Norway Restores Digital Services After Major DDoS Attack
Norway largely restored its shared digital-government services on August 27 after a multi-day distributed denial-of-service attack, while officials continued monitoring problems affecting some traffic from abroad and did not confirm who was responsible.
The attack began at 3:38 a.m. local time on Monday, August 24, according to the Norwegian Digitalisation Agency, or Digdir. The agency’s incident status page said the attack appeared to stop around 7:30 p.m. on Wednesday, August 26. In an August 27 update, Digdir said its solutions were operating normally in most respects, although some foreign traffic still faced disruptions.
Digdir characterized the incident as an attack on service availability rather than a confirmed intrusion into the systems. The agency said there was no indication that the attack had exposed personal data.
One attack, many public services
The disruption was broad because Digdir operates shared infrastructure used by government agencies, residents and businesses. The affected services included ID-porten, the Contact and Reservation Register, Maskinporten, MinID, eFormidling, ELMA, eInnsyn, Ansattporten and public-sector self-service systems.
Digdir also reported effects on Altinn, eSignering and the digital mailbox for residents. The services were not continuously offline: Digdir said they were often partially available, but some users experienced slow logins, instability or short periods of complete unavailability.
ID-porten was central to the disruption because it is a common gateway for authentication. Residents use it to log in to multiple public services, including through BankID and MinID. When that shared gateway is impaired, an attack aimed at common infrastructure can appear across many otherwise unrelated websites and applications.
Tax and customs workflows felt the effects
The outage also reached business systems that exchange information with the government. Norwegian Customs reported interruptions in Digitoll, its customs data-exchange service, as instability in Digdir’s systems affected the submission of information.
Norwegian Customs recorded a full stoppage in parts of the Digitoll API flow on August 24 and another interruption on August 25. Message traffic later resumed, but the agency warned that it would take time to clear the resulting queue. The customs status page listed Digitoll and its other major systems as operational on August 29.
That sequence illustrates why shared digital services matter beyond individual logins. A DDoS attack does not need to steal records to disrupt commerce. If authentication or data-exchange services become unreliable, agencies, carriers and businesses may need emergency procedures while delayed messages are processed.
Digdir calls it its largest attack
Digdir said the incident was the largest attack against its solutions that it had experienced. It also said the event was the third similar attack against its services in a short period.
The agency worked with its operating partner, Vivicta, to shield and stabilize the systems. Digdir said it had largely kept services available during the attack, although some functions experienced significant operational disruption. It notified Norway’s National Security Authority and Data Protection Authority and said it would conduct a detailed post-incident evaluation.
The recovery was staged rather than instantaneous. Digdir retained emergency measures after the apparent end of the attack and continued monitoring as traffic returned to normal.
A claim of responsibility is not proof of attribution
The pro-Russian hacker group Server Killers claimed responsibility in a Telegram post and said it had declared cyberwar on Norway after Oslo renewed security cooperation with Ukraine on August 23. Norway and Ukraine also announced further cooperation involving drone technology and other forms of modern warfare.
Norwegian officials had not publicly confirmed the group’s claim in the reporting available for this article. A public claim can indicate how an actor wants an incident understood, but it does not by itself establish technical responsibility or show that a government directed the operation.
Cybersecurity firm Truesec said it had no direct evidence that Server Killers was led by the Russian state. The firm noted similarities with other Russian-linked hacktivist activity, but that assessment is different from an authoritative finding about this specific attack.
For now, the confirmed facts are narrower: Norway’s shared digital infrastructure was hit by a sustained DDoS attack, public and business services were disrupted, and Digdir reported that its systems were largely operating normally by August 27. The identity and direction of the attackers remain unresolved.
What changed
The immediate service problem has eased, but Digdir’s planned review will help determine what changes follow. The incident showed both the value and the concentration risk of centralized authentication and data-exchange systems: they can simplify access and help contain ordinary breaches, while also giving an availability attack a wider reach.
For residents and businesses, recovery means that most shared services are available again, not that every dependent system was unaffected or that the investigation is complete.
Sources
- Norwegian Digitalisation Agency incident notice
- Digdir recovery status
- Associated Press report
- Norwegian Customs service status
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.