Pro-Russian Hackers Launch Cyberattack on Norway’s Public Digital Services
Pro-Russian hackers have claimed responsibility for a major cyberattack on Norway’s public digital services, disrupting critical infrastructure for three days.
Introduction
A pro-Russian hacking collective has asserted responsibility for a significant disruption targeting Norway’s digital public services, which has persisted for three days. The incident, initiated on Monday, involved sustained cyber operations that overwhelmed the Norwegian Digitalization Agency’s (Digdir) infrastructure, according to Are Kvistad, a spokesperson for the organization.
Details of the Cyberattack
Digdir, tasked with modernizing and streamlining government services, reported that the attack represented the most severe cyber threat it has encountered. The assault utilized Distributed Denial of Service (DDoS) tactics, flooding the agency’s systems with excessive traffic to disable critical functions.
Impact on Government Services
One affected service enabled users to access multiple government platforms through a single authentication mechanism. Despite the pressure, Digdir maintained operational continuity, with Kvistad noting that services remained functional “practically throughout the entire period.”
Pro-Russian Group’s Claim
The pro-Russian group Server Killers claimed accountability for the attack in a Telegram post shared on Wednesday, as reported by Norwegian media outlets. The group cited Norway’s renewed security collaboration with Ukraine as a catalyst for the operation, referencing the country’s decision to extend military and financial support to Kyiv.
Reason for the Attack
On August 23, Norwegian Prime Minister Jonas Gahr Støre announced during a visit to Kyiv that Norway would allocate 85 billion Norwegian kroner (approximately 9.2 billion U.S. dollars) from the 2027 state budget to fund aid for Ukraine for the third consecutive year. The agreement also included enhanced cooperation on drone technology and other advanced defense systems.
Norwegian Officials’ Response
Norwegian officials have not publicly addressed the hackers’ claim. The incident aligns with broader European concerns over increased Russian cyber activities since the 2022 invasion of Ukraine. Authorities warn that such attacks aim to destabilize European nations, erode public confidence, and divert resources from critical investigations.
Broader European Cybersecurity Concerns
In 2025, Norwegian authorities linked a sabotage attempt at a dam to Russian cyber actors. Hackers infiltrated a digital control system managing a dam’s valve operations, manually adjusting it to increase water flow. A three-minute video published on Telegram at the time displayed the control interface and a marker linking the incident to a pro-Russian cybercriminal group.
Cyberattacks in Denmark
Recent reports highlight similar patterns across the region. In 2024 and 2025, Danish officials attributed cyberattacks on infrastructure and websites to Russian-linked entities. The water utility company in Denmark faced a “destructive attack” by the group Z-Pentest in 2024, while another group, NoName057(16), targeted Danish websites ahead of the 2025 local elections. Both groups were linked to Russian state interests.
Conclusion
The evolving threat landscape underscores the need for heightened vigilance as cyber operations continue to intersect with geopolitical tensions.
“Digdir maintained operational continuity, with Kvistad noting that services remained functional ‘practically throughout the entire period.’”
