SecurityReports disagree4 publishers3 min readPublished Updated
Norway's shared login layer failed for the third time since June, and nobody broke in
Three attacks on one shared dependency since June, none attributed. Digdir keeps restoring service, and the attackers keep returning to the single queue everything else waits in.
The Watch · Security desk
What happened
- The DDoS started at 03:38 CEST on Monday 24 August against infrastructure operated by Norway's digitalisation agency Digdir and its provider Vivicta.
- Digdir said it was the third such attack on its solutions in a short period, after incidents in June and on 3 August.
- Ten shared services were disrupted, covering identity checks, public-service logins, inter-agency data exchange, public records and employee access.
- Digdir press officer Are Kvistad told NRK the attack was two to three times larger than the previous one.
- Director Frode Danielsen said there was no indication of a breach of Digdir's systems or of any personal data being compromised.
Why it matters
- exposure Agencies that were never touched inherit an outage they cannot see, mitigate or explain, and their users blame the tax office for traffic aimed at someone else's authentication layer.
- constraint With no intrusion to investigate, the response has nowhere to go except absorbing more traffic at the same choke point that failed the last two times.
- precedent An unattributed tactic that keeps working, and that scaled up rather than down on its third outing, is an argument for a fourth attempt rather than against one.
- contradiction Norwegian media point at Russia while no attribution exists and Digdir cannot say the three incidents are linked; one campaign and three opportunists call for very different defences.
Nobody had to touch Altinn or Skatteetaten to give their users login failures. Both posted notices about login problems and pointed at Digdir's status page [4]. Norwegian health services that authenticate through ID-porten were pulled in as well, with authorities warning about access to online pharmacies and the electronic prescription system [15]. Earlier attacks this summer reached Helsenorge, NAV and Skatteetaten by the same route [10]. ID-porten is the gateway to thousands of Norwegian government services and has more than 4.5 million users [14]. Fan-out on that scale makes the login layer the cheapest thing in the country to jam.
The interval is more instructive than any single outage. Digdir had normal operations back the day after the 3 August attack and said it would review the incident with Vivicta and other partners [16]. Twenty-one days later the same infrastructure was under attack again [18]. Whatever the review concluded, it did not change the answer to a bigger flood.
June is the tell for targeting. That attack went at ID-porten through Vivicta's network infrastructure and temporarily took MinID, Maskinporten, eInnsyn and eFormidling with it [17]. The concentration point was found on the first attempt, and there has been no reason to look elsewhere since.
The mitigation record is genuinely good, which is the trap. In securityaffairs' account, complete unavailability came only in short bursts, with the rest of the damage showing up as failed connections, slow responses and longer login times [9]. The Record put the attack at roughly 30 hours of varying intensity, still affecting some services on Tuesday morning [7], and BleepingComputer reported ID-porten and eSignering still partially inaccessible after most systems had been stabilised [8]. A day and a bit of degraded national authentication is not an outage anyone has to declare. It is also not a working service.
Digdir's disclosure is careful and, on what has been published, accurate: this is availability rather than intrusion, with no sign personal data was touched, and both NSM and Datatilsynet notified [3][11]. That accuracy is also why the incident generates so little friction for whoever is sending the traffic. There is nothing to prosecute and nothing exfiltrated, so the entire bill sits with Digdir, its operations provider and the agencies queued behind them.
Which leaves a measurement gap. Digdir reports these events service by service, stabilised or not, and that framing flatters the response every time. The number that would describe the actual damage is user-minutes of failed authentication across an account base of 4.5 million [14], and nobody has published it for June, for 3 August, or for this week. Until someone does, the case for putting one agency and one provider behind every citizen-facing login will keep being argued on cost per transaction, because that is the only column with figures in it.
What to watch
- Whether NSM ties the June, 3 August and 24 August incidents to a single actor, or an attribution is made public.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence72
- Adoption80
- Hype gap+15
- Incentives35
- Confidence70
Perspective Coverage
4 publishers- Builder
- Builder 28%
- Operator
- Operator 62%
- Investor
- Investor 10%
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A DDoS attack began at 03:38 CEST on Monday, 24 August, targeting infrastructure operated by the Norwegian Digitalisation Agency (Digdir) together with its service provider Vivicta.
- [2]
Digdir said this was the third DDoS attack directed at its solutions in a short period, following incidents in June and on 3 August.
ReportedSupportedSource: Digdir statement4 sources— create a free account to open themView cited source - [3]
Digdir director Frode Danielsen said the investigation showed no indication of a security breach affecting the organisation's systems or any compromise of personal data.
ReportedSupportedSource: Frode Danielsen, Digdir4 sources— create a free account to open themView cited source - [4]
Altinn published a warning about login issues and operational problems linking to Digdir's status page, and tax administration agency Skatteetaten displayed a similar notice urging users to try again later.
- [5]
There is currently no official attribution for the attack, although Norwegian media have speculated about potential Russian involvement.
- [6]
It was not immediately clear who was behind the attack or whether the recent incidents were connected or part of a broader campaign targeting Norway.
- [7]
The attack continued for around 30 hours at varying levels of intensity and, as of Tuesday morning, was still affecting some services according to Digdir's status page.
- [8]
Digdir said many affected systems had been stabilised, although some services including ID-porten and eSignering remained partially inaccessible.
- [9]
Digdir reported that several shared services became completely unavailable for short periods, while others remained accessible but suffered connection failures, slow responses and longer-than-usual login times.
- [10]
Earlier attacks this summer produced similar knock-on effects, including disruption to access to Helsenorge, NAV and Skatteetaten.
- [11]
Digdir notified Norway's National Security Authority (NSM) and the Data Protection Authority (Datatilsynet) as part of its response.
- [12]
Three DDoS incidents hit the same shared government infrastructure within a span of under three months, from June to 24 August.
- [13]
Digdir press officer Are Kvistad told Norwegian broadcaster NRK that this latest attack, ongoing for a day, is two to three times larger than the previous one.
- [14]
ID-porten is a digital identification service that acts as a gateway to thousands of Norwegian government services, allows identity verification via services such as BankID and MinID, and has more than 4.5 million users.
- [15]
The disruption affected parts of Norway's health infrastructure because several health services rely on ID-porten for authentication, and authorities warned of possible problems accessing online pharmacies and the electronic prescription system.
- [16]
After the 3 August attack Digdir restored normal operations the following day, said the incident had again affected several shared services, and said it would review the event with Vivicta and other partners.
- [17]
The June incident targeted ID-porten through Vivicta's network infrastructure and temporarily affected services including ID-porten, MinID, Maskinporten, eInnsyn and eFormidling.
- [18]
The 24 August attack came 21 days after the 3 August attack on the same infrastructure.
- [19]
The incident disrupted 10 digital services used for verifying people's identities, logging into public services, exchanging data and documents between government agencies and businesses, accessing public records, and managing employee access.
Sources
4 independent publishers whose own reporting we read for this story.
- bleepingcomputer.comMassive DDoS attack disrupts Norway’s government digital services
1 article · August 25, 2026
- infosecurity-magazine.comDDoS Attack Hits Norwegian Government Services
1 article · August 26, 2026
- securityaffairs.comNorway ’s Digital Government Infrastructure Hit by a new DDoS Attack
1 article · August 25, 2026
- therecord.mediaLarge DDoS attack knocks Norwegian public services offline
1 article · August 25, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Cyber AttributionFollow
- Government Digital InfrastructureFollow
- Digital IdentityFollow
- DDoS Attacks and MitigationFollow