Decoding the world of cybersecurity

DDoS attack strains Norway’s shared digital services

A prolonged DDoS attack against Norway’s shared government infrastructure disrupted access to multiple digital services, again testing the resilience of systems used across the public sector.

DDoS attack strains Norway’s shared digital services
Summary
  • A DDoS attack against infrastructure supporting Norway’s shared government services began early on 24 August and continued into 25 August.
  • Digdir said services had stabilised by Tuesday, although mitigation continued and the attack had caused widespread availability problems.
  • The incident follows previous DDoS disruption affecting the same shared digital infrastructure in June and August.

A prolonged distributed denial-of-service attack against Norway’s shared government digital infrastructure has disrupted access to services used across the public sector, extending a run of availability incidents affecting some of the country’s most widely reused digital components.

Norway’s Digitalisation Agency, Digdir, said the latest attack began at 03:38 on Monday 24 August and remained under mitigation into Tuesday. In an update published at 12:27 CEST on 25 August, the agency said its services were stable, although the attack was continuing and work to limit the impact remained under way.

The attack affected shared systems including ID-porten, the national login service used to authenticate citizens to public digital services, alongside components such as MinID, Maskinporten, eInnsyn and eFormidling. Disruption to a common service such as ID-porten can propagate well beyond the organisation operating it because other public bodies depend on the same authentication layer rather than maintaining separate login systems.

Digdir’s status information identified the incident as a DDoS attack being handled with its infrastructure partner Vivicta. A DDoS attack attempts to exhaust the capacity of an online service with large volumes of traffic, creating an availability failure without necessarily requiring attackers to gain access to the underlying systems or data.

The agency has not publicly identified the attacker behind the latest activity, and there is no basis at present to attribute it to a particular state, criminal group or hacktivist operation. The available evidence points to disruption rather than a compromise of information.

The latest incident is also not isolated. Shared Digdir services were hit by DDoS attacks in late June and again at the beginning of August. In the August incident, ID-porten and other systems became wholly or partly unavailable before returning to normal operation the following day. Digdir said at the time there was no indication of a security breach or loss of personal information.

Repeated attacks against the same shared infrastructure raise a broader resilience question than the immediate mechanics of traffic filtering. Centralised digital services reduce duplication and allow public bodies to rely on common identity, messaging and integration components, but they also create concentration points where an availability problem can be felt across otherwise separate organisations.

That concentration is especially visible around identity services. When authentication infrastructure fails, the application a citizen wants to use may itself be healthy while remaining effectively inaccessible. The operational dependency therefore extends from the identity provider into every relying service, making recovery and capacity planning part of public-sector continuity rather than simply the responsibility of an individual website operator.

Norway’s experience also illustrates why DDoS incidents cannot be assessed solely by whether data was stolen. Sustained service denial can consume operational resources, interrupt public access and expose dependencies that would be less visible during normal operation. Where one platform underpins many government processes, resilience rests on both defensive capacity at the shared provider and the ability of dependent services to tolerate degraded authentication or communications.

As of the 25 August update, Digdir said its shared services were stable while the attack continued and mitigation remained active. No public attribution had been made.

×