CSIDB logo
Incident

Norway

Incident posture

Attack window
Jun 2022
Location
Norway
Status
Historical
CIA posture
Available to members
Updated
2025-10-18 00:00

Linked entities

Victim
Norway
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A pro-Russian criminal group conducted targeted distributed denial-of-service attacks against multiple large Norwegian entities, disrupting critical public-facing websites and online services. The attacks caused significant accessibility issues, though impacted organizations swiftly implemented mitigation measures to restore operations despite sporadic follow-on incidents. The Norwegian National Security Authority attributed the activity to broader geopolitical tensions, noting similar attacks had occurred internationally without lasting damage but warning such incidents could fuel public uncertainty. NSM had previously urged preparedness for service disruptions amid the heightened threat environment and continued assisting victims while anticipating future attacks.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 29, 2022, multiple large Norwegian organizations experienced distributed denial-of-service (DDoS) attacks targeting their websites and web-based services, causing significant disruptions that rendered critical online platforms inaccessible to users. The attacks were attributed to a pro-Russian criminal group, as confirmed by Norway’s National Security Authority (NSM). These incidents affected entities providing essential services to the public, though specific company names were not disclosed. NSM Director Sofie Nystrøm emphasized the deliberate nature of the attacks, noting they aligned with similar incidents observed in other countries amid heightened geopolitical tensions in Europe. The agency had proactively warned Norwegian entities in May 2022 to bolster defenses against such threats, citing the evolving security landscape. While the attacks disrupted operations temporarily, no permanent damage or data breaches were reported. NSM provided direct assistance to targeted organizations during the incident response phase.

Sporadic DDoS activity continued beyond June 29, though affected organizations rapidly implemented countermeasures to restore services and maintain normal operations. NSM reiterated the likelihood of future attacks and stressed the importance of organizational preparedness. Director Nystrøm highlighted that while comparable incidents abroad had not resulted in long-term consequences, the attacks risked amplifying public uncertainty and reinforcing perceptions of Norway’s involvement in broader European geopolitical conflicts. The agency maintained its advisory role, monitoring the situation without disclosing technical specifics of the attacks or mitigation strategies employed by victims. A press briefing featuring Nystrøm was held on June 29 at Oslo’s Havnelageret to address media inquiries, underscoring the operational transparency surrounding the incident.

Sources

Sources available to members: 1 source.

CSIDB