Norway’s digital government faced the largest recorded attack of its kind this week, but the campaign failed to knock most public services offline.
The Norwegian Digitalization Agency, or Digdir, said a distributed denial-of-service campaign began Monday against systems used by citizens and businesses. Digdir spokesperson Are Kvistad told The Associated Press it was the biggest attack the agency had experienced.
A pro-Russian group called Server Killers later claimed responsibility and linked the campaign to Norway’s support for Ukraine, but Norwegian authorities have not publicly confirmed who was behind the attack.
Despite the scale of the attack, Digdir said it kept its services available for most of the incident. Kvistad said they were operating “practically all the time,” AP reported.
The assault used distributed denial-of-service (DDoS) tactics, flooding systems with traffic to make online services difficult to access. One targeted service allows people to use a single login across multiple government services.
Digdir also said socially critical systems were not affected and that most residents and businesses had not experienced major disruption, according to Norwegian broadcaster TV 2.
Hackers link attack to Ukraine support
Server Killers, a group that describes itself as pro-Russian, claimed responsibility in a Telegram post Wednesday and said it had declared cyberwar on Norway.
The group said the action was linked to the attack on an Aug. 23 defense and security cooperation agreement between Norway and Ukraine, according to TV 2.
The timing also follows Norwegian Prime Minister Jonas Gahr Støre’s announcement during a visit to Kyiv that Norway plans to provide 85 billion Norwegian kroner ($9.2 billion) to Ukraine through next year’s state budget. Norway and Ukraine also agreed to expand cooperation on drone technology and other modern warfare capabilities.
Norwegian officials had not publicly confirmed that Server Killers was responsible for the attack. The Police Security Service, the National Security Authority and Kripos are involved in monitoring or investigating the incident, with Kripos declining to discuss who may be behind it, TV 2 reported.
Part of a wider cyber threat
Server Killers has been active since 2023 and has claimed other DDoS attacks in Europe and Canada. Its Telegram channel also references the better-known NoName057(16) group.
Cybersecurity company ZeroFox has previously linked Server Killers and NoName057(16) to coordinated DDoS attacks against Spanish government websites, according to TV 2. Norway has also faced suspected Russian cyber activity before.
Authorities said Russian hackers were likely behind a 2025 incident involving a dam, where attackers accessed a system controlling a valve and increased water flow.
What this means for government services
The attack shows that even when hackers fail to take public systems offline, prolonged DDoS campaigns can still test the resilience of highly digitized governments.
Digdir’s ability to keep services running limits the immediate consumer impact, but the incident also demonstrates how politically motivated groups can target widely used public platforms without necessarily breaching sensitive systems.
The key hurdle for Norway is to maintain public confidence and service availability while security agencies determine whether the attack is an isolated activist operation or part of a broader campaign connected to the conflict in Ukraine.
For government agencies elsewhere, the practical lesson is resilience: critical digital services need enough redundancy and DDoS protection to remain usable even when politically motivated attackers make availability itself the target.
More News: The FBI and Justice Department disrupted QScan and QTRouter, two platforms allegedly used by Chinese state-sponsored hackers to target U.S. government agencies and critical infrastructure while hiding their activity behind compromised IoT devices.





