Massive DDoS Attack Disrupts Norwegian Public Services, Including Identity Gateway
A large-scale distributed denial-of-service (DDoS) attack has crippled Norwegian public services for over a day, impacting critical infrastructure like the national identity gateway.

Norwegian public services experienced significant disruptions for more than 24 hours due to a large-scale distributed denial-of-service (DDoS) attack targeting the infrastructure of the Norwegian Digitalisation Agency (Digdir) and its IT partner, Vivicta. The attack, which began on Monday, flooded servers with traffic, rendering numerous essential digital services unavailable to citizens and businesses.
The distributed denial-of-service (DDoS) attack specifically targeted the infrastructure managed by Vivicta, a key IT partner for Digdir. These types of attacks aim to overwhelm servers with a flood of illegitimate traffic, making them inaccessible to legitimate users. Digdir confirmed the incident and stated that its teams were working diligently with Vivicta to restore system stability, with some services gradually coming back online as of Tuesday morning.
At its peak, the attack had been ongoing for approximately 30 hours, affecting services crucial for daily life and government operations. Among the most significantly impacted systems was ID-porten, Norway's primary digital identity service. ID-porten acts as a gateway for millions of Norwegians to access thousands of government services, requiring users to authenticate via services like BankID and MinID. Its disruption meant many citizens could not log in to essential public portals.
The repercussions of the attack extended to Norway's healthcare sector, as numerous health services rely on ID-porten for user authentication. This led to potential difficulties for individuals attempting to access online pharmacies and the national electronic prescription system, highlighting the interconnectedness of digital public infrastructure.
This incident marks the third DDoS attack to affect Digdir's services since June, but authorities noted that the current attack was notably larger than previous ones. Digdir press officer Are Kvistad told Norwegian broadcaster NRK that the current attack was "two to three times larger than what we experienced last time," indicating a significant escalation in the scale and intensity of the threat.
While the attack caused widespread disruption, Digdir emphasized that the attackers did not gain access to any sensitive information stored within the affected systems. The focus remained on restoring service availability and investigating the source of the prolonged and intense attack.
Authorities have not yet identified the perpetrators behind the attack or determined if it is linked to previous incidents targeting Digdir. The lack of immediate attribution leaves open the possibility of a coordinated campaign against Norway's digital infrastructure, though no specific threat actor has been named.
The incident underscores the vulnerability of critical public digital infrastructure to large-scale DDoS attacks and the cascading impact such disruptions can have across essential services, from identity verification to healthcare access.