Security Digest 031, Special — Audio
Listen to the audio version of this special, voiced by Andrew.
In Brief
Norway has been under a sustained denial-of-service campaign since 20 June. Five waves, ten weeks, and the intervals between them, start to start, run 44 days, 21 days, 5 days, 4 days. The first three hit the state’s shared login layer through Digdir. The fourth, on 29 August, hit Sikt, which runs Feide, Studentweb and the admissions system for higher education. The fifth began at 12:30 on 2 September and is running as this is written. It hit eight universities by name.
Nothing has been breached. That is the point of the technique, and the reason it keeps working.
We measured the attacked services at 19:58 and again at 20:12 on 2 September, from two places at once. From a Norwegian residential line every service answered within a tenth of a second. From a VPN exit in Zürich, four of them refused the connection outright and a fifth took four and a half seconds to complete a handshake. The login services, Feide and Noroff’s learning platform, answered both. That difference is what the rest of this issue is about.
The Five Waves
| When | Target | Scale | Claimed by | |
|---|---|---|---|---|
| 1 | 20 to 22 June | ID-porten, through Digdir’s operator Vivicta | about 42 hours, over a weekend | nobody |
| 2 | 3 August, Monday morning | Pharmacies and e-prescriptions, Helsenorge, Altinn, municipal portals | recovered by Tuesday | nobody |
| 3 | 24 to 26 August, from 03:38 Monday | Ten Digdir services: ID-porten, MinID, Altinn, Maskinporten, eFormidling, ELMA, eInnsyn, Ansattporten, eSignering, Digital postkasse | about 64 hours wall clock, intermittent, two to three times the previous wave’s traffic by Digdir’s own measure | Server Killers, on Telegram, 26 August |
| 4 | 29 August, 18:31 to 21:57 | Sikt: Feide, Studentweb, Felles studentsystem, Samordna opptak, Educloud, fsweb, Vitnemålsportalen, cristin.no, and UiO. Nineteen services | three and a half hours to stabilise | a Russian group, per Khrono |
| 5 | 2 September, from 12:30 | UiT, NTNU, UiO, UiA, Innlandet, USN, NMBU, OsloMet, and Sikt’s FS sites | open at time of writing | Server Killers, per VG |
Sources for the dates and durations are digi.no and NTB for wave three, Sikt’s own status page and NRK Innlandet for wave four, Sikt’s status page, Uniforum and the VG and TV2 reporting for wave five, and hard2bit’s summer timeline for the first two.
One figure needs handling with care. Wave three has been reported at thirty hours. Digdir’s spokesperson Are Kvistad told digi.no the attack began at 03:38 on Monday and that there had been no attack activity after 19:30 on Wednesday. That is closer to sixty four hours of wall clock. Coverage describes the attack as intermittent, with a pause and a resumption at 17:15 on the Tuesday, so the shorter figure is most likely cumulative attack time. No source states which is meant. We print both.
What We Measured
The question that matters to anyone who depends on these services is simple. When a wave is on, does the service still answer you? The answer depends on where you are standing, and we can show that rather than assert it.
At 19:58 on 2 September, with wave five running, we made the same TLS connection to each attacked service from two doorsteps at the same minute. One was a Norwegian residential line, Lyse in Moss. The other was a Proton VPN exit in Zürich on a Datacamp datacenter address, the kind of egress a privacy-minded person uses without thinking about it. The instrument was curl’s time to complete the TLS handshake, with a fifteen second ceiling.
| Service | Home line | VPN exit |
|---|---|---|
| fsweb.no | 0.09 s | no connection |
| vitnemalsportalen.no | 0.09 s | no connection |
| fellesstudentsystem.no | 0.11 s | 8.30 s |
| uit.no | 0.13 s | 0.33 to 0.77 s across five samples |
| learning.noroff.no | 0.12 s | 0.18 s |
| idp.feide.no | 0.10 s | 0.27 s |
A second reading at 20:12, taking the worst of three samples on the VPN side, added the universities themselves. From the home line, every one answered in a tenth of a second. From the VPN exit, uio.no, ntnu.no, fellesstudentsystem.no and vitnemalsportalen.no refused the connection, fsweb.no took 4.5 seconds, and uit.no, Feide and Noroff answered normally.
This is what scrubbing looks like from outside. Under attack, the operators or their mitigation providers are shedding traffic that does not look Norwegian, and a datacenter address in Switzerland is the first thing shed. Sikt’s own operations board said as much in plainer words on 27 August, closing an ID-porten notice on 27 August with Digdir still handling residual traffic problems from abroad. We had measured the same shape on 28 August, when ID-porten refused TLS from this exact VPN exit while answering in 65 milliseconds from home, and we had measured it disappear on 30 August when the wave ended and both doorsteps answered alike.
So the mechanism is now observed three times across two waves and two operators. Foreign egress is a live variable while a wave is on and a non-issue outside one.
Two things this measurement does not show, stated once. It does not show who is being filtered on purpose and who is collateral, because a scrubbing appliance does not explain itself. And it does not show the universities’ internal systems, only their public front doors. Both limits are real and neither changes the practical reading.
Who Is Claiming It, and Who Is Investigating
Server Killers claimed wave three on Telegram on 26 August and tied it to Norway renewing defence and security cooperation with Ukraine on 23 August, and to Norway’s planned NOK 85 billion in support for 2027. VG reports the same group claiming wave five. Khrono attributes wave four to a Russian group without naming one. No Norwegian authority has confirmed any attribution, and digi.no’s own commentator advised taking the Telegram claim with a pinch of salt. A group announcing a hit on a channel it controls is a claim. It sits in a different class of evidence from a court affidavit naming a company, which is what the US Justice Department produced the same week for two Chinese scanning platforms.
Kripos has an investigation open. Prosecutor Birgitte Valen told digi.no it is natural to see the attacks in connection with one another, which means Norwegian law enforcement treats the waves as one campaign. PST is monitoring. Defence Minister Tore O. Sandvik told VG on 26 August that Norway is being continuously tested, and declined to attribute the activity to a state. NSM’s reading of the motive, reported by Dagsavisen on 25 August, is that it may be aimed at weakening public trust in the authorities. Digdir’s director Frode Danielsen has stated there is no indication of a security breach or of personal data being compromised. UiO’s IT subdirector Dagfinn Bergsaker confirmed the fifth wave on 2 September in one sentence: “vi er under nytt DDOS-angrep.”
The wider frame is not subtle. A NATO official told Reuters on 30 August that Russian hybrid activity across Europe is intensifying. On 2 September Germany formally blamed Russia for an explosive-laden drone found beside a Ukrainian cargo aircraft at Leipzig-Halle on 4 August, and announced it will close the Russian consulate in Bonn. The European pattern over the past year runs through Polish district heating, a Swedish heating plant, and now Norwegian identity and education infrastructure. It favours disruption and doubt over theft.
What This Is Doing, and What It Is Not
This is not a breach, and reading it as one misses what is happening. No data has left. No system has been entered. Digdir has said so explicitly, through its director, and nothing reported about Sikt or the universities contradicts it.
What the campaign does is make the shared layer unreliable at moments that matter. Norway has concentrated identity into a small number of names. ID-porten for the state, Feide for education, Altinn for business. A country that has done that has also concentrated confidence into those names, and confidence is what a denial-of-service campaign spends. For an ordinary person the exposure is a morning when the bank, the tax office and the university all refuse entry and nothing tells you why. For an institution it is an examination sitting, an application deadline or a payment run that depends on an identity provider answering at nine o’clock.
The cadence matters more than any single wave. Two of the five began in the small hours of a Monday. One took a weekend. The intervals have shortened from six weeks to four days. The sector has moved from Digdir’s shared layer, through Sikt’s shared layer, to the institutions’ own front doors. That is a campaign finding new targets rather than re-hitting a hardened one. Nothing about the stated trigger has changed, and there is no Norwegian election in 2026 for it to run out against. The next one is Kommunevalget in September 2027.
The reasonable expectation is recurrence over months. Sustained, opportunistic, aimed at trust.
What to Do
- If you depend on Feide or ID-porten for anything time-bound, write the fallback down now. Exam sittings, application deadlines, payment runs. A documented path that does not require the identity provider to answer at the minute it is needed.
- Log in early and stay logged in. The exposure is the authentication moment. A live session survives an identity provider outage. A fresh login at nine o’clock does not.
- Sit on a Norwegian address for anything that matters during a wave. We have now measured foreign egress being shed three times. A VPN exit abroad is a bet you do not need to take for the duration of an exam or a filing.
- Do not take a service’s own status page as the whole story. Sikt’s board said core services were normal while its FS sites refused foreign connections. Both were true. Measure from where you actually are.
- Treat a Telegram claim as a claim. Attribution comes from Kripos, PST or NSM, or it has not come.
- Expect Monday. Two of five waves began before dawn on one. If your week has a Monday morning that cannot slip, it has a risk the other days do not.
By the Numbers
- 5 waves in 74 days
- 44, 21, 5, 4: days between them
- 19 Sikt services in wave four, 8 universities named in wave five
- 0.09 s and no connection: the same service, the same minute, two doorsteps
- 0 breaches reported by any operator
- 3 times we have now measured foreign egress being shed during a wave
Method and Data
Measurements were taken with curl from two hosts under FTRCRP’s control, reporting the TLS handshake time to each public hostname with a fifteen second ceiling. The 19:58 reading was a single sample per host except uit.no, which was five. The 20:12 reading took three samples per host on the VPN side and reports the worst. Both readings are published alongside this piece as norway_ddos_measurements_2026-09-02.tsv, twenty-eight rows, tab separated. The overnight log is on file and follows when the night is over. Wave dates and durations are as published by the operators and the outlets named above, with the one contradiction printed rather than resolved.