Norway’s public services were disrupted by a cyberattack that affected access to government, welfare and healthcare platforms from the early hours of Monday, 3 August. The Norwegian Digitalisation Agency (Digitaliseringsdirektoratet, Digdir) identified the incident as a distributed denial-of-service attack, or DDoS, targeting the infrastructure used to operate ID-porten.
The attack generated artificial traffic intended to overload the system and prevent legitimate users from reaching digital services. According to Digdir’s updates reported by Aftenposten, all affected public platforms had returned to normal operation by Tuesday morning.
The cyberattack affected Norway’s shared digital infrastructure
The attack targeted ID-porten, Norway’s common authentication gateway for public services, through the network infrastructure of Digdir’s operational partner Vivicta.
ID-porten allows residents to use electronic identification systems such as BankID and MinID when accessing government websites. It is used by more than 4.5 million people, connects users to around 5,000 public services and typically handles approximately 30 million logins each month.
The disruption also affected MinID, Altinn, eFormidling, the Contact and Reservation Register (Kontakt- og reservasjonsregisteret), eInnsyn, Maskinporten, ELMA, Ansattporten and several self-service platforms.
Most systems were functioning again by Monday evening, although Digdir continued to report instability and unusually high error rates in ID-porten. On Tuesday morning, the agency said that all public services had returned to full operation.
Some users connecting through data centres in Germany, Switzerland, the Netherlands and Belgium continued to experience difficulties later on Tuesday. Digdir said it was working with its operating partner to adjust or remove possible geographical blocking measures introduced during the response.
Welfare and healthcare services were also disrupted
The failure of the common authentication systems caused login problems for the Norwegian Labour and Welfare Administration (Nav) and other institutions, including the Norwegian Tax Administration (Skatteetaten).
The effects also reached the healthcare sector. Helsenorge, HelseID, the electronic prescription service Reseptformidleren, the national summary care record Kjernejournal and the patient questionnaire platform ePROM experienced problems, according to operational notices reported by Digi.no.
The disruption affected pharmacies and temporarily prevented healthcare personnel from accessing some information through Kjernejournal. In particular, staff could not retrieve relatives’ contact details when treating patients who were unable to provide the information themselves.
The incident did not simply make individual websites unavailable. It interrupted the common infrastructure through which residents identify themselves, access welfare services, manage tax matters and interact with the healthcare system.
A second DDoS incident in six weeks
The August cyberattack was the second major DDoS incident affecting Digdir’s shared systems in about six weeks.
In June, Vivicta’s network infrastructure was targeted by a similar attack. ID-porten and several other services were then partly or completely unavailable from Saturday afternoon until Monday morning.
Digdir said the June incident had not resulted in a security breach or the loss of personal data. The Norwegian Data Protection Authority (Datatilsynet) and the Norwegian National Security Authority (Nasjonal sikkerhetsmyndighet, NSM) were notified under established procedures.
The agency described its services after that attack as part of Norway’s critical social infrastructure, underlining how failures in shared digital components can spread rapidly across otherwise separate public institutions.
The latest disruption again illustrates the advantages and risks of a highly integrated digital administration. Common systems make it easier for residents to access thousands of services with the same electronic identity. However, concentrating authentication and data exchange around a limited number of components also means that an attack against one provider can become a nationwide problem involving government administration, welfare and healthcare.
Norwegian authorities will now have to assess whether the measures used to limit the attack were sufficient and how the resilience of these shared systems can be strengthened. As Nordic public administrations continue to expand digital access, maintaining alternative routes to essential services will remain an important part of cybersecurity and public-sector preparedness.





