A denial-of-service attack that began at 03.38 on Monday 24 August left ID-porten and nine other shared Norwegian government services unstable for roughly 30 hours. ID-porten is the login gateway more than 4.5 million people use to reach public services and when it faltered so did Altinn, the tax administration Skatteetaten and parts of the country’s health infrastructure. None of those systems were attacked directly.
Digitaliseringsdirektoratet (Digdir) confirmed the attack in a press release on Tuesday 25 August saying its operations partner Vivicta was the target and that the two had been working on stabilising measures since it started. Director Frode Danielsen said the investigation found no sign of a breach of Digdir’s systems and no compromise of personal data. The Norwegian National Security Authority (NSM) and the data protection authority Datatilsynet were notified.
The Third Attack on Digdir Since June
This is the third denial-of-service attack against Digdir’s shared infrastructure in roughly two months. One hit in late June, another in early August and on both occasions Digdir restored normal operations within a day. Digdir press officer Are Kvistad told the news agency NTB that this one is two to three times larger than the earlier attacks.
The repetition is the story, not the duration. Digdir and Vivicta can absorb these waves and bring services back which they have now demonstrated three times. What they have not done is stop the same category of attacker returning to the same target with more volume each time. That is a different problem from the one you solve by buying scrubbing capacity.
One Authentication Service, Ten Broken Ones
Digdir runs the components most of Norwegian public administration is built on, ID-porten, MinID, Maskinporten, eFormidling, eInnsyn, Kontakt- og reservasjonsregisteret and Ansattporten. Ten services were disrupted this week covering identity verification, logins to public services, document and data exchange between agencies and businesses, access to public records and employee access management.
Altinn published a notice about login problems and pointed users at Digdir’s status page. Skatteetaten put a similar warning on its own site. Neither was under attack. Both depend on ID-porten to authenticate the people trying to reach them which is the point of a shared identity layer and also its most obvious weakness.
Earlier attacks in the same series reached Helsenorge and NAV. The Record reports that health services relying on ID-porten for authentication were affected again this week.
No Attribution, and Plenty of Speculation
There is no official attribution. Digdir has not named a suspect and neither has NSM. That has not stopped the gap being filled, VG published an expert view that the attackers could be Russian. As a guess about a category of actor it is reasonable. As evidence it is worth nothing.
Denial-of-service is the cheapest thing in the offensive toolkit. Booter services rent capacity by the hour and aiming that capacity at a national identity provider produces headlines far out of proportion to the skill involved. An attribution made within 48 hours of a DDoS wave, resting on target selection and geography, is a hypothesis. If NSM reaches a firmer conclusion it will publish one.
Sweden Is Built the Same Way
Swedish public administration carries the same shape of exposure and the precedent is already on the books. In August 2025 a ransomware attack on Miljödata whose HR and rehabilitation systems are used by roughly 80 % of Swedish municipalities, disrupted services across around 200 of the country’s 290 kommuner. Different attack method, identical structural lesson, the blast radius of a shared supplier is not the supplier, it is everyone wired into it.
Cybersäkerhetslagen (SFS 2025:1506) has been in force since 15 January 2026 and Article 21 of NIS2 puts business continuity and supply chain security in the same set of obligations. Availability counts. An outage caused by a supplier you did not choose and cannot patch is still your incident and the clock still runs, 24 hours for an early warning, 72 hours for full notification, one month for the final report.
Test the Fallback, Not the Firewall
Three things are worth doing this week if your organisation depends on a shared identity provider whether that is ID-porten, BankID or a commercial IdP.
Map what breaks when authentication fails rather than when an application fails. Most continuity plans model the loss of a system. Very few model the loss of the thing that lets staff and customers log into every system at once.
Agree the manual fallback before you need it. Digdir brought services back inside a day each time and a day is long enough to matter for a payroll run, a prescription or anything with a statutory deadline. Decide now what gets done on paper.
Then ask your own provider what changed after its last outage. Digdir said it would review the early-August incident together with Vivicta and its other partners. Put the equivalent question to your supplier in writing. The answer will tell you quickly whether something was fixed or whether the attack simply stopped.
References
- Digdir stabiliserer løsningene etter dataangrep
- Massive DDoS Attack Disrupts Norway’s Government Digital Services
- Large DDoS Attack Knocks Norwegian Public Services Offline
- What’s Happening with the Norwegian Government’s Online Services?
- Norway’s Digital Government Infrastructure Hit By a New DDoS Attack
This post is also available in:

