DDoS against Norwegian government IT infrastructure – status

(status.digdir.no)

85 points | by e12e 8 hours ago ago

38 comments

  • just_some_user 8 hours ago ago

    The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?

    • Retr0id 7 hours ago ago

      DDoS tends to be monetised as DDoS-as-a-service. Taking down "significant" services is good advertising. Either that, or they plan to extort the Norwegian government.

      • just_some_user 7 hours ago ago

        But for such a "proof of power" a short attack which takes the service down once is enough, long attacks are not so common and actually require some work from the attacker

        • Retr0id 7 hours ago ago

          If the attack doesn't last long, bystanders can't know whether it was trivially mitigated by the victim.

          A shorter attack won't make as many news headlines, either.

        • devin 7 hours ago ago

          Unless part of the social proof is that mitigation is more difficult.

    • roflmaostc 8 hours ago ago

      is there actually any source those attacks are really done by "script kiddies"?

      More likely this more politically motivated and backed up by money and more capable groups

    • giwook 7 hours ago ago

      Probably a country that lost to Norway in the World Cup.

    • InTheArena 8 hours ago ago

      What do they benefit from taking down any government, NGO or civic work program? American systems, as well as larger European systems are constantly attacked. I've seen the same traffic. Fire walling off China, North Korea and smaller eastern European countries is a must if you ever plan to expose any internet exposed services.

    • cantalopes 7 hours ago ago

      Imo russia most likely

    • esseph 7 hours ago ago

      It hasn't been majorly like that in twenty years.

      Botnets are services now, a business. They gain customers by their effectiveness and resilience.

      For $$50-100 you can deny service to a lot of big sites and services.

      • inigyou 5 hours ago ago

        I've seen people say this but no proof of it. Could I really take down Stack Overflow for $50? Oh wait, it took itself down for free.

    • iwontberude 8 hours ago ago

      those script kiddies control botnets in foreign countries and use them to attack stuff just bc. its not their compute, so no marginal cost to them

    • tuatoru 7 hours ago ago

      The UK. It wants to steal Norway's vast stores of electricity.

    • cynicalsecurity 8 hours ago ago

      Really, you have no one in mind? Someone who is sending hundreds of bombing drones daily to Ukraine, killing civilian population, women and children, and who is eager to send a message to NATO countries any way possible?

      • motbus3 7 hours ago ago

        That is much less effective than every other manner they tested on the past few years such as shadow fleets, ghost satellites etc.

        Up to the moment it has not been the operation adopted which would make it weird.

        On who would do it then, anyone who benefits from instability. From corporations trying to sell flocked uped sytems, politicians, etc.

        There is one south american country who was attacked exactly this way before their head of the government was kidnapped.

        • cynicalsecurity 7 hours ago ago

          You don't understand Kremlin's mentality. Any even little nasty thing they can do to the West makes them giggle like Doctor Evil. "Oh, a NATO country's government infra was not protected from DDoS? Let's have fun, haha!" You are dealing with story book villains. I know, this sounds so ridiculous it's hard to believe someone can actually be like this. But then the reality check hits.

          • throwaway742 5 hours ago ago

            They aren't story book villains. I think this says a lot about your mentality.

      • inigyou 5 hours ago ago

        I didn't know Israel was supplying drones to Ukraine

  • lschueller 6 hours ago ago

    I'd guess someone in the us fat-fingered ip ranges and mixed up 2.144.0.0/14 (Iran) with 2.148.0.0/14 (Norway)

    • TacticalCoder 5 hours ago ago

      Or someone entered 2.144.0.0/14 but on a machine without ECC and a bit-flip happened, turning it into 2.148.0.0/14.

  • speerer 6 hours ago ago

    There's some interesting commentry at https://www.techtimes.com/articles/322754/20260803/norway-id... , which suggests that the widespread outage is due to a single point of failure:

    > ID-Porten: When One Gateway Controls Everything

    > At the center of the disruption is ID-porten — the national login gateway operated by Norway's Digitaliseringsdirektoratet (Digdir), the government agency responsible for public-sector digitalization. ID-porten functions as the single sign-on portal through which Norwegian citizens authenticate themselves to access public digital services.

    It seems to be a corporate service provider that's a dependency for many other services.

    • e12e 4 hours ago ago

      Yes, it's a single point of failure by design - but has been pretty stable mostly - with this and a previous attack in June being exceptions.

      The identity portal is administered by the department for digital services, but hosted at a commercial provider, Vivicta (formerly TietoEvery, formerly Tieto and Every - Consulting companies from Finland and Norway).

      https://www.agilitaspe.com/index.php?id=136

  • p0w3n3d 8 hours ago ago

    There has been also DDoS against my friend's employer ISP. He had to work a lot to mitigate. There was a random request before

  • leke 7 hours ago ago

    The bus card ride purchase system was down today in my part of Finland. I wonder if it is related.

  • spapas82 7 hours ago ago

    Would the attack be successful is the Norwegian government used a way to protect itself against ddos like cloudflare or akamai?

    • inigyou 5 hours ago ago

      I certainly hope the Norwegian government doesn't force all of its citizens to transmit all of their private data to the US government.

  • kachnuv_ocasek 7 hours ago ago

    Bets on which AI lab it is this time?

  • AtNightWeCode 7 hours ago ago

    Many important services with problems. Ouch. My guess is that the root cause is misconfiguration rather than an attack.

    • e12e 4 hours ago ago

      From TFA:

      > Det har siden kl. 01 mandag 3. august pågått et tjenestenektangrep (DDoS) som rammer ID-porten som driftes hos Digdirs driftspartner Vivicta.

      > Since 0100 hours Monday August 31st there's been an ongoing DDoS attack which affects the ID-Portal which is run/hosted by DepDig's (Department of digital services') service provider Vivicta.

      (My translation)

      Ed: just realized Vivicta is TietoEvery with a haircut and new shoes:

      https://www.agilitaspe.com/index.php?id=136

  • crest 6 hours ago ago

    <hat type="tinfoil">I wonder who wants the Norwegian gov infrastructure between a TLS terminating proxy service</hat>

  • roschdal 7 hours ago ago

    The Internet was supposed to withstand a nuclear attack

    • buildbot 7 hours ago ago

      "The internet" is currently fine, besides Norwegian government services.

      Also something designed to withstand something does not imply it survives other somethings.

    • pprotas 7 hours ago ago

      Guess a nuclear attack would actually lessen the load on the global internet, rather than increase it - like a DDOS would!