"The affected services have been completely unavailable for short periods. For most of the time, they have been partially available, but have experienced operational disruptions, where, for example, logging in has taken longer than usual," Digdir said.
Digdir, Vivicta and the list of disrupted services
The Norwegian Digitalisation Agency (Digitaliseringsdirektoratet, or Digdir) reported a major distributed denial-of-service (DDoS) attack that disrupted a broad set of the country's shared public IT services. Digdir said the incident affected ID-porten (the national identity gateway), the Contact and Reservations Register, the Maskinporten machine-to-machine authentication hub, e-ID service MinID, the eFormidling message exchange, the ELMA business address register, the eInnsyn search service, the Employee Portal, the Self-Service Solution, the Altinn portal, eSignering digital signature service, and the Digital Mailbox.
Digdir reported that "the affected services have been completely unavailable for short periods" and that most were "partially available" but suffered operational disruptions including longer-than-usual login times. Digdir said it has worked together with subcontractor Vivicta on measures to protect the solution against the attack.
When the attack began and the immediate status
According to Digdir's update on August 25, the attack began on Monday night at 3.38am local time. In the agency's latest status update, most services had "now stabilized," although some continued to experience operational disruption. At the time of writing, Digdir reported that only ID‑porten remained partially inaccessible.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageDigdir's public assessment and leadership comment
Digdir director Frode Danielsen framed the incident as an availability attack and sought to reassure users about data confidentiality: “The purpose of this type of attack is to affect availability, not to break into the solutions. There are no indications that the attack has led to a security breach or that personal data has been compromised.” He also noted the seriousness of disruptions because "our digital joint solutions are used by the entire public sector in Norway."
Expert reaction: chokepoints and attribution signals
Security executives who spoke about the incident highlighted architectural and attribution implications visible in the public reporting. Denis Calderone, COO at AI security firm Suzu Labs, argued the architecture that funnels public services through a single authentication gateway creates a critical chokepoint and said, in full: “There are legitimate reasons to funnel an entire country's public services through a single authentication gateway. You get one place to enforce policy, one set of logs to monitor, one surface to harden. The trade off is obvious though: that single entry point becomes the one thing you absolutely cannot let go down. And if you've made that architectural choice, you'd better have every DDoS defense in the book tuned and tested for that exact chokepoint.”
Kevin Surace, CEO of authentication specialist Token, said the attacks bore the hallmarks of a classic Russian disruption campaign and warned that disruption can be achieved without breaking into systems: "Attackers don’t have to break into government systems to disrupt a country,” he added. “Keeping people from getting in is enough."
What this means for technologists, policymakers, and the public
- Technologists and security teams: will focus on the resilience of ID‑porten and Maskinporten, and on testing and tuning DDoS defenses around the single authentication chokepoint Digdir relies on, as Digdir and Vivicta continue mitigation efforts.
- Policymakers and public-sector leaders: will need to weigh the trade-off Denis Calderone described between centralized control (one place to enforce policy and monitor logs) and the risk that a single entry point can bring down many services across the public sector.
- The general public and public-service users: experienced partial or short complete unavailability of widely used services, including slower logins and temporary inability to access identity and messaging services hosted by Digdir's shared infrastructure.
Norway is no stranger to cyber incidents: the report notes this is the third DDoS attack on Digdir and Vivicta in a short time, and recalls earlier incidents in the country — a July 2023 espionage incident traced to an Ivanti zero-day that impacted 12 ministries, and ransomware targeting private firms such as Tomra and Norsk Hydro. Norway, the report adds, is "a country of less than six million people."
In Digdir's account, the immediate harm in this incident was interruption of availability rather than a breach of confidentiality; the agency and its subcontractor Vivicta remain engaged in mitigation and protection work. The near-term question now is whether repeated attacks on the same shared infrastructure will prompt further hardening, architectural change, or new testing regimes for the authentication gateway that ties so many public services together.




