A massive distributed denial-of-service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, affecting online services used by public agencies, businesses, and citizens.
The attack began at 03:38 CET on Monday and targeted infrastructure supporting services operated by Norway’s Agency for Digital Government, known as Digitaliseringsdirektoratet or Digdir, along with its operational provider, Vivicta.
Digdir manages Norway’s shared digital government infrastructure, including public-service logins, electronic identification and signatures, secure digital mail, government forms, access to public records, and data exchange between government agencies.
In an announcement released earlier today, Digdir said some government digital services were completely unavailable for a brief period.
Many affected systems have since stabilized, but services including ID-porten and electronic signatures remain partially inaccessible.
Users may continue to encounter connection failures, slow server responses, and unusually long login times while the DDoS attack continues to affect service availability.
For the latest updates on Digdir services, visit the Digdir service status page or the incident report page.
Digdir Director Frode Danielsen said the investigation has found no evidence that the incident resulted in a security breach or compromised personal data.
Danielsen said this is the third DDoS attack targeting Digdir in recent months, following previous incidents in June and on August 3.
The Norwegian National Security Authority (NSM) and the Norwegian Data Protection Authority (Datatilsynet) have been notified of the incident.
No official attribution has been announced. However, Norwegian media have reported speculation about possible Russian involvement.
Government services that depend on Digdir but were not directly targeted may also experience outages and login problems.
Altinn, Norway’s central digital platform for communication between citizens, businesses, and government agencies, has issued a warning directing users to Digdir’s status page for information about login and service disruptions.
Norway’s Tax Administration, Skatteetaten, has also reported login issues and advised users to try again later.
An organization’s prevention score does not show what happens after an attacker gains initial access. When attackers use valid credentials, defensive controls can become significantly less effective.
Blue Report 2026 evaluates defensive techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




