
A major distributed denial of service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, affecting services used by the public sector.
The attack began at 03.38 CEST on Monday and targeted services supporting the infrastructure run by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider, Vivicta.
Digdir manages Norway’s shared digital government infrastructure, including login to public services, electronic IDs and signatures, secure digital mail, government forms, access to public records and inter-agency data exchange.
In a statement released earlier today, the organization said several services were completely unavailable for short periods.
The agency says many affected systems have now been stabilized, although some services, such as ID-porten and eSignering, remain partially unavailable.
As a result of the attack, users may experience errors such as failed connections, slow server responses, and unusually long login times.
For live updates on the availability of Digdir services people can consult service status page as well as of incident report page with updates from the Norwegian Directorate for Digitization.
Directed by Digdir Frode Danielsen says the incident investigation showed no indication of a security breach affecting the organization’s systems or compromising personal data.
Danielsen added that this is the third DDoS attack targeting Digdir recently, following one in June and another on August 3.
The Norwegian National Security Authority (NSM) and the Norwegian Data Protection Authority (Datatilsynet) have been notified accordingly.
There is currently no official attribution for the attack, although Norwegian media are speculating potential Russian involvement.
Meanwhile, services that rely on Digdir but are not directly targeted are also experiencing disruption.
Altinn, Norway’s central digital platform for communication between citizens, businesses and government agencies, post a warning regarding login issues and operational issues, link to Digdir status page.
Skatteetaten, Norway’s tax administration agency, displays a similar notification about problems logging into its website and urges users to try again later.
Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.
The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

