Norway has faced its largest cyberattack to date against systems operated by the country’s Digitalisation Agency, with a sustained distributed denial-of-service (DDoS) campaign disrupting multiple government digital services. The pro-Russian hacking group Server Killers has claimed responsibility, saying the operation was retaliation for Norway’s continued security and financial support for Ukraine.
The attacks began on Monday and continued for several days, according to the Norwegian Digitalisation Agency, known as Digdir. Attackers generated massive volumes of traffic against government infrastructure in an attempt to overwhelm services and make them inaccessible to citizens. Are Kvistad, a spokesperson for Digdir, described it as the biggest attack the agency’s systems have ever experienced.
Norway’s digital identity infrastructure was targetedAmong the affected infrastructure was a service that allows Norwegian citizens to use a single login across multiple public services. Disrupting this type of centralized digital infrastructure can have a wider effect than taking an individual government website offline because authentication systems often act as gateways to numerous public platforms.
Despite the scale of the attack, Digdir said its systems remained operational for practically the entire period. This suggests the attackers succeeded in generating substantial pressure and intermittent disruption but did not achieve a prolonged shutdown of Norway’s digital public services.
There is also no indication in the current reporting that attackers penetrated government networks or stole information. The activity described by Norwegian officials is a denial-of-service operation, which attempts to make systems unavailable rather than compromise the underlying data.
Server Killers declares “cyber war” on NorwayServer Killers claimed responsibility through Telegram and connected the campaign directly to Norway’s relationship with Ukraine. The group said it had declared a cyber war against the country following the renewal of Norwegian-Ukrainian security cooperation on August 23. Norwegian authorities had not publicly validated the group’s attribution at the time of publication.
The timing follows Norwegian Prime Minister Jonas Gahr Støre’s visit to Kyiv, where he announced that Norway plans to provide 85 billion Norwegian kroner—approximately $9.2 billion—to Ukraine from next year’s budget, continuing substantial Norwegian assistance for a third consecutive year. Norway and Ukraine also agreed to deepen cooperation around drone technology and other areas of modern warfare.
That political context makes the attack consistent with a broader pattern of pro-Russian hacktivist groups targeting European governments after announcements involving military assistance, sanctions or cooperation with Ukraine.
DDoS has become a tool of geopolitical pressureDDoS attacks are technically less sophisticated than espionage operations or destructive malware, but they offer hacktivist groups several advantages. They can be launched relatively cheaply, create highly visible disruption and generate headlines without requiring persistent access to sensitive government networks.
Their psychological and political effect can therefore exceed their technical impact. Taking government portals temporarily offline allows attackers to demonstrate that a country supporting Ukraine can be digitally targeted, even when no sensitive systems have actually been compromised.
For defenders, the objective is resilience rather than simply preventing every malicious connection. Traffic filtering, distributed infrastructure, content delivery networks and scalable mitigation systems can absorb attacks while allowing legitimate users to continue accessing services. Norway’s ability to keep the affected platforms mostly operational demonstrates why this resilience is important.
Norway has faced more serious cyber-physical incidentsThe DDoS campaign also arrives against a more concerning background of suspected Russian-linked activity in Scandinavia. In 2025, Norwegian authorities said Russian hackers were likely responsible for an incident involving a dam control system. Attackers gained access to a digital interface controlling one of the dam’s valves and increased water flow before footage of the intrusion appeared on Telegram.
Neighboring Denmark has experienced similar activity. Danish authorities previously attributed attacks against infrastructure and websites to pro-Russian actors, including a destructive attack against a water utility and attacks against Danish websites ahead of the country’s 2025 local elections.
These incidents illustrate the spectrum of cyber operations associated with geopolitical conflict. At one end are disruptive but comparatively limited DDoS campaigns. At the other are intrusions into operational technology where malicious actions can potentially affect physical infrastructure.
Cyberattacks increasingly accompany political eventsThe attack on Digdir demonstrates how quickly geopolitical developments can now produce corresponding activity in cyberspace. Norway announces deeper cooperation and billions of dollars in continued support for Ukraine, and within days a pro-Russian group publicly claims a campaign against Norwegian government infrastructure.
That does not establish that Server Killers operates directly on behalf of the Russian government, nor have Norwegian authorities confirmed the group’s claim. The distinction between state-directed operations, loosely affiliated hacktivists and independent actors sympathetic to Russian interests remains important.
Nevertheless, the strategic effect can be similar: disrupting services, attracting media attention and attempting to impose a visible cost on governments supporting Ukraine.
In Norway’s case, the attackers appear to have achieved visibility more successfully than lasting disruption. The campaign became the largest DDoS attack Digdir says it has experienced, yet the targeted public services remained available for almost the entire attack.
That makes the incident both a warning and a demonstration of defensive resilience.The volume of politically motivated cyberattacks against European infrastructure is increasing, but a large attack does not automatically translate into a successful compromise.
Original report at SecurityWeek