3 min read

Norway’s digital government services hit by repeated DDoS

A large DDoS attack disrupted Norway’s shared government infrastructure, including electronic IDs, signatures and public-service logins.

Norway’s digital government services hit by repeated DDoS

Image: BleepingComputer

A large distributed denial-of-service attack has disrupted Norway’s shared government digital infrastructure since 03:38 CEST on August 24, 2026, causing outages and degraded performance across services used by citizens, businesses and public agencies.

The attack is aimed at infrastructure operated by Norway’s Digitalisation Agency, known as Digdir, and its operations provider, Vivicta. Digdir runs common services that sit underneath several government functions: public-service logins, electronic identification, electronic signatures, secure digital mail, government forms, public-record access and data exchange between agencies.

Several services were fully unavailable for short periods. Digdir says many systems have since been stabilized, but ID-porten, the government login service, and eSignering, its electronic-signature service, remain partially inaccessible. Users may still see failed connections, slow responses and unusually long login times.

No evidence of a data breach

Digdir director Frode Danielsen said the agency’s investigation found no indication that its systems were breached or that personal data was compromised. A DDoS attack can make a service unreachable without giving an attacker access to the underlying accounts or databases.

Digdir has notified Norway’s National Security Authority and Data Protection Authority. The agency is publishing service updates through its official status page and a separate incident report.

The attack is the third DDoS incident targeting Digdir in a short period, following one in June and another on August 3, 2026. The repeated targeting suggests that restoring availability may require more than handling a single traffic surge, although the available reporting does not identify the attackers' infrastructure, methods or mitigation changes.

There is no official attribution. Norwegian media have speculated about possible Russian involvement, but neither Digdir nor the Norwegian authorities have publicly confirmed that connection. The lack of attribution also means there is no established link between this incident and the broad service outage that disrupted Russian banks, marketplaces, rail services and mobile connections on August 6.

Disruptions spread to dependent services

The effects are not limited to Digdir-operated services. Altinn, Norway’s central platform for communication between citizens, companies and government agencies, warned users about login failures and operational problems and directed them to Digdir’s status information. Norway’s tax administration, Skatteetaten, displayed a similar notice and told users to try again later.

That dependency creates a practical failure mode for public services: even when an agency’s own systems are functioning, authentication or data-exchange components shared across the government can prevent users from completing a transaction. In this case, the available information does not establish how much traffic the attackers generated, which endpoints were targeted, whether mitigation involved filtering, capacity changes or traffic rerouting, or when full availability will return.

Article image
Article image

The confirmed impact is availability rather than confidentiality. Users may continue to encounter failed logins and delayed responses while Digdir works through the incident; its status and incident pages provide restoration updates.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

/ Keep reading