DDoS against Norwegian government IT infrastructure – status

85 pointsposted 8 hours ago
by e12e

38 Comments

just_some_user

8 hours ago

The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?

Retr0id

7 hours ago

DDoS tends to be monetised as DDoS-as-a-service. Taking down "significant" services is good advertising. Either that, or they plan to extort the Norwegian government.

just_some_user

7 hours ago

But for such a "proof of power" a short attack which takes the service down once is enough, long attacks are not so common and actually require some work from the attacker

Retr0id

7 hours ago

If the attack doesn't last long, bystanders can't know whether it was trivially mitigated by the victim.

A shorter attack won't make as many news headlines, either.

devin

7 hours ago

Unless part of the social proof is that mitigation is more difficult.

roflmaostc

8 hours ago

is there actually any source those attacks are really done by "script kiddies"?

More likely this more politically motivated and backed up by money and more capable groups

giwook

7 hours ago

Probably a country that lost to Norway in the World Cup.

InTheArena

8 hours ago

What do they benefit from taking down any government, NGO or civic work program? American systems, as well as larger European systems are constantly attacked. I've seen the same traffic. Fire walling off China, North Korea and smaller eastern European countries is a must if you ever plan to expose any internet exposed services.

esseph

7 hours ago

It hasn't been majorly like that in twenty years.

Botnets are services now, a business. They gain customers by their effectiveness and resilience.

For $$50-100 you can deny service to a lot of big sites and services.

inigyou

5 hours ago

I've seen people say this but no proof of it. Could I really take down Stack Overflow for $50? Oh wait, it took itself down for free.

iwontberude

8 hours ago

those script kiddies control botnets in foreign countries and use them to attack stuff just bc. its not their compute, so no marginal cost to them

tuatoru

7 hours ago

The UK. It wants to steal Norway's vast stores of electricity.

Crunchified

7 hours ago

"vast stores of electricity"?

QuantumNomad_

7 hours ago

Electricity production in Norway is predominantly hydroelectric.

When it rains dams fill up. The water is drained into shafts with turbines, and electricity is generated.

However, even though we are big on hydroelectricity percentage wise I’m not sure it’s all that vast an amount of electricity on a global scale. We are a pretty small country after all.

According to Wikipedia, the Norwegian electricity sector had 40.26 GW installed capacity as of 2021 and was producing 157.113 TWh in the same year. [1]

Great Britain had 74.8 GW installed capacity in 2023 and was producing 292.7 TWh in 2023. [2]

France was producing 537.7 TWh in 2020. [3]

Germany was producing 488.5 TWh in 2024. [4]

[1]: https://en.wikipedia.org/wiki/Electricity_sector_in_Norway

[2]: https://en.wikipedia.org/wiki/Electricity_in_Great_Britain

[3]: https://en.wikipedia.org/wiki/Electricity_sector_in_France

[4]: https://en.wikipedia.org/wiki/Electricity_sector_in_Germany

Crunchified

7 hours ago

It stored energy. It's not stored electricity.

cynicalsecurity

8 hours ago

Really, you have no one in mind? Someone who is sending hundreds of bombing drones daily to Ukraine, killing civilian population, women and children, and who is eager to send a message to NATO countries any way possible?

motbus3

7 hours ago

That is much less effective than every other manner they tested on the past few years such as shadow fleets, ghost satellites etc.

Up to the moment it has not been the operation adopted which would make it weird.

On who would do it then, anyone who benefits from instability. From corporations trying to sell flocked uped sytems, politicians, etc.

There is one south american country who was attacked exactly this way before their head of the government was kidnapped.

cynicalsecurity

7 hours ago

You don't understand Kremlin's mentality. Any even little nasty thing they can do to the West makes them giggle like Doctor Evil. "Oh, a NATO country's government infra was not protected from DDoS? Let's have fun, haha!" You are dealing with story book villains. I know, this sounds so ridiculous it's hard to believe someone can actually be like this. But then the reality check hits.

throwaway742

5 hours ago

They aren't story book villains. I think this says a lot about your mentality.

inigyou

5 hours ago

I didn't know Israel was supplying drones to Ukraine

lschueller

6 hours ago

I'd guess someone in the us fat-fingered ip ranges and mixed up 2.144.0.0/14 (Iran) with 2.148.0.0/14 (Norway)

TacticalCoder

5 hours ago

Or someone entered 2.144.0.0/14 but on a machine without ECC and a bit-flip happened, turning it into 2.148.0.0/14.

speerer

6 hours ago

There's some interesting commentry at https://www.techtimes.com/articles/322754/20260803/norway-id... , which suggests that the widespread outage is due to a single point of failure:

> ID-Porten: When One Gateway Controls Everything

> At the center of the disruption is ID-porten — the national login gateway operated by Norway's Digitaliseringsdirektoratet (Digdir), the government agency responsible for public-sector digitalization. ID-porten functions as the single sign-on portal through which Norwegian citizens authenticate themselves to access public digital services.

It seems to be a corporate service provider that's a dependency for many other services.

e12e

4 hours ago

Yes, it's a single point of failure by design - but has been pretty stable mostly - with this and a previous attack in June being exceptions.

The identity portal is administered by the department for digital services, but hosted at a commercial provider, Vivicta (formerly TietoEvery, formerly Tieto and Every - Consulting companies from Finland and Norway).

https://www.agilitaspe.com/index.php?id=136

p0w3n3d

8 hours ago

There has been also DDoS against my friend's employer ISP. He had to work a lot to mitigate. There was a random request before

spapas82

7 hours ago

Would the attack be successful is the Norwegian government used a way to protect itself against ddos like cloudflare or akamai?

inigyou

5 hours ago

I certainly hope the Norwegian government doesn't force all of its citizens to transmit all of their private data to the US government.

AtNightWeCode

7 hours ago

Many important services with problems. Ouch. My guess is that the root cause is misconfiguration rather than an attack.

e12e

4 hours ago

From TFA:

> Det har siden kl. 01 mandag 3. august pågått et tjenestenektangrep (DDoS) som rammer ID-porten som driftes hos Digdirs driftspartner Vivicta.

> Since 0100 hours Monday August 31st there's been an ongoing DDoS attack which affects the ID-Portal which is run/hosted by DepDig's (Department of digital services') service provider Vivicta.

(My translation)

Ed: just realized Vivicta is TietoEvery with a haircut and new shoes:

https://www.agilitaspe.com/index.php?id=136

crest

6 hours ago

<hat type="tinfoil">I wonder who wants the Norwegian gov infrastructure between a TLS terminating proxy service</hat>

roschdal

7 hours ago

The Internet was supposed to withstand a nuclear attack

buildbot

7 hours ago

"The internet" is currently fine, besides Norwegian government services.

Also something designed to withstand something does not imply it survives other somethings.

pprotas

7 hours ago

Guess a nuclear attack would actually lessen the load on the global internet, rather than increase it - like a DDOS would!