Massive DDoS Attack Disrupts Norwegian Digital Services
For the third consecutive day, a massive Distributed Denial-of-Service (DDoS) attack continues to severely disrupt Norway’s state digital services. The overwhelming overload upon the shared infrastructure directly impacted critical authorization systems, electronic signatures, and vital inter-departmental data exchanges. Consequently, these widespread disruptions affected numerous government websites across the entire nation.
The Genesis of the Attack
The disruptions commenced on August 24th at precisely 03:38 local time. The Norwegian Digitalisation Agency, known as Digdir, alongside its primary contractor Vivicta, promptly confirmed the ongoing attack and initiated protocols to restrict the malicious traffic. According to official status reports, critical systems including ID-porten, MinID, Maskinporten, and eFormidling experienced total or partial failure during the initial hours. The outage also affected ELMA, eInnsyn, the contact and reservation registry, Ansattporten, and various self-service portals.
Cascading Failures Across Government Systems
The disruptions rapidly escalated beyond the primary systems absorbing the brunt of the malicious traffic. Issues originating within ID-porten subsequently affected Altinn, the eSignering electronic signature service, digital mailboxes, and numerous government websites reliant upon the unified login system. Desperate users encountered persistent connection errors, agonizingly slow loading times, and protracted authorization delays. During specific intervals, several crucial services became entirely inaccessible.
The problems plagueing ID-porten proved particularly prominent. This system functions as the unified authorization gateway for a vast array of government online services. It permits citizens to authenticate utilizing MinID, BankID, Buypass, and Commfides. Therefore, the failure of this single, central component instantly reverberated across a multitude of independent departments and their associated websites.
Ongoing Mitigation Efforts
The relentless attack persisted throughout the night of August 26th. At 09:06, Digdir officially announced that the infrastructure remained stable, primarily due to the stringent restrictions implemented. However, they noted that ID-porten was still not operating at total capacity. Previously, Digdir had acknowledged that these necessary restrictions were inadvertently creating critical problems for several clients and dependent services. The agency has not yet provided a definitive timeline for the complete removal of these protective measures. Fortunately, the eSignering service, which prevented document signing for a period on August 25th, had returned to normal operation by nightfall.
Impact on the Norwegian Tax Administration
The widespread failure also significantly impacted the Norwegian Tax Administration. On its dedicated status page, Skatteetaten directly linked the instability of multiple internal systems to the ongoing issues at Digdir. Partial outages were observed within the tax return services, the Min Skatt personal cabinet, several inter-system interfaces, VAT services, and certain data exchange mechanisms. The primary Tax Administration website prominently displayed a warning regarding potential login difficulties.
Assessing the Damage and Investigating the Perpetrators
According to Digdir’s preliminary assessment, investigators have discovered absolutely no evidence suggesting internal system penetration or the compromise of any personal data. The attack focuses entirely upon disrupting service availability. The malicious actors are generating an enormous volume of requests, intentionally overloading the infrastructure and preventing legitimate users from accessing essential services.
Digdir promptly notified the Norwegian National Security Authority (NSM) and the Data Protection Authority (Datatilsynet) regarding the ongoing incident. Currently, no official data exists regarding the identity of the attackers orchestrating this massive assault.
A Disturbing Trend of Recent Attacks
Alarmingly, this current incident represents the third time malicious actors have targeted Digdir’s infrastructure within a short timeframe. In June, attackers successfully overloaded ID-porten utilizing Vivicta’s network infrastructure, rendering several state services temporarily inaccessible. Furthermore, attackers struck the infrastructure again during the night of August 3rd. That assault successfully disrupted logins for Helsenorge, NAV, Skatteetaten, and other vital government systems. The affected services only managed to fully restore operations the following morning.
Digdir, working closely with Vivicta, continues the arduous task of filtering the malicious traffic and dynamically adjusting the implemented restrictions. The incident remains active and unresolved. The agency continues to publish critical updates regarding the infrastructure’s status on its official page.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.