Locked out: a summer of DDoS attacks against Norway

Revontulet · Incident timeline

Move through the incidents with the arrows, the dots, or by swiping the cards. The map highlights when and where each one took place. No threat emerges in isolation.

Swipe or use the arrows to move through the timeline.

On the morning of Monday 3 August, pharmacists across Norway were struggling to pull up prescriptions, and people trying to reach Helsenorge, Altinn or their municipal services found that their login went nowhere. Beneath every one of those failures lay the same component. ID-porten, the national login gateway that more than 4.5 million people use to reach some 5,000 public services, was under a denial-of-service attack, running since about one in the morning against the infrastructure of Digdir's operations partner. Most services were back that evening, and everything was declared normal by nine on Tuesday morning.

A failure at that layer suspends ordinary life in ways that accumulate by the hour: prescriptions wait, benefit applications wait, filings miss their deadlines, and there is no analogue fallback to absorb the load. Even one such day would deserve scrutiny; Monday's was the fourth episode of its kind in nine weeks. Norsk Tipping, the state-owned company that holds Norway's gambling monopoly and channels its surplus to sport, culture and humanitarian causes, was hit on the evenings of 2 June and 3 June. After the second attack, the company's press chief said someone had clearly singled them out and was bombarding them with traffic. The ID-porten infrastructure at Digdir's operations partner, the same login layer that failed this week, was taken down for roughly 42 hours over the weekend of 20 to 22 June. Norsk Tipping was hit again on 2 August, closing Oddsen for the afternoon, and the second attack on ID-porten followed within the day. Every incident in the series is an availability attack: the services were flooded rather than penetrated, and Digdir has been explicit that no systems were intruded on and no personal data was compromised.

What we do not know is who is doing this. None of the incidents has been claimed. Digdir says it has no indication of who is behind the attacks and declines to speculate. Denial-of-service capacity is also cheap: Europol's Operation PowerOFF, in which Kripos took part this April, identified over three million users of DDoS-for-hire services worldwide, 78 of them Norwegian. The candidates therefore range from criminals with rented capacity to state actors testing how Norway reacts. Vivicta, the operations partner under attack, told Aftenposten that attacks of this type are generally the work of foreign powers or other well-resourced actors, with motives that can be political, economic, or aimed at creating uncertainty and instability. The contrast with last September is instructive: when Høyre's website went down six days before the election, the pro-Russian group NoName057(16) claimed the attack the same day. The Swedish fact-checking outlet Källkritikbyrån has documented a wider run of such self-claimed DDoS attacks on Nordic targets. The current wave is conspicuously unclaimed. What the incidents themselves support is narrower. The targeting is learned rather than opportunistic: the same supplier has been hit twice, the same company three times. The timing runs to nights, weekends and the middle of the summer holidays. ID-porten, meanwhile, is the doorway through which citizens reach almost every public service, from health records and prescriptions to taxes, benefits and unemployment support, at around 30 million logins a month; it is what you attack if you want to show that one pressure point can take out much of digital Norway at once.

Norway's own services described the backdrop in February. NSM's Risiko 2026 warned that Russian intelligence may attempt sabotage against Norwegian targets this year, and flagged dependence on external suppliers as a vulnerability in itself. The Bremanger dam intrusion of April 2025, which PST attributed to pro-Russian actors last August, showed a willingness to reach into physical infrastructure. Norway makes an obvious target: NATO's northern flank, a principal supplier of Europe's gas, a visible supporter of Ukraine. Reading the summer's attacks against that backdrop is reasonable; attributing them to it is not, at least not yet.

Both of the summer's targets are in practice public services, and the attacks all aimed at the same thing, denying Norwegians access: Norsk Tipping is a state-owned company that a large share of the population uses, and ID-porten is the way into nearly every public service. Viewed independently, each of these incidents was handled competently. To form a complete picture, the incidents must, however, be viewed in context of each other. The gap is on the public record: Digdir's own risk assessment for 2025 pointed to a limited ability to identify and detect advanced digital attacks, and NTNU's Peggy Lill Sandbekke, speaking to Aftenposten about Monday's attack, called for more sharing of risk assessments and experience from attacks, noting that good risk assessments require knowledge of other incidents.

Getting a complete picture across incidents and domains is the premise Revontulet was built on, and why we say that no threat emerges in isolation. It is also why we built Cortexia for cross-domain correlation rather than single-feed monitoring.

The type of attacks seen over the summer are not isolated to Norway. Similar attacks are running across Europe, in a landscape of wars and alliances where criminal groups, state-backed proxies and state actors are increasingly hard to tell apart. Norway's outage came weeks after France summoned Russia's ambassador and the EU sanctioned nine individuals and four entities over a campaign of espionage and sabotage across a dozen European countries that France's foreign minister said the FSB had orchestrated. Reading any one of these events well requires holding the others in view.

The prescriptions loaded again on Tuesday morning, and with them the health records, tax filings and benefit applications of everyone who had been locked out. Little else about the episode is reassuring: the attacks repeat, the attackers learn, and the targets are the services people depend on every day. The next attack must be prevented, and the harm limited when it inevitably comes. Both depend on intelligence that connects each incident to the ones before it and to the wider European picture, and on sharing what every attack teaches before the next one arrives. Good intelligence, evidence and shared practice are what shorten the next outage from days to hours, and what turn each attack into something learned rather than something merely endured.

Next
Next

Prevention After Berlin