Norwegian Digitalization Agency
Incident posture
Linked entities
- Victim
- Norwegian Digitalization Agency
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A pro-Russian hacker group claimed responsibility for a denial-of-service attack that targeted the Norwegian Digitalization Agency, disrupting multiple government digital services over several days. The agency said the assault was the largest it had ever faced but managed to keep the services running practically all the time. The attackers stated they launched the cyber war after Norway renewed its security cooperation with Ukraine.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The cyberattack against the Norwegian Digitalization Agency began on Monday and continued through Wednesday, 2026-08-27. It was characterized as a denial-of-service operation in which attackers directed massive volumes of traffic at the agency’s infrastructure. The traffic overload targeted multiple government digital services, including the platform that allows citizens to use a single login across various public services. According to Are Kvistad, a spokesperson for the Norwegian Digitalization Agency, the attack represented the biggest such incident ever experienced by Digdir. On Wednesday, the pro‑Russian hacker group Server Killers posted on Telegram claiming responsibility for the operation. In that post the group stated that it had declared cyber war on Norway following the country’s renewal of security cooperation with Ukraine on August 23, 2026.
Despite the volume of traffic, the agency reported that it managed to keep the affected services running “practically all the time.” No specific service outages were disclosed by the spokesperson, and the agency did not detail any technical countermeasures employed. Norwegian officials refrained from commenting on the hackers’ claim at the time of publication. The article notes that European countries remain on high alert due to increased Russian sabotage and malign activity since the 2022 invasion of Ukraine. It also references a 2025 incident in which Norwegian authorities said Russian hackers were likely behind suspected sabotage at a dam, during which hackers gained access to a digital system controlling a valve and opened it to increase water flow. Additionally, it notes that Danish authorities blamed Russia for cyberattacks against infrastructure and websites in Denmark in 2024 and 2025, citing the groups Z‑Pentest and NoName057(16) as responsible for specific attacks.
Sources
Sources available to members: 1 source.