HackMyIP
← Back to News
2026-08-25 The Record

Major DDoS Attack Disrupts Norwegian Government ID Services for 30+ Hours

Incident ResponseAuthenticationCloud Security

Norway's public digital infrastructure faced severe disruption this week after a large-scale distributed denial-of-service (DDoS) attack knocked government services offline for more than 30 hours. The Norwegian Digitalisation Agency (Digdir) confirmed the attack began Monday and targeted infrastructure operated by its IT partner Vivicta. According to Digdir press officer Are Kvistad, the assault was two to three times larger than the previous incident, flooding servers with traffic to render them unavailable to legitimate users. Network defenders can use tools like a port scanner to identify exposed attack surfaces that DDoS campaigns frequently exploit.

The attack disrupted 10 digital services tied to Digdir's ecosystem, most notably ID-porten—a critical digital identification gateway used by more than 4.5 million Norwegians to authenticate across thousands of government services via BankID and MinID. The outage cascaded into Norway's health sector, as several health services depend on ID-porten for user authentication. Authorities issued warnings about potential difficulties accessing online pharmacies and the national electronic prescription system. Security teams handling authentication infrastructure can benefit from running a privacy checkup to evaluate the resilience of their identity verification workflows.

This marks the third DDoS incident to hit Digdir's services since June, though officials have not confirmed whether the attacks are connected or part of a coordinated campaign targeting Norwegian infrastructure. Digdir stated that attackers did not gain access to sensitive information stored within affected systems, but the prolonged nature of the attack—fluctuating in intensity over 30+ hours—underscores the growing sophistication of volumetric threats facing public-sector cloud environments. Investigating the origin of attack traffic may involve a WHOIS lookup on associated IP addresses to trace command-and-control infrastructure.

Digdir said it is working with Vivicta to stabilize the affected systems, with some services gradually returning to normal as of Tuesday morning. The agency's status page continued to reflect partial outages, and full restoration timelines were not immediately disclosed. The incident highlights the vulnerability of centralized authentication platforms and the urgent need for redundant failover architectures in government digital services.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Password Checker →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

Password security basics →Two-factor authentication explained →How to create a strong password →