A sustained denial-of-service campaign against Norway's shared government infrastructure provider has disabled the national digital ID gateway for more than 30 hours, cutting authentication access to health, banking, and public-records systems used by 4.5 million citizens.

Intelligence Lead

A distributed denial-of-service attack that began at 03:38 CEST on 24 August has disabled or degraded ten digital services operated by Norway's Digitalisation Agency (Digdir), including ID-porten, the mandatory authentication gateway for most Norwegian government platforms. Digdir has confirmed this is the third DDoS incident to hit its infrastructure since June and, by its own account, two to three times larger in scale than the previous strike. No data exfiltration has been confirmed, but the outage has cut authentication access for services spanning health records, tax administration, and inter-agency document exchange for a country whose digital-ID system underpins nearly all interaction between citizens and the state.

Situation Report

Digdir confirmed the attack targeted the infrastructure of Vivicta, the private IT operator that hosts and maintains the agency's shared technical platform, rather than Digdir's own systems directly. ID-porten, which authenticates more than 4.5 million users through BankID and MinID credentials and serves as the entry point to thousands of government services, was among the hardest hit. Altinn, the business-to-government reporting platform, and Helsenorge, the national health portal, were also degraded, with CERT-affiliated health authorities warning of disruption to online pharmacy access and Norway's electronic prescription system.

Digdir press officer Are Kvistad told Norwegian broadcaster NRK the attack was two to three times larger than the incident the agency experienced in its prior encounter, and that intensity has varied over more than 30 hours rather than arriving as a single spike. As of Tuesday morning local time, most services had been stabilized, though ID-porten and the eSignering digital-signature service remained partially inaccessible. Digdir said no sensitive data stored in the affected systems had been accessed, distinguishing this incident from an intrusion or exfiltration event.

This is the third such incident affecting Digdir's shared infrastructure since June 2026, following an earlier attack on Vivicta's network and a recurrence roughly six weeks ago. Norwegian authorities have not attributed the current wave to a specific actor, state or criminal, and have not said whether the three incidents form a single sustained campaign or separate attacks converging on the same soft target. Norway's reliance on ID-porten as a single authentication chokepoint for government, health, and financial-adjacent services means a successful denial-of-service action against one contractor can cascade across sectors with no operational relationship beyond shared infrastructure.

Background & Context

Digital-ID gateways have become a recurring target across Nordic and Baltic states, reflecting both their high-value, low-cost profile for disruptive actors and the outsized civic impact of even brief outages. Norway's escalating pattern of attacks on Vivicta-hosted infrastructure since June sits alongside Latvia's confirmed CSDD data breach, disclosed in mid-August, which triggered the resignation of that agency's supervisory board and a public commitment from its director to step down once the investigation concludes.

The escalating scale across three incidents in ten weeks fits a pattern security researchers associate with either a probing campaign testing defensive responses ahead of something more consequential, or an actor returning once earlier hardening proved incomplete. Norway's NATO membership and its role hosting critical northern-flank military and energy infrastructure make its civilian digital backbone a plausible target for state-linked disruption that stops short of clear attribution, the deniable, below-threshold profile that has characterized much DDoS activity attributed to Russia-aligned hacktivist collectives against European government targets since 2022. Digdir's dependence on a single contractor for infrastructure hosting and monitoring also echoes the accountability dispute now playing out in Latvia, where concentration of critical functions with one vendor has created both efficiency and a single point of failure.

Analysis & Assessment

The absence of confirmed data exfiltration lowers this incident's severity relative to an intrusion, but sustained denial of authentication access to health, tax, and inter-agency systems for a NATO member state is itself a strategically relevant outcome regardless of attribution. A sufficiently resourced actor gains useful intelligence from each iteration: how long recovery takes, which services degrade first, and how the shared-infrastructure model performs under sustained load.

The escalating scale is the most analytically significant detail. Larger attacks against the same provider suggest either a single actor iterating its capability or a wider pool of actors recognizing Digdir's shared systems as a repeatable soft target. Norway's eventual response, whether limited to technical hardening at Vivicta or extended to a broader review of single-vendor dependency across government services, will indicate how seriously officials assess the pattern.

If the incidents prove connected to a state-tolerated campaign, Norway's response would carry weight beyond its own borders, given how many Nordic and Baltic governments run structurally similar centralized digital-ID systems. Confirmed state linkage would likely sharpen debate inside NATO's cyber-defense structures over whether attacks on shared civilian authentication infrastructure belong within the alliance's collective-defense threshold, a question that has stayed unresolved through previous DDoS waves against member states.