A sustained distributed denial-of-service attack on Norway's national digitalization agency has knocked out critical government services since Monday, marking the third such incident in recent weeks. The agency, Digitaliseringsdirektoratet (Digdir), announced in an update on August 25 that the assault began early Monday morning at 3:38 a.m. local time. The attack targeted the central infrastructure that Norway's entire public sector relies on for identity verification and digital communication.
The attack hit a dozen essential systems, including ID-porten (the national identity gateway), the Contact and Reservations Register, Maskinporten (a machine-to-machine authentication platform), MinID (the electronic ID service), eFormidling (a message exchange system), ELMA (a business address register), eInnsyn (a search tool), the Employee Portal, Self-Service Solution, the Altinn portal, eSignering (digital signature service), and Digital Mailbox. According to Digdir, the impacted services were entirely unreachable during brief windows, while for most of the duration they remained partially accessible but suffered operational problems, such as login processes taking significantly longer than normal. The agency worked continuously with its subcontractor Vivicta throughout the incident to implement protective countermeasures against the ongoing assault.
Most services have since returned to stable operation, though some continue to experience disruptions. As of the latest status report, only ID-porten remained partially unavailable. Digdir director Frode Danielsen stated that "our digital joint solutions are used by the entire public sector in Norway, and it is serious when we experience that the solutions are not available or there are major operational disruptions." He added that the attack's objective was to compromise availability rather than penetrate systems, and there are no signs that the attack resulted in a security breach or that personal information was exposed.
Security experts pointed to the architectural risks inherent in Norway's centralized approach. Denis Calderone, chief operating officer at AI security firm Suzu Labs, noted that while there are valid reasons to route an entire nation's public services through a single authentication gateway—including unified policy enforcement, consolidated logging, and a single hardened surface—the obvious trade-off is that this single entry point becomes the one element you absolutely cannot allow to fail. Kevin Surace, CEO of authentication specialist Token, characterized the attacks as bearing the hallmarks of a typical Russian disruption campaign, observing that attackers don't need to infiltrate government systems to destabilize a country—simply preventing people from accessing them is sufficient. Norway, with fewer than six million residents, has faced cyber-attacks before, including a July 2023 espionage incident affecting 12 ministries linked to exploitation of an Ivanti zero-day vulnerability by suspected Chinese threat actors, as well as ransomware strikes on private firms like recycling company Tomra and aluminum manufacturer Norsk Hydro.
The repeated targeting of Digdir and Vivicta within a compressed timeframe signals a sustained campaign against Norway's digital infrastructure rather than isolated incidents. For organizations building similar centralized authentication architectures, the calculus between efficiency and resilience becomes sharper when state-level adversaries enter the picture. What works brilliantly in peacetime can become a single point of failure the moment geopolitical tensions rise—and no amount of tuning will eliminate that fundamental trade-off.

