Norway has been dealing with a significant cyber incident affecting several government digital services over the past few days. A spokesperson for Norway’s Digitalization Agency, Digdir, said the disruption began on Monday and continued through Wednesday, when a pro-Russian group publicly claimed responsibility.
According to Digdir, the attack focused on overwhelming traffic to block access to online services. Even so, the agency reported it managed to keep its platforms running “practically all the time,” limiting long-term downtime for users.
What happened to Norway’s public digital services
Are Kvistad, a spokesperson for Digdir, stated that the denial-of-service activity started on Monday and has been ongoing for roughly three days. The purpose of a denial-of-service attack is to flood systems with traffic so that services become slow or unavailable for legitimate users.
In this case, the impact targeted multiple Digdir solutions used by the public sector. One key service described by Digdir enables citizens to use a single login across multiple public services, making it an important entry point for online government interactions.
Kvistad characterized the incident as the biggest attack against Digdir solutions the agency has experienced.
Traffic flooding as the core tactic
The denial-of-service approach centered on generating massive volumes of traffic toward Digdir. That pressure is typically intended to exhaust system capacity and disrupt user access.
Despite the intensity of the attempted disruption, Digdir said it successfully maintained service availability for users for almost the entire period. The spokesperson emphasized continuity, noting that the services stayed up “practically all the time.”
Claim of responsibility from a pro-Russian group
On Wednesday, widely reported Norwegian media covered a Telegram post in which a pro-Russian hacking group calling itself Server Killers claimed responsibility for the attack. The group also stated that it had declared cyber war on Norway.
In the same claim, the group linked its action to Norway renewing its security cooperation with Ukraine on Aug. 23. The statement positioned the attack within a broader narrative of conflict-linked cyber operations.
Norway and Ukraine: cooperation in focus
Norwegian officials did not comment on the group’s claim by the time of publication. However, the timing of the cyberattack aligns with major cooperation developments between Norway and Ukraine.
During a visit to Kyiv, Prime Minister Jonas Gahr Støre announced that Norway would provide 85 billion Norwegian crowns (about 9.2 billion US dollars) to Ukraine starting next year. This would be the third consecutive year of such support.
Both countries also committed to additional cooperation related to drone technology and other forms of modern warfare, underscoring the political and strategic context in which the cyberattack unfolded.
Why European countries are on high alert
The incident sits within a broader European cybersecurity environment where authorities have reported heightened risks associated with sabotage and hostile activity. Since Russia’s full-scale invasion of Ukraine in February 2022, officials across the continent have described increased malicious campaigns aimed at undermining support for Ukraine.
In general terms, governments say these operations seek to spread fear and discord in European societies and to drain the time and resources available for investigation and defense.
Against this backdrop, the pro-Russian DDoS Norway incident illustrates how disruptive cyber tactics can target public-facing services that citizens rely on daily.
Past suspected incidents involving Russian-linked activity
Norway’s incident is not the only case in the region where authorities have alleged Russia-linked cyber involvement. In 2025, Norwegian authorities said Russian hackers were likely behind suspected sabotage at a dam in the country.
In that earlier event, attackers reportedly gained access to a digital system that remotely controls one of the dam’s valves, opening it to increase water flow. Police said a short video—about three minutes—was published on Telegram showing the dam’s control panel, alongside a marker identifying a pro-Russian cybercriminal group.
Denmark has also faced similar accusations. Last year, Danish authorities blamed Russia for cyberattacks targeting infrastructure and websites in Denmark in 2024 and 2025.
Officials said pro-Russian group Z-Pentest carried out a “destructive attack” on a water utility company in 2024. They also stated that the group NoName057(16) was responsible for a cyberattack on Danish websites ahead of the 2025 local elections. Danish officials said those groups have links to the Russian state.
Impact on citizens and government operations
For users, denial-of-service attacks can mean difficulty accessing online government services, ranging from identity and login features to other digital public offerings. When attacks focus on centralized authentication, even partial service degradation can affect how quickly citizens can complete routine tasks online.
In this case, Digdir’s assessment that services remained available for nearly the entire period suggests that mitigation measures—such as traffic handling and defensive capacity—may have helped prevent prolonged outages.
Even when uptime is largely preserved, repeated traffic flooding attempts can still increase operational strain and require sustained monitoring by security teams.
What to watch next
Although the claiming group has tied the incident to Norway’s security cooperation with Ukraine, authorities had not publicly confirmed responsibility by the time of reporting. Still, the public claim and the timing underline how cyber operations may be used as part of a wider contest of influence.
In the coming days, investigators may focus on technical indicators, traffic patterns, and system logs to better understand the attack’s origin and scope. For Digdir and other public service providers, the priority remains maintaining resilience so that essential services—including cross-service login capabilities—stay accessible under pressure.
Conclusion
The pro-Russian DDoS Norway incident shows how denial-of-service tactics can target digital public infrastructure with the goal of disrupting access. Digdir reported that the attacks were the largest it had experienced, yet it said the services stayed online for nearly all of the time.
Meanwhile, the broader European cybersecurity context—marked by allegations of sabotage and state-linked cyber activity—continues to keep governments on high alert as cooperation with Ukraine remains a key geopolitical factor.
