There have been a significant DDoS attack targeting Norway’s public services:
Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizens, businesses and public agencies. The incident began at 03:38 CEST on Monday, August 24, and targeted infrastructure operated by the Norwegian Digitalisation Agency, Digdir, together with its service provider Vivicta.
The timing matters because this isn’t an isolated event. Digdir says it’s the third DDoS attack against its services in a short period, following incidents in June and on August 3.
“The Norwegian Directorate for Digitalisation (Digdir) has been subjected to a denial of service attack (DDoS attack) that has been ongoing since 03:38 on the night of Monday, August 24.” reads the statement published by Digdir Agency. “This is the third time in a short time that this type of attack has been directed at Digdir’s solutions. Digdir is working closely with our subcontractor Vivicta. NSM and the Norwegian Data Protection Authority have also been notified of the case.”
That status update refers to the test environment, but the underlying attack also affected production services. Digdir reported that several shared services became completely unavailable for short periods, while others remained accessible but suffered connection failures, slow responses and longer-than-usual login times.
Kevin Surace, CEO, Token (https://www.linkedin.com/in/ksurace)
“This attack is a reminder that shared digital infrastructure can also mean shared failure. When a national identity service goes down, the impact can quickly spread across dozens of otherwise healthy government services.
“Organizations need to design for days of hostile traffic, not minutes – with redundant providers, upstream DDoS protection, geographic failover, and critical services that can degrade gracefully rather than simply disappear.
“At this scale, it stops being just an IT problem. If an attacker can prevent citizens from accessing essential government services, that is a national resilience issue. While attribution is not yet confirmed, the scale, persistence and target fit the pattern of Russian or pro-Russian disruption campaigns seen across Europe.
“Attackers don’t have to break into government systems to disrupt a country. Keeping people from getting in is enough.”
Doc McConnell, Head of Policy & Compliance, Finite State (https://www.linkedin.com/in/doc-mcconnell)
“A denial-of-service attack is often billed as a ‘cybersecurity’ incident, but the conversation about response should start with resilience, not security.
“The right measure of resilience is what a citizen can still do while the service is down. For some services, like filing a tax return, a delay of a day or two may be manageable. For others, like filling a prescription, a delay might not be acceptable. Organizations that depend on shared digital infrastructure need to understand which of their services can tolerate downtime and which can’t, then establish and regularly test the backups that keep life-, health-, and safety-critical functions running.
“There is a cybersecurity dimension to this as well. Although this incident hasn’t been attributed, attacks of this scale generally rely on large numbers of compromised IoT devices assembled into botnets: baby monitors, smart televisions, and home routers. These devices sell cheaply and in large numbers to buyers who have little reason to think about security updates, which leaves a large population of devices on the internet carrying exploitable vulnerabilities. That is where the capacity for large-scale DDoS comes from, and it is why connected device security matters well beyond the owner of any one device.
“Manufacturers are the party best positioned to reduce that supply, and two priorities matter most: shipping products that are secure by default, out of the box, and maintaining a way to deliver security updates for as long as the product is in service.”
Damon Small, Board Member, Xcape, Inc. (https://www.linkedin.com/in/damon-small-7400501)
“Centralization buys efficiency in peacetime and pays for it in a crisis; the same architecture that made ID-porten convenient made a single operational disruption a national outage. When one digital bottleneck can freeze transit, medical access, and government data at once, cybersecurity stops being server defense and becomes national security. While a distributed denial-of-service attack does not compromise underlying data integrity, a prolonged multi-day surge highlights the operational fragility of shared authentication backbones. The common thread is redundancy before the outage, not response after it; implement distributed identity, always-on filtering, and shared accountability for the auth layer. To ride out sustained Layer 4 and Layer 7 flooding without triggering cascading service collapse, security leaders must decouple non-critical dependencies, deploy automated edge scrubbers with multi-provider content delivery networks, and implement graceful degradation paths so localized outages do not paralyze civil infrastructure.
“Critical takeaways include: single points of failure in centralized identity infrastructure elevate volumetric network attacks from IT disruptions to national security crises; operational resilience requires pre-outage architectural investments, including distributed identity backbones and multi-provider traffic scrubbing; and critical infrastructure must support graceful degradation paths so that identity layer outages do not halt core civil and municipal operations.
“Redundancy built before the storm is resilience; redundancy attempted during the attack is just panic.”
Denis Calderone, Principal & COO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)
“There are legitimate reasons to funnel an entire country’s public services through a single authentication gateway. You get one place to enforce policy, one set of logs to monitor, one surface to harden. The tradeoff is obvious though: that single entry point becomes the one thing you absolutely cannot let go down. And if you’ve made that architectural choice, you’d better have every DDoS defense in the book tuned and tested for that exact chokepoint.
“Three attacks in nine weeks against the same vendor, the same infrastructure, with 30-plus hour outages each time. That tells me the defenses either weren’t there or weren’t scaled to match the criticality of what they’re protecting. When your mitigation strategy is geo-blocking entire countries’ worth of IP space after the attack is already underway, you’re doing reactive triage, not DDoS defense. Upstream scrubbing, anycast distribution, automated traffic diversion to cleaning centers, pre-negotiated capacity with mitigation providers, all of that should be standing and warm before the first packet of attack traffic arrives. You don’t build the levee during the flood. And you certainly don’t build the same inadequate levee three times in a row. When pharmacies can’t fill prescriptions and health systems go dark because one vendor’s network is getting flooded, that’s not an IT availability problem anymore. That’s a failure to treat critical national infrastructure like critical national infrastructure.”
I know that I’ve said it before. You need to sort your stuff out so that you’re defended against these attacks. Or you will be the next victim of these attacks. It’s that simple.
Related
This entry was posted on August 26, 2026 at 8:00 am and is filed under Commentary with tags Hacked, Norway. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Norway DDoS attack exposes national resilience risks
There have been a significant DDoS attack targeting Norway’s public services:
Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizens, businesses and public agencies. The incident began at 03:38 CEST on Monday, August 24, and targeted infrastructure operated by the Norwegian Digitalisation Agency, Digdir, together with its service provider Vivicta.
The timing matters because this isn’t an isolated event. Digdir says it’s the third DDoS attack against its services in a short period, following incidents in June and on August 3.
“The Norwegian Directorate for Digitalisation (Digdir) has been subjected to a denial of service attack (DDoS attack) that has been ongoing since 03:38 on the night of Monday, August 24.” reads the statement published by Digdir Agency. “This is the third time in a short time that this type of attack has been directed at Digdir’s solutions. Digdir is working closely with our subcontractor Vivicta. NSM and the Norwegian Data Protection Authority have also been notified of the case.”
That status update refers to the test environment, but the underlying attack also affected production services. Digdir reported that several shared services became completely unavailable for short periods, while others remained accessible but suffered connection failures, slow responses and longer-than-usual login times.
Kevin Surace, CEO, Token (https://www.linkedin.com/in/ksurace)
“This attack is a reminder that shared digital infrastructure can also mean shared failure. When a national identity service goes down, the impact can quickly spread across dozens of otherwise healthy government services.
“Organizations need to design for days of hostile traffic, not minutes – with redundant providers, upstream DDoS protection, geographic failover, and critical services that can degrade gracefully rather than simply disappear.
“At this scale, it stops being just an IT problem. If an attacker can prevent citizens from accessing essential government services, that is a national resilience issue. While attribution is not yet confirmed, the scale, persistence and target fit the pattern of Russian or pro-Russian disruption campaigns seen across Europe.
“Attackers don’t have to break into government systems to disrupt a country. Keeping people from getting in is enough.”
Doc McConnell, Head of Policy & Compliance, Finite State (https://www.linkedin.com/in/doc-mcconnell)
“A denial-of-service attack is often billed as a ‘cybersecurity’ incident, but the conversation about response should start with resilience, not security.
“The right measure of resilience is what a citizen can still do while the service is down. For some services, like filing a tax return, a delay of a day or two may be manageable. For others, like filling a prescription, a delay might not be acceptable. Organizations that depend on shared digital infrastructure need to understand which of their services can tolerate downtime and which can’t, then establish and regularly test the backups that keep life-, health-, and safety-critical functions running.
“There is a cybersecurity dimension to this as well. Although this incident hasn’t been attributed, attacks of this scale generally rely on large numbers of compromised IoT devices assembled into botnets: baby monitors, smart televisions, and home routers. These devices sell cheaply and in large numbers to buyers who have little reason to think about security updates, which leaves a large population of devices on the internet carrying exploitable vulnerabilities. That is where the capacity for large-scale DDoS comes from, and it is why connected device security matters well beyond the owner of any one device.
“Manufacturers are the party best positioned to reduce that supply, and two priorities matter most: shipping products that are secure by default, out of the box, and maintaining a way to deliver security updates for as long as the product is in service.”
Damon Small, Board Member, Xcape, Inc. (https://www.linkedin.com/in/damon-small-7400501)
“Centralization buys efficiency in peacetime and pays for it in a crisis; the same architecture that made ID-porten convenient made a single operational disruption a national outage. When one digital bottleneck can freeze transit, medical access, and government data at once, cybersecurity stops being server defense and becomes national security. While a distributed denial-of-service attack does not compromise underlying data integrity, a prolonged multi-day surge highlights the operational fragility of shared authentication backbones. The common thread is redundancy before the outage, not response after it; implement distributed identity, always-on filtering, and shared accountability for the auth layer. To ride out sustained Layer 4 and Layer 7 flooding without triggering cascading service collapse, security leaders must decouple non-critical dependencies, deploy automated edge scrubbers with multi-provider content delivery networks, and implement graceful degradation paths so localized outages do not paralyze civil infrastructure.
“Critical takeaways include: single points of failure in centralized identity infrastructure elevate volumetric network attacks from IT disruptions to national security crises; operational resilience requires pre-outage architectural investments, including distributed identity backbones and multi-provider traffic scrubbing; and critical infrastructure must support graceful degradation paths so that identity layer outages do not halt core civil and municipal operations.
“Redundancy built before the storm is resilience; redundancy attempted during the attack is just panic.”
Denis Calderone, Principal & COO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)
“There are legitimate reasons to funnel an entire country’s public services through a single authentication gateway. You get one place to enforce policy, one set of logs to monitor, one surface to harden. The tradeoff is obvious though: that single entry point becomes the one thing you absolutely cannot let go down. And if you’ve made that architectural choice, you’d better have every DDoS defense in the book tuned and tested for that exact chokepoint.
“Three attacks in nine weeks against the same vendor, the same infrastructure, with 30-plus hour outages each time. That tells me the defenses either weren’t there or weren’t scaled to match the criticality of what they’re protecting. When your mitigation strategy is geo-blocking entire countries’ worth of IP space after the attack is already underway, you’re doing reactive triage, not DDoS defense. Upstream scrubbing, anycast distribution, automated traffic diversion to cleaning centers, pre-negotiated capacity with mitigation providers, all of that should be standing and warm before the first packet of attack traffic arrives. You don’t build the levee during the flood. And you certainly don’t build the same inadequate levee three times in a row. When pharmacies can’t fill prescriptions and health systems go dark because one vendor’s network is getting flooded, that’s not an IT availability problem anymore. That’s a failure to treat critical national infrastructure like critical national infrastructure.”
I know that I’ve said it before. You need to sort your stuff out so that you’re defended against these attacks. Or you will be the next victim of these attacks. It’s that simple.
Share this:
Like this:
Related
This entry was posted on August 26, 2026 at 8:00 am and is filed under Commentary with tags Hacked, Norway. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.