Norway's shared government digital infrastructure has been experiencing disruptions since Monday, August 22, due to a distributed denial-of-service (DDoS) attack. The attack, which began at 03:38 CEST, has targeted services operated by the Norwegian Digitalization Agency (Digitaliseringsdirektoratet, or Digdir) and its operations provider, Vivicta.
Digdir is responsible for critical public sector services, including electronic IDs and signatures, public-service logins, secure digital mail, government forms, and data exchange between agencies. The agency confirmed that several services were completely unavailable for brief periods. While many affected systems have since been stabilized, some services, such as ID-porten and eSignering, remain partially inaccessible. Users may encounter slow server responses, failed connections, and extended login times.
Frode Danielsen, director of Digdir, stated that an investigation into the incident has found no evidence of a security breach within the organization's systems or any compromise of personal data. Danielsen also noted that this is the third DDoS attack targeting Digdir in recent months, following previous incidents in June and on August 3. The Norwegian National Security Authority (NSM) and the Norwegian Data Protection Authority (Datatilsynet) have been informed.
The attack has also impacted other government services that rely on Digdir's infrastructure. Altinn, Norway's central digital platform for communication between citizens, businesses, and government agencies, issued a warning about login and operational issues, directing users to Digdir's status page. Similarly, Skatteetaten, Norway's tax administration agency, has displayed notices regarding login problems on its website, advising users to attempt access again later.
As of now, there has been no official attribution for the attack. However, some Norwegian media outlets have speculated about potential Russian involvement.






