Norway's shared digital government infrastructure has been subjected to a third distributed denial-of-service (DDoS) attack, causing widespread disruption to public services. The latest incident, which began at 03:38 CEST on Monday, August 24, targeted infrastructure operated by the Norwegian Digitalisation Agency (Digdir) and its service provider, Vivicta.
Digdir confirmed that several shared services experienced complete unavailability for short periods, while others suffered from connection failures, slow responses, and extended login times. The agency operates critical components of Norway's public-sector infrastructure, including ID-porten, MinID, Maskinporten, eFormidling, eInnsyn, the Contact and Reservation Register, and Ansattporten.
The impact of the attack extended beyond Digdir's direct services. Altinn, Norway's central platform for communication between citizens, businesses, and government, was also affected. Other public services relying on ID-porten experienced login problems, demonstrating how disruption to a shared authentication service can propagate throughout the digital government ecosystem. Previous attacks this summer similarly affected access to Helsenorge, NAV, and Skatteetaten.
Digdir has emphasized that the incident primarily concerns service availability and has found no indication of a successful intrusion or compromise of personal data. Director Frode Danielsen stated that there is no evidence the attack led to a security breach or that personal data was exposed. The agency has notified Norway's National Security Authority (NSM) and the Data Protection Authority (Datatilsynet) as part of its response.
This latest attack marks the third such incident in a short timeframe. Previous DDoS attacks against Digdir's services occurred in June and on August 3. The June incident specifically targeted ID-porten through Vivicta's network infrastructure, temporarily affecting services including ID-porten, MinID, Maskinporten, eInnsyn, and eFormidling. While Digdir and Vivicta have been able to mitigate these attacks and restore services, the repeated nature of the incidents suggests a persistent challenge for the wider public sector.
The ongoing campaign highlights how repeated attacks against shared infrastructure can create significant operational friction, forcing defenders to continuously adjust traffic controls, filtering rules, and protection measures. Digdir's status updates on August 24 reflected this dynamic, reporting initial improvements followed by complete outages for some solutions, and subsequent stabilization efforts.
There has been no official attribution for the attacks. While Norwegian media has speculated about potential Russian involvement, this remains unconfirmed. The motivation behind the DDoS campaign could range from political or financial objectives to simply demonstrating capability. Without technical evidence and an official attribution process, assigning responsibility to a specific state or group would be premature.






