Norway Says 12 Shared Public Services Were Disrupted by a Denial-Of-Service Attack

A distributed denial-of-service attack that began at 3:38 a.m. on Monday, Aug. 24, disrupted twelve shared digital services run by the Norwegian Digitalisation Agency, the agency said in a statement issued at 12:27 p.m. local time on Tuesday. The services are the common login, messaging and filing systems used across Norway's public sector.
The agency, known as Digdir, named the affected services as ID-porten, MinID, Maskinporten, the Contact and Reservation Register, eFormidling, ELMA, eInnsyn, Ansattporten and its self-service solution, together with Altinn, eSignering and Digital postkasse. They were completely unavailable for short periods, Digdir says, and partly available for most of the time, with logins taking longer than usual.
Digdir says the services are now stable, that some are still seeing disruption, and that work will continue until the situation is over.
"There is no indication that the attack has led to a security breach or that personal data has gone astray," director Frode Danielsen said in the statement, which was issued in Norwegian and is translated here. He said the purpose of this type of attack is to hit availability rather than to break into the systems.
This is the third time in a short period that this type of attack has been directed at Digdir's services, the agency says. It says it is working with its supplier Vivicta on measures to shield the services, and that it has notified NSM, Norway's national security authority, and the data protection authority Datatilsynet. Operating status is being published at status.digdir.no.
Digdir says it will evaluate the incident closely once it is over and consider further measures to reduce the risk of it happening again. Its statement does not say who was behind the attack.
