Digdir's shared solutions back in normal operation after DDoS attack
On Saturday, several of Digdir's shared solutions experienced complete or partial unavailability as a result of a denial of service attack (DDoS attack). The attack targeted ID-porten, through our supplier Vivicta's network infrastructure. All services were restored and in normal operation as of Monday at 07:30.
DDoS attacks overload digital services with artificial network traffic to make them unavailable.
The denial of service attack resulted in services being partially or completely unavailable for a period of time, but has not resulted in a security breach. No personal data is compromised, but the Norwegian Data Protection Authority has been routinely notified as a result of limited access to services that process personal data. The National Security Authority has also been notified in line with our routines related to such incidents.
— The Directorate of Digitalisation's services are part of a socially critical infrastructure. We therefore take operational disruptions very seriously, and have good practice for this type of handling. Our response this weekend shows that the contingency plan is working well: The denial of service attack was identified, in close cooperation with Vivicta we were able to limit the consequences, and together we restored the services to normal operation. We are now conducting a thorough evaluation of the incident, in line with our routines, says Department Director Nina Munthe Olsen.
Facts about the incident:
- Duration: Saturday at 1:16 PM to Monday morning at 7:30 AM.
- Affected services: ID-porten, MinID, Maskinporten, Contact and reservation register, eFormidling, ELMA, eInnsyn, Ansatporten, Self-service solutions.