A DDoS Against One Provider Reached Norway’s Digital Government.
A distributed denial-of-service attack against infrastructure operated by Digdir’s supplier Vivicta disrupted access to shared digital services used across Norway’s public sector. The incident affected ID-porten and a chain of dependent services, showing how an availability attack against one provider can reach far beyond a single website.
The Norwegian Digitalisation Agency, Digdir, said on 25 August that the attack began at 03:38 CEST on Monday, 24 August. Services were stable by the time of the announcement, although some continued to experience disruption while mitigation work remained active.
One availability incident reached many public functions
The affected portfolio included ID-porten, MinID, Maskinporten, the Contact and Reservation Register, eFormidling, ELMA, eInnsyn, Ansattporten and Digdir’s integration self-service tooling. Altinn, eSignering and Digital post were also affected.
Some services became completely unavailable for short periods. More commonly, they remained partially available but responded slowly or failed intermittently. Digdir’s status updates recorded improving access from 07:25 on 24 August, renewed instability, a period from 12:18 when several solutions were fully down, and further improvement from approximately 14:14.
ID-porten is the important link. It provides a common login mechanism for public services. When it is degraded, individual organisations may keep their own applications online but users can still be unable to authenticate. Availability therefore depends on the whole path, not merely the service the citizen intends to use.
Availability, not intrusion
Digdir said there was no indication that the incident involved a security breach or that personal data had been exposed. The agency described the objective as disruption of availability, not entry into the affected systems. The Norwegian National Security Authority and the Norwegian Data Protection Authority were notified.
That distinction matters. A DDoS attack can be operationally serious without giving the attacker access to accounts or data. Slow authentication, failed signing and unavailable machine-to-machine tokens can interrupt healthcare, benefits, taxation, municipal workflows and administrative processes even when confidentiality and integrity remain intact.
Defenders should also resist the opposite mistake. Evidence that an incident is a denial-of-service attack does not automatically prove that no intrusion occurred. In this case, the no-breach statement comes from Digdir’s investigation and monitoring as of 25 August. It should be treated as the current evidence, with room for later updates if the assessment changes.
The third incident changes the resilience question
Digdir said this was the third similar attack in a short period. A June event targeted ID-porten through Vivicta’s network infrastructure and interrupted multiple shared solutions. Another attack beginning overnight on 3 August caused partial or complete unavailability until services returned to normal the following morning.
Repeated attacks change the planning assumption. The question is no longer whether shared public infrastructure might face a volumetric or application-layer flood. It is how authentication, signing and service-to-service trust should degrade when it does.
Centralised identity provides consistency and reduces duplicated security work, but it also concentrates availability risk. The answer is not to discard common identity. It is to design dependencies, capacity, failover and recovery around the consequences of that concentration.
Operational questions for shared-service owners
- Map dependency chains. Service inventories should show which citizen and machine workflows fail when identity, signing, routing, DNS, content delivery or a supplier control plane is degraded.
- Measure the user journey. A green application server does not mean a usable service. Synthetic checks should test login, token issuance, signing and critical transactions from multiple networks.
- Define degraded modes. Decide which functions can continue with cached assertions, delayed processing, queued messages or alternative verification, and which must fail closed.
- Exercise supplier coordination. Incident playbooks need named contacts, shared telemetry, escalation thresholds, mitigation authority and a common status language across agencies and providers.
- Protect the status channel. Citizens and service owners need a reliable place to distinguish an outage from an account problem or breach. Status communications should remain reachable when production systems are under pressure.
- Review repeat-event learning. After three incidents, actions should be tracked across capacity, filtering, architecture and procurement, not only closed as individual operational tickets.
Digital government inherits platform risk
The Norwegian incident is a useful case study because the services were not all attacked independently. Shared infrastructure carried the operational effect across organisational boundaries. That is the efficiency of a common platform and its failure domain in the same picture.
For public-sector leaders, the lesson is not limited to DDoS protection. It is to treat identity, signing, machine access and integration platforms as national service dependencies whose resilience must be measured by the services they enable.
Sources
- Digitaliseringsdirektoratet, Digdir stabiliserer løsningene etter dataangrep, published 25 August 2026 at 12:27:39 CEST.
- Digitaliseringsdirektoratet production status page, incident updates beginning 24 August 2026. Individual updates include their CEST timestamps.
- Digitaliseringsdirektoratet, Digdirs fellesløsninger tilbake i normal drift, published 4 August 2026. No publication time was provided.
- Digitaliseringsdirektoratet, June DDoS incident summary, published 23 June 2026. No publication time was provided.
- BleepingComputer, Massive DDoS attack disrupts Norway’s government digital services, published 25 August 2026 at 11:52. The page did not state a timezone.
Continue the series: European National Cyber & Digital Law Series index


