Application - Operational
Application
API - Operational
API
Monitoring - Operational
Monitoring
Sandbox - Operational
Sandbox
Data Freshness - Operational
Data Freshness
Notice history
Sep 2026
No notices reported this month
Aug 2026
- UpdateUTCUpdateUTC
Report after denial of service attack
This is an open report ("post mortem") following the denial of service attack against ID-porten on August 3.
The attack
From 00:50 on Monday, August 3rd to 13:03 on Tuesday, August 4th, several of Digdir's shared solutions were partially or completely unavailable due to a distributed denial of service (DDoS) attack. DDoS attacks overload digital services with artificial network traffic to make them unavailable.
The attack was targeted at the ID portal.
ID-porten has been subjected to two attacks in a short period of time. The attack on August 3rd is the most powerful denial of service attack we have experienced against ID-porten.
The attack started at 00:50 on 3 August, and from that time on, continuous work was carried out to resolve the problem. The attack came in several waves, and traffic showed improvement from 13:40 on the same day, but some solutions experienced new problems throughout the afternoon and evening. From 01:26 on the night of 4 August, the solutions were partially available. From 13:03 on the same day, the solutions were back in normal operation.
ID-porten and several other of Digdir's common solutions are operated on a common operating platform at our operating provider Vivicta. The attack therefore also affected eFormidling, ELMA, the Contact and Reservation Register, eInnsyn, Maskinporten and Ansattporten. Altinn, eSignering and Digital mailbox for residents were also affected as a result of login via ID-porten being temporarily unavailable.
Handling along the way
Continuous measures were taken along the way to reduce the scope of the attack and stabilize the solutions, in collaboration with Vivicta. Once the attack was over, traffic was quickly stabilized and normal operations were restored. The Norwegian Data Protection Authority and the National Security Authority (NSM) were notified in accordance with current procedures. The incident has not led to a security breach or personal data being lost.
The entire incident is now being thoroughly reviewed, in line with our procedures and practices. We are constantly working closely with our operating partners to improve incident handling.
Information along the way
The denial of service attack caused problems for businesses and citizens, because at times it was not possible for users to log in to public services.
Many of our customers and system suppliers have their own obligations to their customers when the common solutions are unavailable, and it is important that we sufficiently enable them to make their own risk and consequence assessments through the best and most accurate information possible.
In retrospect, we see that it took too long to describe the incident as a denial of service attack. At the same time, the need to provide information about the cause must be weighed against general recommendations not to disclose details about ongoing attacks, both to avoid helping the attacker and to avoid giving the person the effect or attention they are seeking. We are now reviewing routines for status messages for when and how the cause and status are communicated, so that users and customers can get an accurate picture of the situation more quickly –
especially in the case of long-term events.Further work
The Norwegian Directorate of Digital Services is part of a critical infrastructure. It is crucial that the solutions work for citizens and businesses, and we therefore take operational disruptions very seriously.
Dedicated security environments in Digdir are continuously working to ensure high availability and robustness in digital services that are important to society. Together with our operating partners, we have comprehensive security mechanisms in place. At the same time, attack methods are continuously evolving, so that handling this type of attack requires
ongoing adjustments. We are working to protect ourselves as much as possible against similar attacks in the future. - ResolvedUTCResolvedUTC
We are ending the outage. Customers who are still experiencing problems can contact the service desk.
You can read more about the incident here:https://www.digdir.no/felleslosninger/digdirs-felleslosninger-tilbake-i-normal-drift/8315
- UpdateUTCUpdateUTC
We are back to normal operations.
Please contact the service desk if you are still experiencing problems.
- UpdateUTCUpdateUTC
We are changing back to yellow status for several solutions. We have received messages from several people who are unable to connect to services from data centers in various countries.
As of now, we know that the following countries may experience problems connecting:
- Germany
- Switzerland
- Netherlands
- Belgium
We are working with our operating partner to resolve this.
- UpdateUTCUpdateUTC
Status 04.08.2026 at 09:00
All solutions are back in normal operation from approximately 01:30 tonight.
We will keep this case open for a while longer, and will provide more details as time goes on.
- MonitoringUTCMonitoringUTC
Status 04.08.2026 at 07:45
As of approximately 01:26 tonight, the shared solutions have been stable. We will return with more information approximately 08:30
- UpdateUTCUpdateUTC
Status 04.08.2026 at 00:08
There is still a large number of errors in the ID-porten. We are still working on resolving this.
Most other solutions work, but instability and varying response times may still be experienced.
The next update will be at approximately 7:30 AM.
- UpdateUTCUpdateUTC
Status 03.08.2026 at 22:46
Large increase in the number of errors in the ID-porten. Mitigation measures are being worked on.
Most other solutions work, but instability and varying response times may still be experienced.
- UpdateUTCUpdateUTC
Status 03.08.2026 at 21:00
Most solutions work, but instability and varying response times may still be experienced.
- IdentifiedUTCIdentifiedUTC
We are experiencing problems again from approximately 17:55
- UpdateUTCUpdateUTC
Since 01:00 on Monday, August 3, a denial of service (DDoS) attack has been ongoing against the ID-porten operated by Digdir's operating partner Vivicta. This affects several of Digdir's solutions and causes users to experience problems logging in to public services. We are working with Vivicta on measures to resolve the issue.
As of 1:40 PM, traffic was picking up again, but it may take some time before all services are available and back to normal operation.
- MonitoringUTCMonitoringUTC
From approximately 1:40 PM, it appears that traffic is on the rise again on the affected routes.
- UpdateUTCUpdateUTC
We are still working to resolve the issue.
The next update will be at 2:30 PM unless we have anything new before then.
- UpdateUTCUpdateUTC
We are still working to resolve the issue.
The next update will be at 1:30 PM unless we have anything new before then.
- UpdateUTCUpdateUTC
We are still working to resolve the issue.
The next update will be at 12:30 if we don't have anything new before then.
- UpdateUTCUpdateUTC
We are still working to resolve the issue.
The next update will be at 11:30 if we don't have anything new before then.
- UpdateUTCUpdateUTC
We are still working to resolve the issue.
The next status update will be at 10:30.
- UpdateUTCUpdateUTC
Troubleshooting is still ongoing.
- UpdateUTCUpdateUTC
The problem appears to have started around 00:50. The operating partner is working to resolve the issue, we will update when we have something new to report.
- InvestigatingUTCInvestigatingUTC
There are problems with several solutions. We are investigating the problems.
Jul 2026
No notices reported this month