Norway’s shared digital government infrastructure has been disrupted by a large distributed denial-of-service attack, according to BleepingComputer, affecting services used across the public sector since Monday. The attack began at 03:38 CEST on Monday, BleepingComputer reports, and targeted infrastructure supporting services operated by the Norwegian Digitalization Agency, known as Digitaliseringsdirektoratet or Digdir, and its operations provider Vivicta. Digdir runs shared government services including public-service logins, electronic IDs and signatures, secure digital mail, government forms, public-record access, and data exchange between agencies. The incident caused several services to become fully unavailable for short periods, according to Digdir statements cited by BleepingComputer. Many affected systems have since been stabilized, but some services, including ID-porten and eSignering, remained partially inaccessible. Users may still see failed connections, slow server responses, and unusually long login times. The disruption is also affecting services that depend on Digdir even if they were not directly targeted. BleepingComputer reports that Altinn, Norway’s central platform for communication between citizens, businesses, and government agencies, warned users about login and operational problems and linked to Digdir’s status page. Norway’s tax administration agency, Skatteetaten, posted a similar notice about login issues and advised users to try again later. Digdir director Frode Danielsen said the investigation has found no indication of a security breach affecting the agency’s systems and no sign that personal data was compromised, according to BleepingComputer. That distinction matters: a DDoS attack is designed to overwhelm availability, not necessarily to break into systems or steal data, although agencies still need to confirm whether any secondary compromise occurred. Danielsen also said this is the third recent DDoS attack against Digdir, following one in June and another on August 3. Norway’s National Security Authority and the Norwegian Data Protection Authority have been notified. BleepingComputer says there is no official attribution for the current attack, while noting that Norwegian media have speculated about possible Russian involvement. Who benefits: Attackers benefit from the leverage created by shared government platforms: disrupting one layer can affect multiple public-facing services. Citizens and businesses benefit if Digdir’s stabilization work limits the disruption to availability rather than data compromise. Who's exposed: Public agencies and platforms relying on Digdir services are exposed to knock-on login and operational problems. Users of ID-porten, eSignering, Altinn, and tax administration services may face failed connections, slow responses, or long login times while recovery continues.