Skip to content

SecurityReports disagree4 publishers3 min readPublished Updated

Norway's shared login layer failed for the third time since June, and nobody broke in

Three attacks on one shared dependency since June, none attributed. Digdir keeps restoring service, and the attackers keep returning to the single queue everything else waits in.

The Watch · Security desk

How we use AISend a correction

What happened

  • The DDoS started at 03:38 CEST on Monday 24 August against infrastructure operated by Norway's digitalisation agency Digdir and its provider Vivicta.
  • Digdir said it was the third such attack on its solutions in a short period, after incidents in June and on 3 August.
  • Ten shared services were disrupted, covering identity checks, public-service logins, inter-agency data exchange, public records and employee access.
  • Digdir press officer Are Kvistad told NRK the attack was two to three times larger than the previous one.
  • Director Frode Danielsen said there was no indication of a breach of Digdir's systems or of any personal data being compromised.

Why it matters

  • exposure Agencies that were never touched inherit an outage they cannot see, mitigate or explain, and their users blame the tax office for traffic aimed at someone else's authentication layer.
  • constraint With no intrusion to investigate, the response has nowhere to go except absorbing more traffic at the same choke point that failed the last two times.
  • precedent An unattributed tactic that keeps working, and that scaled up rather than down on its third outing, is an argument for a fourth attempt rather than against one.
  • contradiction Norwegian media point at Russia while no attribution exists and Digdir cannot say the three incidents are linked; one campaign and three opportunists call for very different defences.

Nobody had to touch Altinn or Skatteetaten to give their users login failures. Both posted notices about login problems and pointed at Digdir's status page [4]. Norwegian health services that authenticate through ID-porten were pulled in as well, with authorities warning about access to online pharmacies and the electronic prescription system [15]. Earlier attacks this summer reached Helsenorge, NAV and Skatteetaten by the same route [10]. ID-porten is the gateway to thousands of Norwegian government services and has more than 4.5 million users [14]. Fan-out on that scale makes the login layer the cheapest thing in the country to jam.

The interval is more instructive than any single outage. Digdir had normal operations back the day after the 3 August attack and said it would review the incident with Vivicta and other partners [16]. Twenty-one days later the same infrastructure was under attack again [18]. Whatever the review concluded, it did not change the answer to a bigger flood.

June is the tell for targeting. That attack went at ID-porten through Vivicta's network infrastructure and temporarily took MinID, Maskinporten, eInnsyn and eFormidling with it [17]. The concentration point was found on the first attempt, and there has been no reason to look elsewhere since.

The mitigation record is genuinely good, which is the trap. In securityaffairs' account, complete unavailability came only in short bursts, with the rest of the damage showing up as failed connections, slow responses and longer login times [9]. The Record put the attack at roughly 30 hours of varying intensity, still affecting some services on Tuesday morning [7], and BleepingComputer reported ID-porten and eSignering still partially inaccessible after most systems had been stabilised [8]. A day and a bit of degraded national authentication is not an outage anyone has to declare. It is also not a working service.

Digdir's disclosure is careful and, on what has been published, accurate: this is availability rather than intrusion, with no sign personal data was touched, and both NSM and Datatilsynet notified [3][11]. That accuracy is also why the incident generates so little friction for whoever is sending the traffic. There is nothing to prosecute and nothing exfiltrated, so the entire bill sits with Digdir, its operations provider and the agencies queued behind them.

Which leaves a measurement gap. Digdir reports these events service by service, stabilised or not, and that framing flatters the response every time. The number that would describe the actual damage is user-minutes of failed authentication across an account base of 4.5 million [14], and nobody has published it for June, for 3 August, or for this week. Until someone does, the case for putting one agency and one provider behind every citizen-facing login will keep being argued on cost per transaction, because that is the only column with figures in it.

What to watch

  • Whether NSM ties the June, 3 August and 24 August incidents to a single actor, or an attribution is made public.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence72
Adoption80
Hype gap+15
Incentives35
Confidence70

Perspective Coverage

4 publishers
Builder
Builder 28%
Operator
Operator 62%
Investor
Investor 10%
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    A DDoS attack began at 03:38 CEST on Monday, 24 August, targeting infrastructure operated by the Norwegian Digitalisation Agency (Digdir) together with its service provider Vivicta.

  2. [2]

    Digdir said this was the third DDoS attack directed at its solutions in a short period, following incidents in June and on 3 August.

  3. [3]

    Digdir director Frode Danielsen said the investigation showed no indication of a security breach affecting the organisation's systems or any compromise of personal data.

    ReportedSupportedSource: Frode Danielsen, Digdir4 sources— create a free account to open themView cited source

Sources

4 independent publishers whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · August 25, 2026

    Massive DDoS attack disrupts Norway’s government digital services
  2. infosecurity-magazine.com

    1 article · August 26, 2026

    DDoS Attack Hits Norwegian Government Services
  3. securityaffairs.com

    1 article · August 25, 2026

    Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack
  4. therecord.media

    1 article · August 25, 2026

    Large DDoS attack knocks Norwegian public services offline

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories