Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway's Public Digital Services
A pro-Russian hacker group called Server Killers claimed responsibility for a sustained DDoS attack against Norwegian government digital services, calling it the "biggest attack" ever against the Norwegian Digitalization Agency (Digdir) The attack, ongoing since Monday, flooded services with massive traffic to disrupt operations, including the national single-sign-on system used by citizens across public services Norwegian officials reported that services remained operational "practically all th
Analysis
TL;DR
- A pro-Russian hacker group called Server Killers claimed responsibility for a sustained DDoS attack against Norwegian government digital services, calling it the "biggest attack" ever against the Norwegian Digitalization Agency (Digdir)
- The attack, ongoing since Monday, flooded services with massive traffic to disrupt operations, including the national single-sign-on system used by citizens across public services
- Norwegian officials reported that services remained operational "practically all the time" despite the sustained assault
- The attack was framed as retaliation for Norway renewing security cooperation with Ukraine on Aug. 23, including a commitment of 85 billion Norwegian crowns in aid and collaboration on drone technology
- This incident is part of a broader pattern of Russian-linked cyber sabotage across Europe, including a 2025 dam sabotage in Norway and similar attacks on Danish infrastructure and electoral websites
Why It Matters
This incident highlights the escalating intersection of geopolitical conflict and cyber warfare, as state-aligned hacker groups increasingly target critical digital infrastructure in nations supporting Ukraine. For AI and cybersecurity practitioners, it underscores the growing threat of coordinated denial-of-service campaigns against government digital services and the importance of resilient infrastructure design. The pattern also illustrates how cyber operations are being used as tools of hybrid warfare to undermine public confidence and strain national resources.
Technical Details
- The attack was a distributed denial-of-service (DDoS) campaign that overwhelmed Norwegian Digitalization Agency (Digdir) infrastructure with massive traffic volumes, targeting core public service platforms including the national single-sign-on system
- The attack persisted for at least three days, requiring sustained mitigation efforts to keep services running with minimal disruption
- This follows a precedent of Russian-linked actors targeting Norwegian critical infrastructure, including a 2025 incident where hackers gained access to a dam's remote control system and manipulated valve operations
- Pro-Russian hacker collectives such as Server Killers, Z-Pentest, and NoName057(16) have been identified as actors in a coordinated campaign across the Nordics, often publishing proof-of-compromise content on Telegram
- European nations are operating under heightened alert as Russia has intensified sabotage and malign cyber activity across the continent since its full-scale invasion of Ukraine in February 2022
Industry Insight
- Government agencies and critical infrastructure operators should treat sustained, geopolitically motivated DDoS campaigns as a baseline threat rather than an edge case, investing in traffic scrubbing, redundancy, and rapid failover capabilities
- The normalization of hacktivist groups claiming attacks on behalf of state actors blurs the line between criminal and state-sponsored operations, suggesting that defensive strategies must account for both opportunistic and strategically directed threats
- Organizations should prepare for multi-vector campaigns that combine infrastructure disruption with disinformation, as attackers increasingly use public claims on social media to amplify the psychological impact of cyber operations beyond the technical damage
Disclaimer: The above content is generated by AI and is for reference only.