Norway's government login systems knocked offline by third DDoS attack in months
A flood of junk traffic hit the agency that runs Norway's public-sector logins and digital ID, snarling tax and citizen services since Monday morning.

Key points
- A distributed denial-of-service attack began hitting Norway's shared government digital infrastructure at 03:38 local time on Monday.
- The target was Digitaliseringsdirektoratet (Digdir), the agency that runs national services including ID-porten logins and eSignering electronic signatures.
- Digdir director Frode Danielsen says there is no sign of a break-in or personal data being stolen.
- This is the third such attack on Digdir in recent months, following incidents in June and on 3 August.
- Knock-on outages hit Altinn, the main citizen-to-government platform, and Skatteetaten, the tax authority.
Someone spent Monday morning pointing a firehose at the plumbing of the Norwegian state.
A large distributed denial-of-service attack, meaning a flood of junk internet traffic designed to knock a website offline by overwhelming it, hit Norway's shared government digital infrastructure at 03:38 local time on Monday. It is still causing problems.
The target was Digitaliseringsdirektoratet, known as Digdir, the agency that runs the digital rails most Norwegians use to deal with their government. That includes ID-porten, the national login service, and eSignering, which handles legally binding electronic signatures. It also covers secure digital mail from public bodies and the pipes that let one agency share data with another.
Digdir's operations partner Vivicta was hit at the same time. According to reporting from BleepingComputer, several services went completely dark for short stretches before engineers stabilised them.
What are ordinary Norwegians seeing?
Slow logins, failed connections and sluggish servers, mostly when trying to reach public services. If a page times out, wait and try again rather than assuming your account is broken.
ID-porten and eSignering are still partially inaccessible at the time of writing. Two large downstream services have posted their own warnings. Altinn, the platform citizens and businesses use to talk to government agencies, is flagging login problems. Skatteetaten, the tax authority, is telling users on its website to try again later.
None of this means anyone's data has been touched. A DDoS attack is closer to a mob blocking the door of a shop than a burglary. The shop's safe is fine, but no customer can get in.
Did the attackers actually break in?
No, according to Digdir. Director Frode Danielsen says the investigation so far shows no security breach and no compromise of personal data.
That matches the shape of the attack. DDoS floods aim to make a service unavailable, not to steal from it. Digdir has notified the Norwegian National Security Authority (NSM) and the Norwegian Data Protection Authority (Datatilsynet) as required.
Who is behind it?
Nobody official is saying. There is no confirmed attribution. Norwegian media have speculated about Russian involvement, which is plausible given the pattern of pro-Russia hacktivist groups hitting Nordic and Baltic government sites over the past two years, but plausible is not proof.
What is documented is the drumbeat. This is the third DDoS attack against Digdir in a short window.
| Date | Target | Status |
|---|---|---|
| June 2025 | Digdir infrastructure | Prior DDoS incident |
| 3 August 2025 | Digdir infrastructure | Prior DDoS incident |
| Monday, this week (03:38 CEST) | Digdir and Vivicta | Ongoing, partial outages |
Common questions
Is my Norwegian tax or ID data at risk?
Digdir says no. The attack is aimed at making services unreachable, not at stealing data, and the agency reports no sign of a breach.
What should I do if I can't log in with ID-porten?
Wait and try later rather than repeatedly retrying, which adds to the load. Digdir's status page and incident report page carry live updates on which services are working.



