A large-scale distributed denial-of-service (DDoS) attack disrupted Norway’s shared government digital infrastructure by targeting systems operated for the Norwegian Digitalization Agency (Digdir) by its IT partner Vivicta. The attack began early Monday and continued for about 30 hours at varying intensity, knocking multiple public services offline or degrading performance with failed connections, slow responses, and long login times. Authorities said around 10 services were affected, including ID-porten, Norway’s key digital identity gateway, as well as eSignering, with downstream disruption reported for platforms such as Altinn and Skatteetaten.
The outage also caused knock-on effects in parts of Norway’s health infrastructure, including online pharmacies and the electronic prescription system. Digdir said several services were fully unavailable for short periods and some remained partially inaccessible after stabilization efforts. Norwegian authorities, including the National Security Authority and Data Protection Authority, were notified, and officials said there was no indication of unauthorized access, security breach, or compromise of personal data. Digdir described the incident as significantly larger than recent attacks and said it was the third DDoS campaign to hit the agency in recent months.

See attribution, scope, and your downstream exposure.
12 events from the most recent confirmed update back to the earliest known activity.
Pro-Russian group Server Killers claimed in a Telegram post that it was responsible for the DDoS attack against Digdir and Norwegian public digital services, framing it as retaliation for Norway's renewed security cooperation with Ukraine. Norwegian officials had not confirmed the claim at the time of reporting.
Digdir said the DDoS attack that began on August 24 was two to three times larger than the preceding DDoS incident. On Tuesday afternoon, the agency reported that its systems were stable while mitigation continued.
By Tuesday morning, after about 30 hours of attack activity at varying intensity, Digdir said many systems had been stabilized and some services were gradually coming back online. However, some services, including ID-porten and eSignering, were still partially affected.
During the incident, several Digdir services became fully unavailable for short periods and 10 digital services were disrupted, including ID-porten and eSignering. Dependent platforms and parts of Norway’s health infrastructure also experienced login and access problems, including online pharmacies, the electronic prescription system, Altinn, and Skatteetaten.
A large-scale DDoS attack began at 03:38 CEST on Monday against infrastructure used by Norway’s Digitalisation Agency, Digdir, and operated in part by its IT partner Vivicta. The attack disrupted shared government digital infrastructure, including identity, login, signing, and data-exchange services.
BleepingComputer reported that Digdir was targeted by another DDoS attack on August 3, making the later August incident the third recent attack against the agency. No additional operational details for the August 3 event were provided in the references.
Digdir director Frode Danielsen said the Norwegian Digitalisation Agency had previously been targeted by a DDoS attack in June. The references provide no further dated details about that earlier incident.
Norway's National Criminal Investigation Service (Kripos) opened an investigation into the Digdir DDoS incident. The Police Security Service (PST) monitored the situation and coordinated with other government agencies; Server Killers' responsibility remained unverified.
Truesec assessed that Server Killers shares links, messaging, and other similarities with the Russian hacktivist group Noname057(16), which it said had been exposed as a product of the CISM agency. Truesec said Russian-state leadership of Server Killers was likely but emphasized that it had no direct evidence of such control.
As the investigation progressed, Digdir said it found no indication of a security breach or unauthorized access to sensitive information, and no sign that personal data had been compromised. Authorities also said attribution remained unclear at the time of reporting.
Following the attack, Digdir notified Norway’s National Security Authority (NSM) and the Data Protection Authority (Datatilsynet) about the incident. The references do not provide a more specific date than the reporting timeframe.
Digdir reported that it was stabilizing its solutions following a data attack. The available reference provides no details on the attack’s timing, impact, or type beyond the title.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
16 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcetruesec.com
Open sourcexakep.ru
Open sourcesecurityweek.com
Open sourcestatus.digdir.no
Open sourcetestmiljo.status.digdir.no
Open sourcekommunikasjon.ntb.no
Open sourcedigital-strategy.ec.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.