The attack started at 03.38 CEST on Monday, when a large distributed denial-of-service (DDoS) operation began targeting Norway’s shared government digital infrastructure, knocking public-sector services offline and slowing logins for many users.
Digdir and Vivicta: the infrastructure under strain
The assault focused on systems supporting the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider, Vivicta. Digdir “operates Norway’s shared digital government infrastructure,” the agency notes, including public-service logins, electronic IDs and signatures, secure digital mail, government forms, public-record access, and data exchange between agencies.
In an announcement published during the incident, Digdir said several services were “completely unavailable for short periods” while many affected systems were later stabilised. The agency warned that some key services, specifically ID‑porten and eSignering, “remain partially inaccessible.”
Which services and users felt the effects
Users across multiple government services reported errors consistent with a volumetric DDoS disruption: failed connections, slow server responses, and “unusually long login times.” Agencies that rely on Digdir but were not the direct targets nonetheless experienced knock-on effects.
- Altinn, Norway’s central digital platform for citizen, business and government communication, published a warning about login issues and operational problems and linked to Digdir’s status page for updates.
- Skatteetaten, the tax administration agency, displayed a notice about login issues on its website and urged users to “try again later.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTimeline, mitigation and status reporting
The incident began at 03.38 CEST on Monday. Digdir said that, after the initial disruption, “many affected systems have now been stabilized,” but confirmed that partial outages persist for some services. For live updates on service availability, Digdir directed the public to the services’ operating status page and to the incident report page maintained by Norway’s Directorate for Digitization.
Investigation, notifications, and attribution
Digdir director Frode Danielsen said the investigation into the incident showed “no indication of a security breach affecting the organization’s systems or any compromise of personal data.” Danielsen also noted this is the third recent DDoS attack against Digdir, following incidents in June and on August 3. The Norwegian National Security Authority (NSM) and the Norwegian Data Protection Authority (Datatilsynet) have been notified.
There is currently no official attribution for the attack. The organisation’s public communications do not point to a named perpetrator, though Norwegian media have speculated about potential Russian involvement.
What this means for technologists, regulators, and end users
- Technologists and security teams: Operations and incident-response teams will be focused on traffic mitigation and service stabilisation while preserving authentication and data integrity; Digdir’s statement that there is “no indication of a security breach” narrows the initial response to availability and resilience rather than forensic recovery.
- Policymakers and regulators (NSM and Datatilsynet): Both authorities have been notified and will likely monitor the investigation’s findings, particularly the repeated nature of the DDoS incidents in June, August 3, and this latest attack, and whether recurring outages merit changes in oversight or mandatory resilience measures.
- End users and affected agencies (Altinn, Skatteetaten): Citizens, businesses, and public agencies relying on Digdir services should expect intermittent access problems and follow Digdir’s operating status and incident report pages for real‑time guidance and timing for restores.
The immediate technical picture is straightforward: a sustained DDoS campaign disrupted authentication and document-exchange services that form the backbone of Norway’s shared digital government platform, producing brief full outages and ongoing partial interruptions for services such as ID‑porten and eSignering. The longer-term questions the incident leaves open are also clear in Digdir’s own words — repeated attacks, notification of national authorities, and no public attribution — and the investigation, and any subsequent changes to resilience planning, will determine how quickly those questions are resolved.




