HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Norway’s Shared Digital Government Infrastructure Hit by a Third DDoS Attack

Norway’s Digitalisation Agency and its provider Vivicta faced a third DDoS attack in two months, knocking out shared authentication services and downstream citizen portals. The incident underscores the need for robust Availability controls and continuous evidence collection for SOC 2 readiness.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Norway’s Shared Digital Government Infrastructure Hit by a Third DDoS Attack

What Happened — Norway’s Digitalisation Agency (Digdir) and its service provider Vivicta suffered a third distributed‑denial‑of‑service (DDoS) attack in two months, beginning at 03:38 CEST on 24 August 2026. The flood of traffic knocked out several shared services (ID‑porten, MinID, Maskinporten, eFormidling, etc.) and caused downstream outages for citizen‑facing platforms such as Altinn, Helsenorge, NAV and Skatteetaten. No data compromise was reported.

Why It Matters for Compliance & Audit Readiness

  • A DDoS event directly tests the Availability criteria of SOC 2 – auditors expect documented controls, monitoring, and incident‑response evidence that can demonstrate resilience against service‑disruption attacks.
  • Continuous evidence collection (traffic logs, mitigation actions, post‑mortem reports) is essential to prove that the organization’s controls are operating effectively over time.
  • Mapping the incident to SOC 2 controls (e.g., CC6.1 System Monitoring, CC6.2 Incident Management) provides ready‑to‑use audit artifacts and helps close gaps before the next audit cycle.

Who Is Affected — Public‑sector agencies in Norway; any organization that relies on shared authentication or API services for citizen interaction.

Recommended Actions

  • Review and harden DDoS mitigation controls (traffic scrubbing, rate‑limiting, redundant endpoints) and map them to SOC 2 Availability criteria.
  • Implement continuous logging and automated evidence collection for network traffic and mitigation actions to create a defensible audit trail.
  • Conduct a tabletop exercise that simulates a DDoS impact on shared services and update the incident‑response playbook accordingly.

Source: Security Affairs

Technical Notes — The attack leveraged volumetric traffic flooding against the shared infrastructure; no specific malware or vulnerability was disclosed. Services experienced complete outages, connection failures, and prolonged login times. Source: same as above

📰 Original Source
https://securityaffairs.com/197826/cyber-warfare-2/norway-s-digital-government-infrastructure-hit-by-a-new-ddos-attack.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →