problem for the wider public sector.
This is where DDoS stops being just a bandwidth problem. A sufficiently persistent campaign can force defenders to keep changing traffic controls, filtering rules and protection measures, while legitimate users continue to depend on the same infrastructure.
Digdirâs own status updates show that dynamic clearly. On August 24, the agency first reported improvement, then said several solutions were completely down, followed by further stabilization efforts.
There is currently no official attribution for the attacks. Norwegian media have raised the possibility of Russian involvement, but that remains speculation rather than an established finding.
That distinction matters. A DDoS campaign can be politically motivated, financially motivated, conducted for disruption or simply intended to demonstrate capability. Without technical evidence and an official attribution process, assigning responsibility to a particular state or group would be premature.
What is established is the target and the effect. The attacks repeatedly hit infrastructure that sits underneath a large number of Norwegian digital public services.
Thatâs enough to make the incidents strategically relevant without adding an attribution story that the evidence doesnât yet support.
The Norwegian case is also a useful reminder that cybersecurity isnât limited to confidentiality and integrity. Availability is a security property too, particularly when the affected systems provide national digital services.
A compromised database is an obvious security incident. An authentication service that repeatedly becomes unavailable can create a different kind of problem: citizens canât access services, businesses canât complete procedures and government agencies may struggle to perform routine operations.
Digdir says its services have largely stabilized, although some disruptions remain. As of the latest incident updates, ID-porten still had limitations, eSignering remained unavailable because of those ID-porten restrictions, and some users were still reporting connection problems or increased response times with Maskinporten.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs â hacking, newsletter)
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.