DDoS against Norwegian government IT infrastructure – status
status.digdir.no
status.digdir.no
> ID-Porten: When One Gateway Controls Everything
> At the center of the disruption is ID-porten — the national login gateway operated by Norway's Digitaliseringsdirektoratet (Digdir), the government agency responsible for public-sector digitalization. ID-porten functions as the single sign-on portal through which Norwegian citizens authenticate themselves to access public digital services.
It seems to be a corporate service provider that's a dependency for many other services.
The identity portal is administered by the department for digital services, but hosted at a commercial provider, Vivicta (formerly TietoEvery, formerly Tieto and Every - Consulting companies from Finland and Norway).
Ed: I'm guessing yes?
https://vayla.fi/-/new-public-transportation-travel-card-sys...
> Det har siden kl. 01 mandag 3. august pågått et tjenestenektangrep (DDoS) som rammer ID-porten som driftes hos Digdirs driftspartner Vivicta.
> Since 0100 hours Monday August 31st there's been an ongoing DDoS attack which affects the ID-Portal which is run/hosted by DepDig's (Department of digital services') service provider Vivicta.
(My translation)
Ed: just realized Vivicta is TietoEvery with a haircut and new shoes:
Also something designed to withstand something does not imply it survives other somethings.
Up to the moment it has not been the operation adopted which would make it weird.
On who would do it then, anyone who benefits from instability. From corporations trying to sell flocked uped sytems, politicians, etc.
There is one south american country who was attacked exactly this way before their head of the government was kidnapped.
More likely this more politically motivated and backed up by money and more capable groups
AI kiddies, more likely. in some ways script kiddies weren't a thing for a decade or more as the attack surface got considerably harder to penetrate, and the model changed for pay-to-play attacks. AI simply caused the bottom of that market to fall further, and effectiveness to increase.
When it rains dams fill up. The water is drained into shafts with turbines, and electricity is generated.
However, even though we are big on hydroelectricity percentage wise I’m not sure it’s all that vast an amount of electricity on a global scale. We are a pretty small country after all.
According to Wikipedia, the Norwegian electricity sector had 40.26 GW installed capacity as of 2021 and was producing 157.113 TWh in the same year. [1]
Great Britain had 74.8 GW installed capacity in 2023 and was producing 292.7 TWh in 2023. [2]
France was producing 537.7 TWh in 2020. [3]
Germany was producing 488.5 TWh in 2024. [4]
[1]: https://en.wikipedia.org/wiki/Electricity_sector_in_Norway
[2]: https://en.wikipedia.org/wiki/Electricity_in_Great_Britain
[3]: https://en.wikipedia.org/wiki/Electricity_sector_in_France
[4]: https://en.wikipedia.org/wiki/Electricity_sector_in_Germany
A shorter attack won't make as many news headlines, either.
Botnets are services now, a business. They gain customers by their effectiveness and resilience.
For $$50-100 you can deny service to a lot of big sites and services.
Flare + BleepingComputer 2026, Kaspersky, StormWall, and others show that the DDoS-as-a-service market is highly commoditized and prices are extremely low:
A short test / basic attack on a website: $5–25.
Daily attack on a poorly protected target: around $100/day.
A more robust or well-protected target: $200–500 per day.
Monthly subscription to booter/stresser services: often $15–40 (sometimes even less); premium packages cost hundreds of dollars.
Larger or longer-term campaigns or infrastructure: thousands of dollars.
On the governmental level these money are almost nothing if you want to hurt someone else…
do we really need to ask?
clearly it's the Danes