The actual interesting part about such an attack is not that something is down, but rather why someone would run it.
A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive.
So which actor would actually benefit from downing the Norwegian government?
DDoS tends to be monetised as DDoS-as-a-service. Taking down "significant" services is good advertising. Either that, or they plan to extort the Norwegian government.
But for such a "proof of power" a short attack which takes the service down once is enough, long attacks are not so common and actually require some work from the attacker
What do they benefit from taking down any government, NGO or civic work program? American systems, as well as larger European systems are constantly attacked. I've seen the same traffic. Fire walling off China, North Korea and smaller eastern European countries is a must if you ever plan to expose any internet exposed services.
Really, you have no one in mind? Someone who is sending hundreds of bombing drones daily to Ukraine, killing civilian population, women and children, and who is eager to send a message to NATO countries any way possible?
You don't understand Kremlin's mentality. Any even little nasty thing they can do to the West makes them giggle like Doctor Evil. "Oh, a NATO country's government infra was not protected from DDoS? Let's have fun, haha!" You are dealing with story book villains. I know, this sounds so ridiculous it's hard to believe someone can actually be like this. But then the reality check hits.
Electricity production in Norway is predominantly hydroelectric.
When it rains dams fill up. The water is drained into shafts with turbines, and electricity is generated.
However, even though we are big on hydroelectricity percentage wise I’m not sure it’s all that vast an amount of electricity on a global scale. We are a pretty small country after all.
According to Wikipedia, the Norwegian electricity sector had 40.26 GW installed capacity as of 2021 and was producing 157.113 TWh in the same year. [1]
Great Britain had 74.8 GW installed capacity in 2023 and was producing 292.7 TWh in 2023. [2]
> At the center of the disruption is ID-porten — the national login gateway operated by Norway's Digitaliseringsdirektoratet (Digdir), the government agency responsible for public-sector digitalization. ID-porten functions as the single sign-on portal through which Norwegian citizens authenticate themselves to access public digital services.
It seems to be a corporate service provider that's a dependency for many other services.
It's a little more complicated than that. Norway has a few authentication services that can be used to access government, health and banking services.
A service provider can use a few of these; and the government operates one meta service (idporten) that federates over BankID, MinID, Buypass and one more which I don't recall atm.
With eg MinID down you can't authenticate with the national id. With BankID down you can't authenticate via that privately operated id.
But with idporten down, you can't log in to most public services, as they generally don't allow direct login with BankID or MinID, but delegate to idporten (the identity portal) for auth.
This is single point of failure by design - but they have a pretty good track record so far of staying up.
I'd guess someone in the us fat-fingered ip ranges and mixed up 2.144.0.0/14 (Iran) with 2.148.0.0/14 (Norway)
Or someone entered 2.144.0.0/14 but on a machine without ECC and a bit-flip happened, turning it into 2.148.0.0/14.
The actual interesting part about such an attack is not that something is down, but rather why someone would run it. A lot of DDoS originates from script kiddies, but such attacks are usually very short lived as attacks are expensive. So which actor would actually benefit from downing the Norwegian government?
DDoS tends to be monetised as DDoS-as-a-service. Taking down "significant" services is good advertising. Either that, or they plan to extort the Norwegian government.
But for such a "proof of power" a short attack which takes the service down once is enough, long attacks are not so common and actually require some work from the attacker
If the attack doesn't last long, bystanders can't know whether it was trivially mitigated by the victim.
A shorter attack won't make as many news headlines, either.
Unless part of the social proof is that mitigation is more difficult.
What do they benefit from taking down any government, NGO or civic work program? American systems, as well as larger European systems are constantly attacked. I've seen the same traffic. Fire walling off China, North Korea and smaller eastern European countries is a must if you ever plan to expose any internet exposed services.
is there actually any source those attacks are really done by "script kiddies"?
More likely this more politically motivated and backed up by money and more capable groups
Yes, thats what I meant
Imo russia most likely
Probably a country that lost to Norway in the World Cup.
Really, you have no one in mind? Someone who is sending hundreds of bombing drones daily to Ukraine, killing civilian population, women and children, and who is eager to send a message to NATO countries any way possible?
That is much less effective than every other manner they tested on the past few years such as shadow fleets, ghost satellites etc.
Up to the moment it has not been the operation adopted which would make it weird.
On who would do it then, anyone who benefits from instability. From corporations trying to sell flocked uped sytems, politicians, etc.
There is one south american country who was attacked exactly this way before their head of the government was kidnapped.
You don't understand Kremlin's mentality. Any even little nasty thing they can do to the West makes them giggle like Doctor Evil. "Oh, a NATO country's government infra was not protected from DDoS? Let's have fun, haha!" You are dealing with story book villains. I know, this sounds so ridiculous it's hard to believe someone can actually be like this. But then the reality check hits.
It hasn't been majorly like that in twenty years.
Botnets are services now, a business. They gain customers by their effectiveness and resilience.
For $$50-100 you can deny service to a lot of big sites and services.
those script kiddies control botnets in foreign countries and use them to attack stuff just bc. its not their compute, so no marginal cost to them
The UK. It wants to steal Norway's vast stores of electricity.
"vast stores of electricity"?
Electricity production in Norway is predominantly hydroelectric.
When it rains dams fill up. The water is drained into shafts with turbines, and electricity is generated.
However, even though we are big on hydroelectricity percentage wise I’m not sure it’s all that vast an amount of electricity on a global scale. We are a pretty small country after all.
According to Wikipedia, the Norwegian electricity sector had 40.26 GW installed capacity as of 2021 and was producing 157.113 TWh in the same year. [1]
Great Britain had 74.8 GW installed capacity in 2023 and was producing 292.7 TWh in 2023. [2]
France was producing 537.7 TWh in 2020. [3]
Germany was producing 488.5 TWh in 2024. [4]
[1]: https://en.wikipedia.org/wiki/Electricity_sector_in_Norway
[2]: https://en.wikipedia.org/wiki/Electricity_in_Great_Britain
[3]: https://en.wikipedia.org/wiki/Electricity_sector_in_France
[4]: https://en.wikipedia.org/wiki/Electricity_sector_in_Germany
It stored energy. It's not stored electricity.
There's some interesting commentry at https://www.techtimes.com/articles/322754/20260803/norway-id... , which suggests that the widespread outage is due to a single point of failure:
> ID-Porten: When One Gateway Controls Everything
> At the center of the disruption is ID-porten — the national login gateway operated by Norway's Digitaliseringsdirektoratet (Digdir), the government agency responsible for public-sector digitalization. ID-porten functions as the single sign-on portal through which Norwegian citizens authenticate themselves to access public digital services.
It seems to be a corporate service provider that's a dependency for many other services.
It's a little more complicated than that. Norway has a few authentication services that can be used to access government, health and banking services.
A service provider can use a few of these; and the government operates one meta service (idporten) that federates over BankID, MinID, Buypass and one more which I don't recall atm.
With eg MinID down you can't authenticate with the national id. With BankID down you can't authenticate via that privately operated id.
But with idporten down, you can't log in to most public services, as they generally don't allow direct login with BankID or MinID, but delegate to idporten (the identity portal) for auth.
This is single point of failure by design - but they have a pretty good track record so far of staying up.
There has been also DDoS against my friend's employer ISP. He had to work a lot to mitigate. There was a random request before
Would the attack be successful is the Norwegian government used a way to protect itself against ddos like cloudflare or akamai?
<hat type="tinfoil">I wonder who wants the Norwegian gov infrastructure between a TLS terminating proxy service</hat>
The bus card ride purchase system was down today in my part of Finland. I wonder if it is related.
Bets on which AI lab it is this time?
Many important services with problems. Ouch. My guess is that the root cause is misconfiguration rather than an attack.
The Internet was supposed to withstand a nuclear attack
"The internet" is currently fine, besides Norwegian government services.
Also something designed to withstand something does not imply it survives other somethings.
Guess a nuclear attack would actually lessen the load on the global internet, rather than increase it - like a DDOS would!