A large distributed denial-of-service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, affecting services used by the public sector.
The attack started at 03.38 CEST on Monday and has targeted the infrastructure supporting services operated by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider, Vivicta.
Digdir operates Norway’s shared digital government infrastructure, including public-service logins, electronic IDs and signatures, secure digital mail, government forms, public-record access, and data exchange between agencies.
In an announcement published earlier today, the organization states that several services were completely unavailable for short periods.
The agency says many affected systems have now been stabilized, although some services, like ID-porten and eSignering, remain partially inaccessible.
As a result of the attack, users may encounter errors such as failed connections, slow server responses, and unusually long login times.
For live updates on the availability of Digdir services, people may consult the services' operating status page as well as the incident report page with updates from Norway's Directorate for Digitization.
Digdir director Frode Danielsen says the investigation into the incident showed no indication of a security breach affecting the organization’s systems or any compromise of personal data.
Danielsen added that this is the third DDoS attack targeting Digdir recently, following one in June and another on August 3.
The Norwegian National Security Authority (NSM) and the Norwegian Data Protection Authority (Datatilsynet) have been notified accordingly.
... continue reading