over:heard
Unclaimed brand page — independent analysis by over:heard, based solely on public coverage.
Digdir logoDDigdirdigdir.no

Norway’s Digdir says systems still troubled after data attack

AssessmentTHREATSeverityHIGHEscalation riskMODERATEUrgencyDAYS
Analysis as of 2026-08-26 — a dated snapshot of the coverage verified that day.
Evidence-backed — 21 verified facts from 4 sourcesAHNSView evidence ›

Executive summary

Digdir, Norway's state agency for digital infrastructure, is experiencing its third DDoS attack in recent months, disrupting ten critical public services including ID-porten and Altinn.5810 The ongoing attack has lasted over 30 hours, with systems experiencing partial availability and intermittent stability despite recovery efforts.13411 While no data breach has occurred, the repeated attacks on critical infrastructure threaten public trust in government digital services.71012 We recommend a diminish strategy focusing on technical containment, transparent updates, and demonstrating coordinated response with partners.11121

Mentions (3)

Show 1 moreShow less
Context — surfaced by research (1)Hide context
State agency under cyber attack
www.newsinenglish.no iconNorway's News in English context · 2026-08-25

Risks / opportunities

THREATRepeated DDoS attacks erode public trust in Norway's critical digital infrastructure, potentially leading to reduced adoption of essential government services.710
THREATExtended service disruptions affect millions of citizens and thousands of public services, creating operational and reputational damage.56
OPPORTUNITYDemonstrating effective incident response and transparency during repeated attacks can strengthen Digdir's credibility as a resilient infrastructure operator.11121

Best response strategy

DIMINISH The DDoS attacks represent an external threat that Digdir could not reasonably prevent, though repeated incidents suggest a need for enhanced resilience measures.1012 Stakeholders primarily seek reassurance about service availability and data security rather than assigning blame for the attacks.5612 Transparent communication about technical response and recovery efforts aligns with public expectations for critical infrastructure operators.11121

Who is watching, and what each expects from the response:

customersAccess to essential public services like ID-porten, MinID, Altinn and E-innsyn remains disrupted, affecting daily life and business operations.56
regulatorAs critical infrastructure operator, Digdir must demonstrate adequate security measures and incident response to protect public services and data.720
publicTrust in government digital services is undermined by repeated cyber attacks disrupting access to essential services.5710
partnersSubcontractors like Vivicta need coordinated response and clear communication about system stability and recovery timelines.21
mediaSeeking updates on the ongoing incident, its impact on citizens, and Digdir's response to repeated attacks.2310

Suggested response plan

T+0-24h
Phase 1 — Contain & verify
Outcome: All internal communications are coordinated, facts verified, and stakeholders notified with consistent messaging.1112021
comms
Convene the crisis team to establish a single source of truth about system status, coordinate with Vivicta on technical response, and prepare a holding statement for public distribution.
  1. Verify current system status and recovery timeline with operations team.
  2. Coordinate with Vivicta subcontractor on joint technical response.
  3. Prepare holding statement acknowledging ongoing issues and recovery efforts.
  4. Notify National Security Authority and Data Protection Authority of latest developments.
Done when: No uncoordinated communications are occurring and all stakeholders have received consistent status updates.
T+1-2 days
Phase 2 — Respond
Outcome: Public receives transparent updates on recovery progress, and stakeholders understand the coordinated response effort.1111221
comms
Publish a comprehensive update on the website detailing current system status, recovery progress, and measures taken to prevent future incidents, while directly notifying affected government agencies.5611
  1. Publish detailed status update on Digdir website with technical specifics.
  2. Issue press release to Norwegian media outlining response efforts.
  3. Directly notify all government agencies using affected services.
  4. Activate customer support channels with updated guidance for users.
Done when: Public statement is live on all channels and key stakeholders have acknowledged receipt.
“Digdir continues to manage the effects of a DDoS attack that began on Monday.917 Our teams, working closely with partner Vivicta, have restored partial functionality to critical services including ID-porten and Altinn.11521 While systems remain under strain, we have maintained service availability for most users throughout this incident.111 There is no indication of any security breach or compromise of personal data.12 We are implementing additional protective measures and will provide regular updates on our recovery progress.11
website statementpress releasedirect outreach
T+2-5 days
Phase 3 — Manage
Outcome: Service stability is restored, public confidence begins to recover, and lessons learned are documented.1114
operations
Monitor public sentiment and media coverage, provide regular technical updates, and begin documenting incident response lessons for future improvement.
  1. Deploy enhanced monitoring to track system stability and user experience.
  2. Provide daily technical updates to media and stakeholders.
  3. Document incident response timeline and effectiveness measures.
  4. Begin planning post-incident review with security partners.
Done when: System stability is consistently maintained and media coverage shifts from crisis reporting to recovery narrative.
T+1-2 weeks
Phase 4 — Recover
Outcome: Public trust is rebuilt through demonstrated resilience improvements and transparent communication about enhanced security measures.710
executive
Publish a comprehensive post-incident report detailing the attack, response effectiveness, and implemented security enhancements, while engaging with stakeholders on long-term resilience planning.
  1. Publish detailed post-incident analysis on Digdir website.
  2. Conduct stakeholder briefings on enhanced security measures.
  3. Develop and communicate long-term resilience strategy.
  4. Establish regular security update communications with users.
Done when: Public confidence metrics return to pre-incident levels and stakeholders endorse the improved security framework.

Evidence sources (4)

Everything this briefing cites — ANCHOR started the story, CONTEXT backs it without naming the brand.

Are you digdir.no?

Your crisis desk is ready — claim it to respond. Claiming is free — your response strategy & plan become collaborative, and you get the option to display your response & status updates on this page.

Claim your brand

Follow this story

One short, factual update when this story develops — nothing else, from over:heard.

Email updates

By subscribing you consent to receive email updates about this story. Double opt-in: nothing is sent until you confirm from your inbox. Unsubscribe anytime — one click in every email.

Push notifications

No email needed — alerts appear on this device.

Not digdir.no? See what over:heard would flag for your brand. Start free →
Independent media-monitoring briefing compiled by over:heard radar from public coverage. Assessments are decision support — not statements by, or affiliation with, the brands mentioned. · Built from public sources, cited. Every brand has a free, permanent right of reply — editorial policy · Powered by over:heard by wise:able