The attack on the Norwegian Digitalisation Agency’s common solutions began at 3.38 a.m. on Monday and was still not over on Tuesday morning.
Ten public services have been affected, including ID-porten, MinID, Altinn and E-innsyn.
– This attack is two to three times larger than the previous one we experienced, but we have largely managed to keep the solutions operational, says press officer Are Kvistad at Digdir to NTB at 8.15 a.m. on Tuesday.
The attack is a so-called denial-of-service attack, or DDoS attack, in which large volumes of traffic are directed at a service in order to overload it. After the problems began during the night leading into Monday, the situation improved over the course of the morning, before deteriorating again in the evening. Shortly before midnight, Digdir stated that operations would continue through the night with restrictions.
Situation still unresolved on Tuesday morning
By 8 a.m. on Tuesday, the attack had been under way for around 30 hours.
– The status this morning is that we have been informed that the attack is continuing at full strength. It has been going on for 30 hours now. We simply have to keep monitoring the situation and wait and see, says Kvistad.
According to him, the common solutions have nevertheless seen stable use throughout the night despite the attack, and traffic is picking up as normal over the course of the morning on an ordinary weekday.
At 8.45 a.m., the agency stated that the attack was still ongoing, but that the services had so far appeared stable with the measures that had been implemented.
Further disruptions expected
Kvistad points out that this type of attack tends to come in waves, and that it can take time for everything to return to normal even after an attack subsides.
– When problems arise in one place, they spread elsewhere. Several of the services may therefore experience restrictions and operational disruptions, meaning that users and organisations may, in the worst case, experience some waiting time, he says.
Digdir asks users of the affected services to be prepared for intermittent login problems for as long as the attack continues.





