A large-scale distributed denial-of-service (DDoS) attack has been targeting Norway's shared government digital infrastructure starting Monday. The attack has disrupted services used by the public sector, affecting the availability of government digital services for citizens and public agencies. The attack targeted centralized infrastructure, meaning multiple government services were simultaneously impacted. Norwegian authorities are aware of the incident and are working to mitigate the disruption. The event highlights the vulnerability of centralized government digital infrastructure to volumetric network attacks. No specific threat actor has been attributed in the article excerpt, though DDoS attacks on government infrastructure are often politically motivated.
A large-scale Distributed Denial-of-Service (DDoS) attack began at 03:38 CEST on Monday, targeting the shared digital government infrastructure of Norway's Digitaliseringsdirektoratet (Digdir) and its operations provider Vivicta. The attack caused complete unavailability of several services for short periods, with some services such as ID-porten and eSignering remaining partially inaccessible after partial stabilization. Affected users experienced failed connections, slow server responses, and unusually long login times. The attack caused cascading disruptions to dependent services including Altinn (citizen-government communication platform) and Skatteetaten (tax administration). No security breach or compromise of personal data was detected. This is the third DDoS attack targeting Digdir in recent months, following incidents in June 2026 and on August 3, 2026. Norwegian media have speculated about potential Russian involvement, though no official attribution has been made.
1. Monitor Digdir's official service status page at status.digdir.no for real-time availability updates. 2. Check the incident report page at testmiljo.status.digdir.no for official updates from Norway's Directorate for Digitization. 3. Users experiencing login failures on affected services such as ID-porten, Altinn, or Skatteetaten should retry later as services are being progressively restored. 4. Organizations relying on Digdir infrastructure should implement fallback procedures for critical government-dependent workflows. 5. The Norwegian National Security Authority (NSM) and the Norwegian Data Protection Authority (Datatilsynet) have been notified; relevant organizations should coordinate with these bodies. 6. Organizations operating shared government digital infrastructure should review DDoS mitigation capabilities given this is the third attack in approximately three months. 7. Implement traffic scrubbing, rate limiting, and CDN-based DDoS protection for critical public-facing services.