
A large distributed denial-of-service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, affecting services used by the public sector.
The attack started at 03.38 CEST on Monday and has targeted the infrastructure supporting services operated by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider, Vivicta.
Digdir operates Norway’s shared digital government infrastructure, including public-service logins, electronic IDs and signatures, secure digital mail, government forms, public-record access, and data exchange between agencies.
In an announcement published earlier today, the organization states that several services were completely unavailable for short periods.
The agency says many affected systems have now been stabilized, although some services, like ID-porten and eSignering, remain partially inaccessible.
As a result of the attack, users may encounter errors such as failed connections, slow server responses, and unusually long login times.
For live updates on the availability of Digdir services, people may consult the services' operating status page as well as the incident report page with updates from Norway's Directorate for Digitization.
Digdir director Frode Danielsen says the investigation into the incident showed no indication of a security breach affecting the organization’s systems or any compromise of personal data.
Danielsen added that this is the third DDoS attack targeting Digdir recently, following one in June and another on August 3.
The Norwegian National Security Authority (NSM) and the Norwegian Data Protection Authority (Datatilsynet) have been notified accordingly.
There is currently no official attribution for the attack, although Norwegian media have speculated about potential Russian involvement.
Meanwhile, services that rely on Digdir but are not directly targeted also experience disruptions.
Altinn, Norway’s central digital platform for communication between citizens, businesses, and government agencies, published a warning about login issues and operational problems, linking to Digdir’s status page.
Skatteetaten, Norway’s tax administration agency, displays a similar notice about login issues on its website and urges users to try again later.
Once attackers have valid credentials, only 37% of their actions are blocked
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report