Norwegians woke Monday to broken logins and stalled government services as a third denial-of-service wave in two months hit the country’s shared public-sector infrastructure.
The outage began at 03:38 CEST on August 24 and landed on Digdir, the Norwegian Digitalisation Agency, working with provider Vivicta. Two earlier rounds hit in June and on August 3.
Because Digdir operates common building blocks, including ID-porten, MinID, Maskinporten, eFormidling, and the Contact and Reservation Register, one attack ripples widely. Altinn, the main channel linking citizens, businesses, and agencies, went down too, and every service leaning on ID-porten saw login problems. The summer’s earlier incidents produced the same knock-on pain at Helsenorge, NAV, and Skatteetaten.
The agency says the fight is over availability, not data. No breach or exposure of personal information has been found, and both the National Security Authority and the Data Protection Authority have been notified.
Moscow’s hand has been suggested in Norwegian press coverage, but investigators have made no official call.
Defenders are watching the pattern, not the single outage. Repeated hits on a shared dependency force constant filter changes and keep legitimate users locked out, which is how DDoS turns into a national availability problem.
