Norway’s central digital government infrastructure has been experiencing disruptions following a large distributed denial-of-service (DDoS) attack that began early Monday morning, affecting systems used across the country’s public sector.
The attack started at 03:38 CEST and targeted infrastructure supporting services operated by Norway’s Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider Vivicta.
Digdir manages shared infrastructure used by numerous Norwegian public services. Its systems support functions including electronic identification, government logins, digital signatures, secure mail, online forms, access to public records, and data exchange between government organizations.
During the attack, several services became completely unavailable for limited periods. Digdir subsequently stabilized much of the affected infrastructure, although problems have continued with some services. ID-porten, Norway’s common login system for public digital services, and the eSignering electronic signature service have been among those experiencing partial availability.
People attempting to use affected systems may encounter failed connections, delayed server responses, or significantly longer authentication times. Digdir is publishing current availability information through its service status page.
The disruption has also spread indirectly to government platforms that depend on Digdir’s infrastructure. Altinn, which provides digital communication and services connecting citizens and businesses with Norwegian authorities, warned users about login and operational difficulties caused by the ongoing incident.
Norway’s Tax Administration, Skatteetaten, has similarly displayed a warning about authentication problems and advised people who cannot log in to try again later.
Despite the scale of the disruption, Digdir says its investigation has so far found no evidence that attackers gained unauthorized access to its systems or compromised personal information. Director Frode Danielsen said the incident was a DDoS attack intended to overwhelm online infrastructure rather than evidence of a successful intrusion into Digdir’s internal systems.
The latest incident is also not the first recent attempt to overwhelm the agency’s services. According to Danielsen, Digdir has now faced three DDoS attacks within a relatively short period, including an attack in June and another on August 3.
Norway’s National Security Authority (NSM) and Data Protection Authority (Datatilsynet) have been informed about the latest incident.
No attacker has been officially identified. Norwegian media have discussed possible Russian involvement, but authorities have not attributed the attack to Russia or any other state, organization, or threat actor.
DDoS attacks work by directing large amounts of traffic or requests toward targeted infrastructure, potentially exhausting the resources required to serve legitimate users. In this case, the attack’s impact extends beyond Digdir itself because numerous Norwegian government services depend on the agency’s shared infrastructure.
Digdir continues to work on stabilizing the affected systems while investigating the attack. Users experiencing problems can follow the agency’s status information for updates as individual services return to normal operation.
