A Norway DDoS attack on Digdir, the Norwegian Digitalisation Agency, began at 03.38 CEST on Monday and proceeded in waves for more than 30 hours, knocking out or degrading a dozen government digital services and causing knock-on disruption across the wider public-sector ecosystem. It is the third such attack to hit Digdir’s infrastructure in recent months, following one in June and another on 3 August.
Digdir, formally Digitaliseringsdirektoratet, operates the shared digital backbone of the Norwegian state: public-service logins, electronic IDs and signatures, secure digital mail, government forms, public-record access, and data exchange between agencies. When something hits that infrastructure, it is not one service that wobbles, it is most of them at once.
Twelve services down, with pharmacy systems caught in the crossfire
According to MazeBolt, twelve services went down or were degraded during the attack, among them ID-porten, MinID, Maskinporten, Altinn, eSignering, and Digital postkasse. The blast radius extended beyond government portals: online pharmacies and electronic prescription services were also caught in the disruption, illustrating how thoroughly Norway’s public digital infrastructure is woven into everyday life.
Digdir press officer Are Kvistad described the attack as two to three times larger than the previous incident targeting the same systems, MazeBolt reports. That framing helps explain why, even with mitigation measures in place from earlier incidents, services struggled to hold. Several were completely unavailable for short periods; many have since been stabilised, though ID-porten and eSignering remained partially inaccessible as of Digdir’s most recent update.
Users encountering the effects of the Norway DDoS attack on Digdir services reported failed connections, slow server responses, and unusually long login times. Anyone needing to track recovery can consult Digdir‘s operating status page and its dedicated incident report page.
No data breach, but official notifications filed
Digdir director Frode Danielsen said the investigation found no indication of a security breach affecting the agency’s systems and no compromise of personal data. A DDoS attack aims to exhaust resources and deny access rather than to infiltrate; that distinction matters for the millions of Norwegians whose records sit inside these systems, even if the disruption itself was severe enough.
The Norwegian National Security Authority (NSM) and the Norwegian Data Protection Authority (Datatilsynet) have both been notified. No official attribution has been made for the attack, though Norwegian media have speculated about potential Russian involvement. Digdir has not confirmed any attribution.
Services dependent on Digdir’s infrastructure but not directly targeted also felt the pressure. Altinn, Norway’s central platform for communication between citizens, businesses, and government agencies, published a warning about login issues and pointed users to Digdir’s status page. Skatteetaten, Norway’s tax administration agency, posted a similar notice on its website, urging users to try again later.
A pattern forming around Norway’s digital core
Three attacks in roughly two months, each apparently larger than the last, against the same organisation’s infrastructure, raises obvious questions about why the Norway DDoS attack pattern is accelerating and whether existing defences are being adjusted quickly enough between incidents. Danielsen’s confirmation that this was the third in a short run suggests the agency is dealing with a persistent, deliberate campaign rather than opportunistic noise.
The breadth of the affected services underlines just how much weight Digdir’s infrastructure carries. ID-porten alone is the gateway through which Norwegians authenticate into hundreds of public and private services. When it slows or fails, the effects ripple into healthcare, taxation, business registration, and beyond, as the electronic prescription disruption this week made plain. With NSM now in the loop for a third time, and the attack scale apparently growing, the pressure on Digdir and its operations provider Vivicta to harden their defences before a fourth incident arrives is considerable.

