Full Report
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]
Analysis Summary
# Incident Report: Distributed Denial-of-Service Attack on Norwegian Government Infrastructure
## Executive Summary
Starting on Monday, August 24, 2026, the Norwegian Digitalization Agency (Digdir) and its provider Vivicta were targeted by a massive, sustained Distributed Denial-of-Service (DDoS) attack. The incident disrupted critical public services, including electronic IDs, signatures, and tax portals, leading to intermittent outages and slow response times for citizens. While operational availability was severely impacted, officials confirmed that no data breach or compromise of personal information occurred.
## Incident Details
- **Discovery Date:** August 24, 2026, 03:38 CEST
- **Incident Date:** August 24, 2026 – Ongoing (as of report time)
- **Affected Organization:** Norwegian Digitalization Agency (Digdir) and Vivicta (Operations Provider)
- **Sector:** Public Sector / Government Digital Infrastructure
- **Geography:** Norway
## Timeline of Events
### Initial Access
- **Date/Time:** August 24, 2026, at 03:38 CEST
- **Vector:** Distributed Denial-of-Service (DDoS)
- **Details:** High-volume traffic flood directed at the shared digital infrastructure supporting Norway’s public services.
### Lateral Movement
- **N/A:** As a DDoS attack, the objective was resource exhaustion rather than network penetration. No lateral movement was reported.
### Data Exfiltration/Impact
- **Impact:** Temporary unavailability of ID-porten (login), eSignering (signatures), Altinn (business portal), and Skatteetaten (Tax Administration).
- **Data Breach:** Investigation confirmed no unauthorized access to systems or theft of personal data.
### Detection & Response
- **Discovery:** Automated monitoring systems identified a surge in traffic and service failures at 03:38 CEST.
- **Response Actions:** Infrastructure stabilization efforts were initiated by Digdir and Vivicta; notifications were sent to the National Security Authority (NSM) and Data Protection Authority (Datatilsynet).
## Attack Methodology
- **Initial Access:** Network-level / Application-level traffic flooding (DDoS).
- **Persistence:** Not applicable (Transient infrastructure attack).
- **Privilege Escalation:** None.
- **Defense Evasion:** Use of distributed botnet traffic to bypass standard rate limiting.
- **Credential Access:** None.
- **Discovery:** None.
- **Lateral Movement:** None.
- **Collection:** None.
- **Exfiltration:** None.
- **Impact:** Resource Exhaustion; Denial of Service; Service Disruption.
## Impact Assessment
- **Financial:** Not yet disclosed; costs involve incident response hours and productivity loss for businesses utilizing Altinn.
- **Data Breach:** None.
- **Operational:** High. Multiple government portals experienced total or partial downtime, affecting e-government services nationwide.
- **Reputational:** Moderate. This marks the third attack since June 2026, potentially impacting public trust in digital infrastructure stability.
## Indicators of Compromise
- **Network Indicators:** High-volume traffic originating from distributed global IP addresses (Specific IPs not disclosed in the report).
- **File Indicators:** None (No malware delivery reported).
- **Behavioral Indicators:** Surge in failed connection requests, high latency in ID-porten authentication flows, and server timeout errors (HTTP 504).
## Response Actions
- **Containment measures:** Traffic scrubbing and filtering at the infrastructure level (Vivicta).
- **Eradication steps:** Implementation of enhanced DDoS mitigation rules.
- **Recovery actions:** Stabilization of the ID-porten and eSignering services; ongoing live status updates via `status.digdir[.]no`.
## Lessons Learned
- **Key Takeaways:** Shared infrastructure creates a single point of failure; an attack on Digdir affects all downstream agencies (Tax, Health, Business).
- **Frequency of Attacks:** The recurrence of attacks (June, early August, and late August) suggests a persistent threat actor targeting Norwegian national interests.
## Recommendations
- **Prevention:** Implement geo-blocking or advanced rate-limiting during high-alert periods.
- **Resilience:** Increase capacity for traffic scrubbing through third-party global DDoS mitigation providers.
- **Redundancy:** Evaluate decoupled authentication methods for critical agencies to prevent total service blackout when the central hub is targeted.