just_some_user 1 day ago

The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?

  • iwontberude 1 day ago

    those script kiddies control botnets in foreign countries and use them to attack stuff just bc. its not their compute, so no marginal cost to them

  • InTheArena 1 day ago

    What do they benefit from taking down any government, NGO or civic work program? American systems, as well as larger European systems are constantly attacked. I've seen the same traffic. Fire walling off China, North Korea and smaller eastern European countries is a must if you ever plan to expose any internet exposed services.

  • cynicalsecurity 1 day ago

    Really, you have no one in mind? Someone who is sending hundreds of bombing drones daily to Ukraine, killing civilian population, women and children, and who is eager to send a message to NATO countries any way possible?

    • motbus3 1 day ago

      That is much less effective than every other manner they tested on the past few years such as shadow fleets, ghost satellites etc.

      Up to the moment it has not been the operation adopted which would make it weird.

      On who would do it then, anyone who benefits from instability. From corporations trying to sell flocked uped sytems, politicians, etc.

      There is one south american country who was attacked exactly this way before their head of the government was kidnapped.

      • cynicalsecurity 1 day ago

        You don't understand Kremlin's mentality. Any even little nasty thing they can do to the West makes them giggle like Doctor Evil. "Oh, a NATO country's government infra was not protected from DDoS? Let's have fun, haha!" You are dealing with story book villains. I know, this sounds so ridiculous it's hard to believe someone can actually be like this. But then the reality check hits.

        • throwaway742 1 day ago

          They aren't story book villains. I think this says a lot about your mentality.

          • throwuxiytayq 22 hours ago

            Story book villains usually have better justification for their evil acts than the Russian government.

    • inigyou 15 hours ago

      Is Israel supplying drones to Ukraine? Good on them.

  • roflmaostc 1 day ago

    is there actually any source those attacks are really done by "script kiddies"?

    More likely this more politically motivated and backed up by money and more capable groups

    • red-iron-pine 13 hours ago

      i don't think script kiddies are a thing anymore.

      AI kiddies, more likely. in some ways script kiddies weren't a thing for a decade or more as the attack surface got considerably harder to penetrate, and the model changed for pay-to-play attacks. AI simply caused the bottom of that market to fall further, and effectiveness to increase.

  • cantalopes 1 day ago

    Imo russia most likely

    • red-iron-pine 13 hours ago

      almost certainly. they're hitting all NATO governments, and Norway is a direct competitor in the arctic.

  • tuatoru 1 day ago

    The UK. It wants to steal Norway's vast stores of electricity.

  • Retr0id 1 day ago

    DDoS tends to be monetised as DDoS-as-a-service. Taking down "significant" services is good advertising. Either that, or they plan to extort the Norwegian government.

    • just_some_user 1 day ago

      But for such a "proof of power" a short attack which takes the service down once is enough, long attacks are not so common and actually require some work from the attacker

      • Retr0id 1 day ago

        If the attack doesn't last long, bystanders can't know whether it was trivially mitigated by the victim.

        A shorter attack won't make as many news headlines, either.

      • devin 1 day ago

        Unless part of the social proof is that mitigation is more difficult.

  • giwook 1 day ago

    Probably a country that lost to Norway in the World Cup.

  • esseph 1 day ago

    It hasn't been majorly like that in twenty years.

    Botnets are services now, a business. They gain customers by their effectiveness and resilience.

    For $$50-100 you can deny service to a lot of big sites and services.

    • inigyou 1 day ago

      I've seen people say this but no proof of it. Could I really take down Stack Overflow for $50? Oh wait, it took itself down for free.

  • sixtyj 17 hours ago

    It is not expensive, unfortunately :(

    Flare + BleepingComputer 2026, Kaspersky, StormWall, and others show that the DDoS-as-a-service market is highly commoditized and prices are extremely low:

    A short test / basic attack on a website: $5–25.

    Daily attack on a poorly protected target: around $100/day.

    A more robust or well-protected target: $200–500 per day.

    Monthly subscription to booter/stresser services: often $15–40 (sometimes even less); premium packages cost hundreds of dollars.

    Larger or longer-term campaigns or infrastructure: thousands of dollars.

    On the governmental level these money are almost nothing if you want to hurt someone else…

  • red-iron-pine 13 hours ago

    > So which actor would actually benefit from downing the Norwegian government?

    do we really need to ask?

    clearly it's the Danes

lschueller 1 day ago

I'd guess someone in the us fat-fingered ip ranges and mixed up 2.144.0.0/14 (Iran) with 2.148.0.0/14 (Norway)

  • TacticalCoder 1 day ago

    Or someone entered 2.144.0.0/14 but on a machine without ECC and a bit-flip happened, turning it into 2.148.0.0/14.

    • soco 20 hours ago

      Or they tasked a frontier AI with it.

speerer 1 day ago

There's some interesting commentry at https://www.techtimes.com/articles/322754/20260803/norway-id... , which suggests that the widespread outage is due to a single point of failure:

> ID-Porten: When One Gateway Controls Everything

> At the center of the disruption is ID-porten — the national login gateway operated by Norway's Digitaliseringsdirektoratet (Digdir), the government agency responsible for public-sector digitalization. ID-porten functions as the single sign-on portal through which Norwegian citizens authenticate themselves to access public digital services.

It seems to be a corporate service provider that's a dependency for many other services.

  • e12e 1 day ago

    Yes, it's a single point of failure by design - but has been pretty stable mostly - with this and a previous attack in June being exceptions.

    The identity portal is administered by the department for digital services, but hosted at a commercial provider, Vivicta (formerly TietoEvery, formerly Tieto and Every - Consulting companies from Finland and Norway).

    https://www.agilitaspe.com/index.php?id=136

    • wasting_time 21 hours ago

      Evry, not Every.

      • e12e 18 hours ago

        Autocorrect hates these neologistic company names...

p0w3n3d 1 day ago

There has been also DDoS against my friend's employer ISP. He had to work a lot to mitigate. There was a random request before

spapas82 1 day ago

Would the attack be successful is the Norwegian government used a way to protect itself against ddos like cloudflare or akamai?

  • inigyou 1 day ago

    I certainly hope the Norwegian government doesn't force all of its citizens to transmit all of their private data to the US government.

AtNightWeCode 1 day ago

Many important services with problems. Ouch. My guess is that the root cause is misconfiguration rather than an attack.

  • e12e 1 day ago

    From TFA:

    > Det har siden kl. 01 mandag 3. august pågått et tjenestenektangrep (DDoS) som rammer ID-porten som driftes hos Digdirs driftspartner Vivicta.

    > Since 0100 hours Monday August 31st there's been an ongoing DDoS attack which affects the ID-Portal which is run/hosted by DepDig's (Department of digital services') service provider Vivicta.

    (My translation)

    Ed: just realized Vivicta is TietoEvery with a haircut and new shoes:

    https://www.agilitaspe.com/index.php?id=136

crest 1 day ago

<hat type="tinfoil">I wonder who wants the Norwegian gov infrastructure between a TLS terminating proxy service</hat>

roschdal 1 day ago

The Internet was supposed to withstand a nuclear attack

  • pprotas 1 day ago

    Guess a nuclear attack would actually lessen the load on the global internet, rather than increase it - like a DDOS would!

  • buildbot 1 day ago

    "The internet" is currently fine, besides Norwegian government services.

    Also something designed to withstand something does not imply it survives other somethings.