There's some interesting commentry at https://www.techtimes.com/articles/322754/20260803/norway-id... , which suggests that the widespread outage is due to a single point of failure: > ID-Porten: When One Gateway Controls Everything > At the center of the disruption is ID-porten — the national login gateway operated by Norway's Digitaliseringsdirektoratet (Digdir), the government agency responsible for public-sector…
Yes, it's a single point of failure by design - but has been pretty stable mostly - with this and a previous attack in June being exceptions. The identity portal is administered by the department for digital services, but hosted at a commercial provider, Vivicta (formerly TietoEvery, formerly Tieto and Every - Consulting companies from Finland and Norway). https://www.agilitaspe.com/index.php?id=136
DDoS against Norwegian government IT infrastructure – status
71–80 of 81 posts
Re: DDoS against Norwegian government IT infrastructure – status
#72Re: DDoS against Norwegian government IT infrastructure – status
#73Earlier quoted context omitted.
Yes, it's a single point of failure by design - but has been pretty stable mostly - with this and a previous attack in June being exceptions. The identity portal is administered by the department for digital services, but hosted at a commercial provider, Vivicta (formerly TietoEvery, formerly Tieto and Every - Consulting companies from Finland and Norway). https://www.agilitaspe.com/index.php?id=136
Evry, not Every.
Re: DDoS against Norwegian government IT infrastructure – status
#74Earlier quoted context omitted.
It hasn't been majorly like that in twenty years. Botnets are services now, a business. They gain customers by their effectiveness and resilience. For $$50-100 you can deny service to a lot of big sites and services.
I've seen people say this but no proof of it. Could I really take down Stack Overflow for $50? Oh wait, it took itself down for free.
Re: DDoS against Norwegian government IT infrastructure – status
#75The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?
Flare + BleepingComputer 2026, Kaspersky, StormWall, and others show that the DDoS-as-a-service market is highly commoditized and prices are extremely low:
A short test / basic attack on a website: $5–25.
Daily attack on a poorly protected target: around $100/day.
A more robust or well-protected target: $200–500 per day.
Monthly subscription to booter/stresser services: often $15–40 (sometimes even less); premium packages cost hundreds of dollars.
Larger or longer-term campaigns or infrastructure: thousands of dollars.
On the governmental level these money are almost nothing if you want to hurt someone else…
Re: DDoS against Norwegian government IT infrastructure – status
#76The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?
Really, you have no one in mind? Someone who is sending hundreds of bombing drones daily to Ukraine, killing civilian population, women and children, and who is eager to send a message to NATO countries any way possible?
Re: DDoS against Norwegian government IT infrastructure – status
#77The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?
do we really need to ask?
clearly it's the Danes
Re: DDoS against Norwegian government IT infrastructure – status
#78The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?
is there actually any source those attacks are really done by "script kiddies"? More likely this more politically motivated and backed up by money and more capable groups
AI kiddies, more likely. in some ways script kiddies weren't a thing for a decade or more as the attack surface got considerably harder to penetrate, and the model changed for pay-to-play attacks. AI simply caused the bottom of that market to fall further, and effectiveness to increase.
Re: DDoS against Norwegian government IT infrastructure – status
#79The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?
Imo russia most likely