Security1 distinct publisher3 min readPublished
Digdir calls three days of DDoS the biggest it has seen, and says services stayed up nearly throughout. The timing tracks a prime ministerial visit, not the grievance the group published.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The stated grievance and the timing do not match. Server Killers told its Telegram audience it had declared cyber war on Norway over the country renewing security cooperation with Ukraine on Aug. 23 [6]. The traffic arrived on Monday [1], one day after Prime Minister Jonas Gahr Store stood in Kyiv and committed 85 billion Norwegian crowns of next year's state budget, about 9.2 billion dollars, to a third consecutive year of support [7][14]. The published cause was weeks old. The money was a day old.
That gap tells you what the operation was for. Volumetric denial of service needs no foothold, no credential and no patch gap; the input is rented capacity and the output is a name in Norwegian media while the pledge is still being reported. Digdir's own account fits that reading: the agency says it kept services running practically all the time [4], which means the deliverable was attention rather than outage.
The target selection is the part worth copying down. Among the services hit was the one that lets citizens use a single login across multiple public services [3]. Aim at that and one availability target degrades the entrance to many services at once, without needing to know which ones. The dependency graph is the blast radius, not the agency's own service catalogue.
What is missing is any denominator. "The biggest attack against Digdir solutions that we have ever experienced" is a comparison against an internal baseline nobody outside the agency can see [2], and there is no published figure for traffic volume or minutes of degradation. An operator elsewhere in Europe cannot use it to size scrubbing capacity, only to justify asking for more.
The same banner covers very different hands. Norwegian authorities said in 2025 that Russian hackers were likely behind suspected sabotage at a dam, where a remotely controlled valve was opened to increase water flow [10], and police said a three-minute video of the control panel, marked by a pro-Russian group, went up on Telegram [11]. Danish officials attributed a destructive attack on a water utility in 2024 to Z-Pentest and a 2025 pre-election website attack to NoName057(16), saying both have links to the Russian state [12]. Against those, three days of traffic against a login service is the cheap end of the campaign, and the cheap end is the part that scales, because it requires no access to anything.
Attribution will lag: Norwegian officials had not commented on the claim by publication time [8]. The diary will not lag. Aid votes, ratification dates, drone cooperation announcements and ministerial visits are all published in advance [9], and officials already describe this activity as aimed at undermining support for Ukraine and draining investigative resources [13]. For any government running a shared citizen login, that calendar is the cheapest surge forecast available, and it costs nothing to read.
Ranked by verification strength, evidence, and original report placement.
A cyberattack affecting multiple Norwegian government digital services had been ongoing since Monday, over the past three days, according to Are Kvistad, spokesperson for the Norwegian Digitalization Agency (Digdir), speaking to The Associated Press.
Kvistad said: "It's the biggest attack against Digdir solutions that we have ever experienced."
The denial-of-service attacks pushed massive traffic toward the agency to block services, including one that enables citizens to use one login across multiple public services.
The Digdir spokesman said the agency managed to keep the services running "practically all the time."
Digdir, the Norwegian Digitalization Agency, is the state body in charge of making Norway's public services more digital and user-friendly.
In a Telegram post on Wednesday, widely reported by Norwegian media, the pro-Russian group Server Killers claimed responsibility for the attack and said it had declared cyber war on Norway after the country renewed its security cooperation with Ukraine on Aug. 23.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named operator on the record, attribution unverified
The core facts come from a named Digdir spokesperson speaking to the Associated Press, which is solid for existence, duration and continuity of service. Everything beyond that is weaker: the 'biggest ever' claim carries no metrics, responsibility rests on a Telegram post, and Norwegian officials had not commented by publication. Only one publisher is in the cluster, so nothing is independently corroborated.
Real incident, limited observed impact
There is a concrete, operator-confirmed event touching national-scale citizen infrastructure, which is more than a vendor announcement. But observed real-world effect is small: services stayed up practically throughout, no outage duration, user impact or downstream service failures are disclosed, and no second jurisdiction reports simultaneous disruption.
Framing outruns disclosed disruption
The 'major cyberattack' and 'biggest attack ever' framing sits against an operator statement that services stayed available practically all the time, an unverified Telegram claim of responsibility, and no official attribution. The attacker's own grievance narrative also fails to match the timeline, since traffic started the day after the Kyiv pledge rather than tracking the Aug. 23 cooperation renewal. The overstatement is moderate rather than severe because the underlying event and the named-source confirmation are real.
Both speakers have reasons to shape the story
Server Killers gains propaganda value from publicising a claim of responsibility against a state that just funded Ukraine, which rewards exaggeration regardless of actual effect. Digdir has a dual incentive: to stress unprecedented scale, which justifies resourcing, and to stress near-total uptime, which protects confidence in national digital services. Officials quoted on motive are describing policy posture. These pressures are visible in the text; nothing in the cluster shows commercial sponsorship or vendor promotion.
Single-publisher, attribution open
Confidence is moderate-to-low: one publisher, one named operator source, no technical telemetry, no official Norwegian attribution, and the only responsibility evidence is a Telegram post. The incident's occurrence and the funding pledge are firm; severity, causation and actor identity are not.
security
New Zealand adds 33 names, including two Cyber Army of Russia Reborn operators1 distinct publisher
security
994 dossiers in 499 pages: the NoName057(16) file reads as collection, not defacement1 distinct publisher
product
From Omaha students to ICE: the shock glove sold as camera-proof force1 distinct publisher
build
Flock cut retention to seven days and published the number that made 30 indefensible1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.