Norway’s Shared Digital Government Infrastructure Hit by a Third DDoS Attack
What Happened — Norway’s Digitalisation Agency (Digdir) and its service provider Vivicta suffered a third distributed‑denial‑of‑service (DDoS) attack in two months, beginning at 03:38 CEST on 24 August 2026. The flood of traffic knocked out several shared services (ID‑porten, MinID, Maskinporten, eFormidling, etc.) and caused downstream outages for citizen‑facing platforms such as Altinn, Helsenorge, NAV and Skatteetaten. No data compromise was reported.
Why It Matters for Compliance & Audit Readiness
- A DDoS event directly tests the Availability criteria of SOC 2 – auditors expect documented controls, monitoring, and incident‑response evidence that can demonstrate resilience against service‑disruption attacks.
- Continuous evidence collection (traffic logs, mitigation actions, post‑mortem reports) is essential to prove that the organization’s controls are operating effectively over time.
- Mapping the incident to SOC 2 controls (e.g., CC6.1 System Monitoring, CC6.2 Incident Management) provides ready‑to‑use audit artifacts and helps close gaps before the next audit cycle.
Who Is Affected — Public‑sector agencies in Norway; any organization that relies on shared authentication or API services for citizen interaction.
Recommended Actions
- Review and harden DDoS mitigation controls (traffic scrubbing, rate‑limiting, redundant endpoints) and map them to SOC 2 Availability criteria.
- Implement continuous logging and automated evidence collection for network traffic and mitigation actions to create a defensible audit trail.
- Conduct a tabletop exercise that simulates a DDoS impact on shared services and update the incident‑response playbook accordingly.
Source: Security Affairs
Technical Notes — The attack leveraged volumetric traffic flooding against the shared infrastructure; no specific malware or vulnerability was disclosed. Services experienced complete outages, connection failures, and prolonged login times. Source: same as above