SecurityNot yet confirmed elsewhere1 publisher3 min readPublished
Server Killers hit Norway's public login the day after an 85 billion crown Kyiv pledge
Digdir calls three days of DDoS the biggest it has seen, and says services stayed up nearly throughout. The timing tracks a prime ministerial visit, not the grievance the group published.
The Watch · Security desk

What happened
- Digdir said denial-of-service traffic had been hitting multiple Norwegian public digital services since Monday, across a three-day window.
- Pro-Russian group Server Killers claimed responsibility on Telegram and cited Norway's renewed security cooperation with Ukraine on Aug. 23.
- On Sunday in Kyiv, Prime Minister Jonas Gahr Store pledged 85 billion crowns from next year's budget, a third straight year of support.
Why it matters
- constraint Scrubbing and headroom for a shared national login have to be bought for the loudest political week of the year, not for average weekday load, because the front door cannot be scaled down when the...
- decision Availability rosters and vendor burst limits now have a scheduling input that sits in the foreign ministry's diary, which means someone has to own the handover between diplomatic planning and...
- exposure The party that pays for an aid announcement is the citizen trying to reach a public service, not the minister making it, and every other donor government with a single sign-on inherits the same...
- contradiction Because the group's published motive and the actual start date point at different events, Telegram declarations are weak forecasting material while published diplomatic dates are usable ones.
The stated grievance and the timing do not match. Server Killers told its Telegram audience it had declared cyber war on Norway over the country renewing security cooperation with Ukraine on Aug. 23 [6]. The traffic arrived on Monday [1], one day after Prime Minister Jonas Gahr Store stood in Kyiv and committed 85 billion Norwegian crowns of next year's state budget, about 9.2 billion dollars, to a third consecutive year of support [7][14]. The published cause was weeks old. The money was a day old.
That gap tells you what the operation was for. Volumetric denial of service needs no foothold, no credential and no patch gap; the input is rented capacity and the output is a name in Norwegian media while the pledge is still being reported. Digdir's own account fits that reading: the agency says it kept services running practically all the time [4], which means the deliverable was attention rather than outage.
The target selection is the part worth copying down. Among the services hit was the one that lets citizens use a single login across multiple public services [3]. Aim at that and one availability target degrades the entrance to many services at once, without needing to know which ones. The dependency graph is the blast radius, not the agency's own service catalogue.
What is missing is any denominator. "The biggest attack against Digdir solutions that we have ever experienced" is a comparison against an internal baseline nobody outside the agency can see [2], and there is no published figure for traffic volume or minutes of degradation. An operator elsewhere in Europe cannot use it to size scrubbing capacity, only to justify asking for more.
The same banner covers very different hands. Norwegian authorities said in 2025 that Russian hackers were likely behind suspected sabotage at a dam, where a remotely controlled valve was opened to increase water flow [10], and police said a three-minute video of the control panel, marked by a pro-Russian group, went up on Telegram [11]. Danish officials attributed a destructive attack on a water utility in 2024 to Z-Pentest and a 2025 pre-election website attack to NoName057(16), saying both have links to the Russian state [12]. Against those, three days of traffic against a login service is the cheap end of the campaign, and the cheap end is the part that scales, because it requires no access to anything.
Attribution will lag: Norwegian officials had not commented on the claim by publication time [8]. The diary will not lag. Aid votes, ratification dates, drone cooperation announcements and ministerial visits are all published in advance [9], and officials already describe this activity as aimed at undermining support for Ukraine and draining investigative resources [13]. For any government running a shared citizen login, that calendar is the cheapest surge forecast available, and it costs nothing to read.
What to watch
- Whether Digdir publishes traffic volumes or minutes of degradation, which would let other agencies size scrubbing capacity against a real figure.
- Whether Norwegian officials formally attribute the campaign or leave the Server Killers Telegram claim unchallenged.
- Whether the next Norwegian step on Ukraine, such as budget passage or the drone cooperation work, is followed by another traffic window.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence52
- Adoption38
- Hype gap+27
- Incentives63
- Confidence45
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A cyberattack affecting multiple Norwegian government digital services had been ongoing since Monday, over the past three days, according to Are Kvistad, spokesperson for the Norwegian Digitalization Agency (Digdir), speaking to The Associated Press.
- [2]
Kvistad said: "It's the biggest attack against Digdir solutions that we have ever experienced."
- [3]
The denial-of-service attacks pushed massive traffic toward the agency to block services, including one that enables citizens to use one login across multiple public services.
- [4]
The Digdir spokesman said the agency managed to keep the services running "practically all the time."
- [5]
Digdir, the Norwegian Digitalization Agency, is the state body in charge of making Norway's public services more digital and user-friendly.
- [6]
In a Telegram post on Wednesday, widely reported by Norwegian media, the pro-Russian group Server Killers claimed responsibility for the attack and said it had declared cyber war on Norway after the country renewed its security cooperation with Ukraine on Aug. 23.
- [7]
On Sunday, Norwegian Prime Minister Jonas Gahr Store announced during a visit to Kyiv that Norway would provide 85 billion Norwegian crowns (9.2 billion US dollars) to Ukraine from next year's state budget, for a third year in a row.
- [8]
Norwegian officials did not comment on the hackers' claim by publication time.
- [9]
Norway and Ukraine also committed to further cooperation on drone technology and other forms of modern warfare.
- [10]
In 2025, Norwegian authorities said Russian hackers were likely behind suspected sabotage at a dam in Norway, where hackers gained access to a digital system that remotely controls one of the dam's valves and opened it to increase water flow.
- [11]
Police said a three-minute video showing the dam's control panel and a mark identifying a pro-Russian cybercriminal group was published on Telegram at the time of the incident.
- [12]
Danish officials said pro-Russian group Z-Pentest carried out a destructive attack on a water utility company in 2024, and that NoName057(16) was responsible for a cyberattack on Danish websites ahead of the 2025 local elections; they said both have links to the Russian state.
- [13]
Officials say the attacks are intended to undermine support for Ukraine, spread fear and discord in European societies and drain investigative resources, with Europe on high alert since Russia's full-scale invasion of Ukraine in February 2022.
- [14]
The attack traffic began one day after the Kyiv funding announcement: the pledge was made on Sunday and the attack has been ongoing since Monday.
Sources
1 independent publisher whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- European Critical Infrastructure SecurityFollow
- Cyber AttributionFollow
- Government Digital Identity ServicesFollow
- DDoS Attacks and MitigationFollow
- Pro-Russian HacktivismFollow
Entities
- Norwegian Digitalisation AgencyFollow
- Server KillersFollow
- Are KvistadFollow
- Jonas Gahr StoreFollow
- Z-PentestFollow
- NoName057(16)Follow
- Associated PressFollow