A large distributed denial-of-service (DDoS) attack disrupted Norway’s shared digital government infrastructure for several days in late August, affecting services used across the public sector and exposing the systemic dependencies created by highly centralised digital government platforms. The attack against the Norwegian Digitalisation Agency (Digdir) began at 03:38 CEST on 24 August and continued until approximately 19:30 on 26 August. Digdir reported that its services remained largely available but experienced periods of significant disruption, with some services becoming completely unavailable for short periods.
The incident affected a broad range of Digdir’s shared digital services, including ID-porten, Norway’s public-sector authentication platform; MinID; Maskinporten; the Contact and Reservation Register; eFormidling; ELMA; eInnsyn; Ansattporten; and self-service solutions. Other platforms depending on Digdir infrastructure, including Altinn, eSignering and the national digital mailbox, were also affected. Users experienced failed connections, slow responses and prolonged login times, demonstrating how disruption to a relatively small number of shared digital components can cascade across multiple government services.
Digdir operates critical digital building blocks used by public authorities throughout Norway. ID-porten, for example, provides authentication for a wide range of public services, while other shared solutions enable secure digital communication, electronic signatures, data exchange and access to public information. The incident therefore went beyond the disruption of an individual government website: it affected shared digital infrastructure on which multiple public services depend. Digdir itself describes these common solutions as part of critical societal infrastructure.
Digdir worked throughout the incident with its operations provider Vivicta to shield the infrastructure from malicious traffic and maintain service availability. The agency subsequently reported that the attack appeared to have ended and that its solutions were returning to normal operation, although some traffic from outside Norway continued to experience disruption. Digdir also stated that the objective of a DDoS attack is to affect availability rather than penetrate systems, and reported no indication of a security breach or compromise of personal data. The Norwegian National Security Authority (NSM) and Data Protection Authority were notified.
The incident is particularly notable because it was the third DDoS attack against Digdir’s shared solutions in a short period. Similar attacks occurred in June and on 3 August. The August attack temporarily disrupted ID-porten and consequently affected access to services including Helsenorge, NAV and the Norwegian Tax Administration. Digdir said it would conduct a detailed evaluation with Vivicta and other partners to identify additional measures to reduce the risk of future incidents.
Why does it matter ?
The attacks illustrate the cascading nature of vulnerabilities in centralised digital-government ecosystems. Services that were not themselves the direct target can become inaccessible when they depend on a shared authentication, communication or data-exchange layer. The disruption reported by Altinn and the Norwegian Tax Administration demonstrates how attacks against common infrastructure can propagate across organisational boundaries and affect citizens’ and businesses’ ability to interact with government. This makes availability, redundancy, resilience and incident-response capacity increasingly important dimensions of digital-government policy.
This case demonstrates how shared digital infrastructure can create efficiency and interoperability while simultaneously creating points of systemic dependency whose disruption can have consequences across multiple public services. The case is therefore relevant to wider debates on digital resilience, critical infrastructure protection, cybersecurity governance and the security of digital public services. It also highlights the importance of designing government digital ecosystems not only for functionality and interoperability, but for resilience against deliberate disruption.
The Norwegian case further illustrates the increasingly blurred boundary between cybersecurity and digital governance. Protecting authentication systems, data-exchange platforms and other shared digital building blocks is essential to maintaining citizens’ access to the state and, ultimately, trust in digital government. For Digital Watch, the repeated attacks against Digdir offer a useful case study of how governments can strengthen resilience through incident preparedness, cooperation with private-sector providers and post-incident evaluation, while raising broader questions about concentration risk, dependencies on shared infrastructure, redundancy and the governance of increasingly interconnected digital public services.
The immediate significance of the incident lies less in attribution (no official attribution for the attack as it stands) than in what it demonstrates: the availability of shared digital government infrastructure, as a matter of public-service continuity, institutional resilience and public trust.