Security3 distinct publishers3 min readPublished
Three attacks on one shared dependency since June, none attributed. Digdir keeps restoring service, and the attackers keep returning to the single queue everything else waits in.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Nobody had to touch Altinn or Skatteetaten to give their users login failures. Both posted notices about login problems and pointed at Digdir's status page [7]. Norwegian health services that authenticate through ID-porten were pulled in as well, with authorities warning about access to online pharmacies and the electronic prescription system [8]. Earlier attacks this summer reached Helsenorge, NAV and Skatteetaten by the same route [17]. ID-porten is the gateway to thousands of Norwegian government services and has more than 4.5 million users [6]. Fan-out on that scale makes the login layer the cheapest thing in the country to jam.
The interval is more instructive than any single outage. Digdir had normal operations back the day after the 3 August attack and said it would review the incident with Vivicta and other partners [12]. Twenty-one days later the same infrastructure was under attack again [2]. Whatever the review concluded, it did not change the answer to a bigger flood.
June is the tell for targeting. That attack went at ID-porten through Vivicta's network infrastructure and temporarily took MinID, Maskinporten, eInnsyn and eFormidling with it [13]. The concentration point was found on the first attempt, and there has been no reason to look elsewhere since.
The mitigation record is genuinely good, which is the trap. In securityaffairs' account, complete unavailability came only in short bursts, with the rest of the damage showing up as failed connections, slow responses and longer login times [11]. The Record put the attack at roughly 30 hours of varying intensity, still affecting some services on Tuesday morning [9], and BleepingComputer reported ID-porten and eSignering still partially inaccessible after most systems had been stabilised [10]. A day and a bit of degraded national authentication is not an outage anyone has to declare. It is also not a working service.
Digdir's disclosure is careful and, on what has been published, accurate: this is availability rather than intrusion, with no sign personal data was touched, and both NSM and Datatilsynet notified [5][14]. That accuracy is also why the incident generates so little friction for whoever is sending the traffic. There is nothing to prosecute and nothing exfiltrated, so the entire bill sits with Digdir, its operations provider and the agencies queued behind them.
Which leaves a measurement gap. Digdir reports these events service by service, stabilised or not, and that framing flatters the response every time. The number that would describe the actual damage is user-minutes of failed authentication across an account base of 4.5 million [6], and nobody has published it for June, for 3 August, or for this week. Until someone does, the case for putting one agency and one provider behind every citizen-facing login will keep being argued on cost per transaction, because that is the only column with figures in it.
Ranked by verification strength, evidence, and original report placement.
A DDoS attack began at 03:38 CEST on Monday, 24 August, targeting infrastructure operated by the Norwegian Digitalisation Agency (Digdir) together with its service provider Vivicta.
Digdir said this was the third DDoS attack directed at its solutions in a short period, following incidents in June and on 3 August.
Digdir director Frode Danielsen said the investigation showed no indication of a security breach affecting the organisation's systems or any compromise of personal data.
The incident disrupted 10 digital services used for verifying people's identities, logging into public services, exchanging data and documents between government agencies and businesses, accessing public records, and managing employee access.
There is currently no official attribution for the attack, although Norwegian media have speculated about potential Russian involvement.
It was not immediately clear who was behind the attack or whether the recent incidents were connected or part of a broader campaign targeting Norway.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named-agency statements corroborated by three independent outlets
The factual spine - onset time, targeted infrastructure, third-incident sequence, availability-only impact, regulator notification, absence of attribution - is reported consistently by three independent security outlets, with named on-record sources (Digdir director Frode Danielsen, press officer Are Kvistad) and a directly quoted Digdir statement. Weaknesses: several quantitative details (service count, 4.5M users, ~30 hours, 'two to three times larger') appear in only one outlet each, and there is no independent telemetry of attack volume.
Confirmed real-world service degradation across a national dependency
This is not a product uptake story; the measurable dimension is how far real systems were actually affected. Documented: 10 disrupted shared services, an identity gateway with more than 4.5 million users, downstream failure notices published by Altinn and Skatteetaten, health flows including pharmacies and e-prescriptions exposed, and ~30 hours of degradation with partial recovery. Held below higher values because impact was intermittent rather than total, most systems were stabilised, and no user-level outage counts or transaction-loss figures are disclosed.
Headline intensity slightly ahead of confirmed availability-only impact
Only mildly overstated. Headlines use 'massive' and 'knocks Norwegian public services offline' while the body text of all three sources confirms intermittent degradation with most systems stabilised, no intrusion and no personal-data compromise. Offsetting this, the reporting is disciplined where it matters most: every outlet explicitly labels the Russian-involvement talk as unattributed media speculation, and securityaffairs.com argues the systemic dependency point may in fact be understated relative to single-outage duration.
Heavy reliance on the affected agency's own account, plus one adjacent vendor promotion
Moderate distortion pressure. The reassurance claims - no breach, no personal-data compromise, systems stabilised, attack two-to-three times larger - originate almost entirely from Digdir, the organisation whose availability failed and which has an interest in framing the event as availability-only and well-handled; no independent forensic confirmation is offered. One source carries a promotional security-report block adjacent to the reporting. Mitigating factors: three independent outlets, on-record named officials, notification to NSM and Datatilsynet, and explicit refusal to endorse attribution.
High confidence on facts and impact, low on cause and actor
Confidence is strong for the event, timeline, affected estate and response posture: three independent outlets, direct agency statements and named officials converge without contradiction. It is deliberately capped because the attacker, motive and whether the three incidents form one campaign are all explicitly unresolved, several quantitative details are single-sourced, and the recovery state was still moving at publication time.
product
Mastercard's Australian outage came from a scheduled update, which is the part worth auditing1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026
1 article · August 25, 2026
1 article · August 25, 2026