Live data from Hacker News

DDoS against Norwegian government IT infrastructure – status

status.digdir.no

71–80 of 81 posts

Re: DDoS against Norwegian government IT infrastructure – status

#71
post #64
post #52

There's some interesting commentry at https://www.techtimes.com/articles/322754/20260803/norway-id... , which suggests that the widespread outage is due to a single point of failure: > ID-Porten: When One Gateway Controls Everything > At the center of the disruption is ID-porten — the national login gateway operated by Norway's Digitaliseringsdirektoratet (Digdir), the government agency responsible for public-sector…

Yes, it's a single point of failure by design - but has been pretty stable mostly - with this and a previous attack in June being exceptions. The identity portal is administered by the department for digital services, but hosted at a commercial provider, Vivicta (formerly TietoEvery, formerly Tieto and Every - Consulting companies from Finland and Norway). https://www.agilitaspe.com/index.php?id=136

Evry, not Every.

Re: DDoS against Norwegian government IT infrastructure – status

#72

I'd guess someone in the us fat-fingered ip ranges and mixed up 2.144.0.0/14 (Iran) with 2.148.0.0/14 (Norway)

Or someone entered 2.144.0.0/14 but on a machine without ECC and a bit-flip happened, turning it into 2.148.0.0/14.

Or they tasked a frontier AI with it.

Re: DDoS against Norwegian government IT infrastructure – status

#73
post #64

Earlier quoted context omitted.

Yes, it's a single point of failure by design - but has been pretty stable mostly - with this and a previous attack in June being exceptions. The identity portal is administered by the department for digital services, but hosted at a commercial provider, Vivicta (formerly TietoEvery, formerly Tieto and Every - Consulting companies from Finland and Norway). https://www.agilitaspe.com/index.php?id=136

Evry, not Every.

Autocorrect hates these neologistic company names...

Re: DDoS against Norwegian government IT infrastructure – status

#74
post #60
post #42

Earlier quoted context omitted.

It hasn't been majorly like that in twenty years. Botnets are services now, a business. They gain customers by their effectiveness and resilience. For $$50-100 you can deny service to a lot of big sites and services.

I've seen people say this but no proof of it. Could I really take down Stack Overflow for $50? Oh wait, it took itself down for free.

Trivial to google and find, for example https://overload.st/

Re: DDoS against Norwegian government IT infrastructure – status

#75

The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?

It is not expensive, unfortunately :(

Flare + BleepingComputer 2026, Kaspersky, StormWall, and others show that the DDoS-as-a-service market is highly commoditized and prices are extremely low:

A short test / basic attack on a website: $5–25.

Daily attack on a poorly protected target: around $100/day.

A more robust or well-protected target: $200–500 per day.

Monthly subscription to booter/stresser services: often $15–40 (sometimes even less); premium packages cost hundreds of dollars.

Larger or longer-term campaigns or infrastructure: thousands of dollars.

On the governmental level these money are almost nothing if you want to hurt someone else…

Re: DDoS against Norwegian government IT infrastructure – status

#76

The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?

Really, you have no one in mind? Someone who is sending hundreds of bombing drones daily to Ukraine, killing civilian population, women and children, and who is eager to send a message to NATO countries any way possible?

Is Israel supplying drones to Ukraine? Good on them.

Re: DDoS against Norwegian government IT infrastructure – status

#77

The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?

> So which actor would actually benefit from downing the Norwegian government?

do we really need to ask?

clearly it's the Danes

Re: DDoS against Norwegian government IT infrastructure – status

#78

The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?

is there actually any source those attacks are really done by "script kiddies"? More likely this more politically motivated and backed up by money and more capable groups

i don't think script kiddies are a thing anymore.

AI kiddies, more likely. in some ways script kiddies weren't a thing for a decade or more as the attack surface got considerably harder to penetrate, and the model changed for pay-to-play attacks. AI simply caused the bottom of that market to fall further, and effectiveness to increase.

Re: DDoS against Norwegian government IT infrastructure – status

#79

The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?

Imo russia most likely

almost certainly. they're hitting all NATO governments, and Norway is a direct competitor in the arctic.

Re: DDoS against Norwegian government IT infrastructure – status

#80
post #72

Earlier quoted context omitted.

Or someone entered 2.144.0.0/14 but on a machine without ECC and a bit-flip happened, turning it into 2.148.0.0/14.

Or they tasked a frontier AI with it.

and it hallucinated
Post reply on HN