ZeroHour
The Recordpublished ()ingested

Large DDoS attack knocks Norwegian public services offline

highThreat actorimportance 62
AI summary · glm-5.3-flash

A large DDoS attack on Norwegian IT partner Vivicta disrupted 10 government services, including ID-porten used by over 4.5 million users, for 30+ hours.

Norway's Digitalisation Agency (Digdir) said a distributed denial-of-service attack that began Monday targeted the infrastructure of its IT partner Vivicta and lasted around 30 hours at varying intensity, with some services still affected Tuesday. Disrupted services included ID-porten, a national digital identity gateway used by more than 4.5 million people, which many government services and parts of the health sector, such as online pharmacies and the electronic prescription system, rely on for authentication. Digdir said attackers did not gain access to sensitive information, and it was the third DDoS incident since June, reportedly two to three times larger than the previous one. Attribution and possible links between the incidents remain unclear.

  • DDoS attack targeted Vivicta infrastructure hosting 10 Norwegian government digital services
  • ID-porten login gateway, used by over 4.5 million people, was affected
  • Health services relying on ID-porten authentication faced possible pharmacy and e-prescription disruptions
  • Third DDoS incident against Digdir services since June, reportedly 2-3x larger than the last
  • No indication attackers accessed sensitive information
VendorsVivicta
ProductsID-porten
OrganizationsDigdirVivicta
CountriesNorway
Full article377 words · extracted from therecord.media · click to collapse

A handful of Norwegian government services have been disrupted for more than a day after a large-scale cyberattack targeted the infrastructure used to operate them, authorities said.

The Norwegian Digitalisation Agency, known as Digdir, said the distributed denial-of-service (DDoS) attack began Monday and targeted the infrastructure of its IT partner, Vivicta. Such attacks flood servers with traffic in an attempt to make them unavailable to legitimate users.

Digdir said it was working with Vivicta to stabilize the affected systems, with some services gradually coming back online. The attack has continued for around 30 hours at varying levels of intensity and, as of Tuesday morning, was still affecting some services, according to Digdir's status page.

The incident disrupted 10 digital services used for verifying people's identities, logging into public services, exchanging data and documents between government agencies and businesses, accessing public records, and managing employee access.

Among the affected systems was ID-porten, a digital identification service that acts as a gateway to thousands of Norwegian government services. It allows people to verify their identity using services such as BankID and MinID and has more than 4.5 million users.

The disruption also affected parts of Norway's health infrastructure because several health services rely on ID-porten for authentication. Authorities warned of possible problems accessing online pharmacies and Norway's electronic prescription system.

It is the third DDoS incident to affect Digdir's services since June, according to Norwegian media.

"What is special about this latest attack, which has now been ongoing for a day, is that it is two to three times larger than what we experienced last time," Digdir press officer Are Kvistad told Norwegian public broadcaster NRK.

It was not immediately clear who was behind the attack or whether the recent incidents were connected or part of a broader campaign targeting Norway.

Digdir said the attackers had not gained access to sensitive information stored in the affected systems.

No previous article

No new articles

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/norway-cyberattack-ddos-government