MazeBolt Blog: DDoS Attack on Norway

Why Did Norway’s ID-porten Go Down Three Times in Two Months?

Norway’s national login gateway went down at 03:38 on Monday, 24 August. ID-porten is the single sign-on service behind Norwegian tax filing, digital signatures, business registration, and government mail, so even though the attack was on a single gateway, it impacted people who had no direct relationship to the system that failed.

The Norwegian Digitalization Agency (Digdir) confirmed that a DDoS attack hit its shared infrastructure and its subcontractor Vivicta. Most services stabilized within days, but ID-porten stayed partially unreachable after the rest recovered. It was the third DDoS attack against the same infrastructure in roughly two months.

What Happened in the Norway DDoS Attack

The attack continued in waves for more than 30 hours. Digdir press officer Are Kvistad described it as two to three times larger than a previous attack on the same systems.

Twelve services went down or were degraded, among them ID-porten, MinID, Maskinporten, Altinn, eSignering, and Digital postkasse. Most were completely unavailable for short periods, then partially available with extended login times. Knock-on effects reached online pharmacies and electronic prescription services.

Digdir director Frode Danielsen stated that this type of attack aims to disrupt availability, and that nothing indicated a security breach or a compromise of personal data. A pro-Russian group calling itself Server Killers claimed responsibility on Telegram, framing it as retaliation for Norway’s renewed security cooperation with Ukraine. Norwegian authorities have not confirmed the claim, and attribution is unverified.

Why a Shared Login Gateway Concentrates Availability Risk

Single sign-on consolidates authentication for sound reasons: fewer credentials, consistent access control, lower operating cost, and one place to enforce policy. That same consolidation routes the availability of many downstream services through a single gateway.

An attacker who reaches the gateway has no need to touch each connected service individually. Availability for all of them are interconnected; for example, during the same window of time, Norwegian banks including DNB and SpareBank 1 reported concurrent access difficulties, which compounded the disruption for anyone trying to reach a digital service.

What Three Attacks in Two Months Establish

Digdir’s systems were hit on June 20, on August 3, and again on August 24. BleepingComputer noted that services remained partially inaccessible after stabilization work began.

Attackers are returning to infrastructure they have already probed, and each attempt meets a configuration that has probably changed since the previous attempt. In any large-scale IT ecosystem, services are added, integrations are built, API endpoints multiply, and routing paths change. Each of those changes impacts the attack surface that a mitigation policy has to cover, and the combined effect on DDoS protection is rarely measured.

Response Time and Configuration Evidence Measure Different Things

Every DDoS incident raises certain questions that need to be answered. One measurement of response relates to how quickly a team reacts after hostile traffic arrives. A second measurement establishes, ahead of the next attempt, whether the configuration behind the DDoS protection would hold.

This second measurement is proactive, and it requires independent evaluation against the live environment. A configuration that was correct at the time of deployment typically will fall out of alignment as the environment changes.

How Continuous DDoS Validation Turns Protection into Proven Resilience

Most organizations running public-facing services have DDoS protection deployed, and no independent evidence of which attack vectors it currently blocks. MazeBolt’s 2026 validation data shows that 37% of attack vectors, on average, bypass deployed DDoS protection when those environments are first independently validated.

RADAR™ is the independent validation layer that produces that evidence. It continuously validates which DDoS attack vectors reach the target, delivers prioritized remediation guidance so the responsible team knows what to change and in what order, then revalidates to confirm the change has been made. Validation runs against live production without affecting availability or SLA response times, so it continues during business hours.

Want to learn more about how continuous DDoS validation reduces the risk of damaging downtime? Speak to an expert.

Key Takeaways about the Norway DDoS Attack

  • A DDoS attack against Norway’s shared government digital infrastructure began at 03:38 on 24 August 2026 and disrupted services in waves for more than 30 hours.
  • ID-porten, MinID, Maskinporten, Altinn, eSignering, and Digital postkasse were among twelve affected services, with knock-on effects reaching electronic prescription services.
  • The incident was the third DDoS attack against the same infrastructure since June 2026, and Digdir described it as two to three times larger than the previous one.
  • A pro-Russian group reportedly claimed responsibility on Telegram, and attribution remains unverified.
  • Consolidated login infrastructure routes the availability of many downstream services through one gateway, which makes independent validation of that gateway a business continuity question.

Frequently Asked Questions about the Norway DDoS Attack

A distributed denial-of-service attack hit the Norwegian Digitalization Agency’s shared infrastructure at 03:38 on 24 August 2026, disrupting ID-porten and eleven other national services for more than 30 hours.

ID-porten, MinID, Maskinporten, Altinn, eSignering and Digital postkasse were among the affected services, and knock-on effects reached online pharmacies and electronic prescription services.

Digdir stated that nothing indicated a security breach or a compromise of personal data, and that this type of attack aims to disrupt availability.

A pro-Russian group calling itself Server Killers reportedly claimed responsibility on Telegram. Norwegian authorities had not confirmed the claim, so attribution remains unverified.

Environments change between attacks. New services, integrations, endpoints and routing paths move the surface a mitigation policy has to cover, and a configuration that blocked an attack vector last month can fall out of alignment before the next attempt.

Incident response measures how quickly a team reacts once an attack is underway. Continuous DDoS validation establishes in advance which attack vectors bypass deployed protection, so the configuration can be corrected before the next attempt.

Stay Updated.
Get our Newsletter*

Recent posts