Skip to content

SecurityNot yet confirmed elsewhere1 publisher3 min readPublished

Server Killers hit Norway's public login the day after an 85 billion crown Kyiv pledge

Digdir calls three days of DDoS the biggest it has seen, and says services stayed up nearly throughout. The timing tracks a prime ministerial visit, not the grievance the group published.

The Watch · Security desk

How we use AISend a correction

Photograph accompanying Server Killers hit Norway's public login the day after an 85 billion crown Kyiv pledge
Photo: securityweek.com

What happened

  • Digdir said denial-of-service traffic had been hitting multiple Norwegian public digital services since Monday, across a three-day window.
  • Pro-Russian group Server Killers claimed responsibility on Telegram and cited Norway's renewed security cooperation with Ukraine on Aug. 23.
  • On Sunday in Kyiv, Prime Minister Jonas Gahr Store pledged 85 billion crowns from next year's budget, a third straight year of support.

Why it matters

  • constraint Scrubbing and headroom for a shared national login have to be bought for the loudest political week of the year, not for average weekday load, because the front door cannot be scaled down when the...
  • decision Availability rosters and vendor burst limits now have a scheduling input that sits in the foreign ministry's diary, which means someone has to own the handover between diplomatic planning and...
  • exposure The party that pays for an aid announcement is the citizen trying to reach a public service, not the minister making it, and every other donor government with a single sign-on inherits the same...
  • contradiction Because the group's published motive and the actual start date point at different events, Telegram declarations are weak forecasting material while published diplomatic dates are usable ones.

The stated grievance and the timing do not match. Server Killers told its Telegram audience it had declared cyber war on Norway over the country renewing security cooperation with Ukraine on Aug. 23 [6]. The traffic arrived on Monday [1], one day after Prime Minister Jonas Gahr Store stood in Kyiv and committed 85 billion Norwegian crowns of next year's state budget, about 9.2 billion dollars, to a third consecutive year of support [7][14]. The published cause was weeks old. The money was a day old.

That gap tells you what the operation was for. Volumetric denial of service needs no foothold, no credential and no patch gap; the input is rented capacity and the output is a name in Norwegian media while the pledge is still being reported. Digdir's own account fits that reading: the agency says it kept services running practically all the time [4], which means the deliverable was attention rather than outage.

The target selection is the part worth copying down. Among the services hit was the one that lets citizens use a single login across multiple public services [3]. Aim at that and one availability target degrades the entrance to many services at once, without needing to know which ones. The dependency graph is the blast radius, not the agency's own service catalogue.

What is missing is any denominator. "The biggest attack against Digdir solutions that we have ever experienced" is a comparison against an internal baseline nobody outside the agency can see [2], and there is no published figure for traffic volume or minutes of degradation. An operator elsewhere in Europe cannot use it to size scrubbing capacity, only to justify asking for more.

The same banner covers very different hands. Norwegian authorities said in 2025 that Russian hackers were likely behind suspected sabotage at a dam, where a remotely controlled valve was opened to increase water flow [10], and police said a three-minute video of the control panel, marked by a pro-Russian group, went up on Telegram [11]. Danish officials attributed a destructive attack on a water utility in 2024 to Z-Pentest and a 2025 pre-election website attack to NoName057(16), saying both have links to the Russian state [12]. Against those, three days of traffic against a login service is the cheap end of the campaign, and the cheap end is the part that scales, because it requires no access to anything.

Attribution will lag: Norwegian officials had not commented on the claim by publication time [8]. The diary will not lag. Aid votes, ratification dates, drone cooperation announcements and ministerial visits are all published in advance [9], and officials already describe this activity as aimed at undermining support for Ukraine and draining investigative resources [13]. For any government running a shared citizen login, that calendar is the cheapest surge forecast available, and it costs nothing to read.

What to watch

  • Whether Digdir publishes traffic volumes or minutes of degradation, which would let other agencies size scrubbing capacity against a real figure.
  • Whether Norwegian officials formally attribute the campaign or leave the Server Killers Telegram claim unchallenged.
  • Whether the next Norwegian step on Ukraine, such as budget passage or the drone cooperation work, is followed by another traffic window.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence52
Adoption38
Hype gap+27
Incentives63
Confidence45
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    A cyberattack affecting multiple Norwegian government digital services had been ongoing since Monday, over the past three days, according to Are Kvistad, spokesperson for the Norwegian Digitalization Agency (Digdir), speaking to The Associated Press.

    ReportedSupportedSource: Are Kvistad, Digdir spokesperson, to APView cited source
  2. [2]

    Kvistad said: "It's the biggest attack against Digdir solutions that we have ever experienced."

    ReportedSupportedSource: Are Kvistad, DigdirView cited source
  3. [3]

    The denial-of-service attacks pushed massive traffic toward the agency to block services, including one that enables citizens to use one login across multiple public services.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. securityweek.com

    1 article · August 27, 2026

    Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories