Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?
  • Really, you have no one in mind? Someone who is sending hundreds of bombing drones daily to Ukraine, killing civilian population, women and children, and who is eager to send a message to NATO countries any way possible?
  • Imo russia most likely
  • It hasn't been majorly like that in twenty years.

    Botnets are services now, a business. They gain customers by their effectiveness and resilience.

    For $$50-100 you can deny service to a lot of big sites and services.

  • What do they benefit from taking down any government, NGO or civic work program? American systems, as well as larger European systems are constantly attacked. I've seen the same traffic. Fire walling off China, North Korea and smaller eastern European countries is a must if you ever plan to expose any internet exposed services.
  • is there actually any source those attacks are really done by "script kiddies"?

    More likely this more politically motivated and backed up by money and more capable groups

  • Probably a country that lost to Norway in the World Cup.
  • DDoS tends to be monetised as DDoS-as-a-service. Taking down "significant" services is good advertising. Either that, or they plan to extort the Norwegian government.
  • It is not expensive, unfortunately :(

    Flare + BleepingComputer 2026, Kaspersky, StormWall, and others show that the DDoS-as-a-service market is highly commoditized and prices are extremely low:

    A short test / basic attack on a website: $5–25.

    Daily attack on a poorly protected target: around $100/day.

    A more robust or well-protected target: $200–500 per day.

    Monthly subscription to booter/stresser services: often $15–40 (sometimes even less); premium packages cost hundreds of dollars.

    Larger or longer-term campaigns or infrastructure: thousands of dollars.

    On the governmental level these money are almost nothing if you want to hurt someone else…

  • The Internet was supposed to withstand a nuclear attack
  • Guess a nuclear attack would actually lessen the load on the global internet, rather than increase it - like a DDOS would!
  • "The internet" is currently fine, besides Norwegian government services.

    Also something designed to withstand something does not imply it survives other somethings.

  • Bets on which AI lab it is this time?
  • <hat type="tinfoil">I wonder who wants the Norwegian gov infrastructure between a TLS terminating proxy service</hat>
  • Many important services with problems. Ouch. My guess is that the root cause is misconfiguration rather than an attack.
  • From TFA:

    > Det har siden kl. 01 mandag 3. august pågått et tjenestenektangrep (DDoS) som rammer ID-porten som driftes hos Digdirs driftspartner Vivicta.

    > Since 0100 hours Monday August 31st there's been an ongoing DDoS attack which affects the ID-Portal which is run/hosted by DepDig's (Department of digital services') service provider Vivicta.

    (My translation)

    Ed: just realized Vivicta is TietoEvery with a haircut and new shoes:

    https://www.agilitaspe.com/index.php?id=136

    by e12e
  • Would the attack be successful is the Norwegian government used a way to protect itself against ddos like cloudflare or akamai?
  • I certainly hope the Norwegian government doesn't force all of its citizens to transmit all of their private data to the US government.
  • The bus card ride purchase system was down today in my part of Finland. I wonder if it is related.
    by leke
  • Is it run/developed by Tieto (Vivicta)?

    Ed: I'm guessing yes?

    https://vayla.fi/-/new-public-transportation-travel-card-sys...

    by e12e
  • There has been also DDoS against my friend's employer ISP. He had to work a lot to mitigate. There was a random request before
  • There's some interesting commentry at https://www.techtimes.com/articles/322754/20260803/norway-id... , which suggests that the widespread outage is due to a single point of failure:

    > ID-Porten: When One Gateway Controls Everything

    > At the center of the disruption is ID-porten — the national login gateway operated by Norway's Digitaliseringsdirektoratet (Digdir), the government agency responsible for public-sector digitalization. ID-porten functions as the single sign-on portal through which Norwegian citizens authenticate themselves to access public digital services.

    It seems to be a corporate service provider that's a dependency for many other services.

  • Yes, it's a single point of failure by design - but has been pretty stable mostly - with this and a previous attack in June being exceptions.

    The identity portal is administered by the department for digital services, but hosted at a commercial provider, Vivicta (formerly TietoEvery, formerly Tieto and Every - Consulting companies from Finland and Norway).

    https://www.agilitaspe.com/index.php?id=136

    by e12e
  • I'd guess someone in the us fat-fingered ip ranges and mixed up 2.144.0.0/14 (Iran) with 2.148.0.0/14 (Norway)
  • Or someone entered 2.144.0.0/14 but on a machine without ECC and a bit-flip happened, turning it into 2.148.0.0/14.