What do you do when BankID is down? — Audio
Listen to this Signal, voiced by Andrew. 18 min 50 sec.
The lede
Norway’s national login infrastructure went down at 03:38 on Monday 24 August and stayed degraded for three days. ID-porten, MinID, Maskinporten and the services that depend on them. Digdir says the attack activity stopped at 19:30 on Wednesday 26 August, roughly 64 hours after it began. Digdir’s operator had confirmed the cause at 08:11 on the Monday:
“Our operating partner Vivicta confirms that this is a denial-of-service attack.”
It was the second such attack in three weeks. The first, on 3 August, took down the same infrastructure the same way.
The most useful thing Digdir published during it was an admission that one of the worsenings was their own doing, not the attacker’s. That is in section 2, and it is the kind of update that makes a status page worth reading.
Who did it is the least useful question available. A pro-Russian group has claimed it and nobody has stood that up. The question worth the space is the one the National Security Authority put to Norwegian organisations twenty days before it happened, and which nobody has answered in public since: what is the fallback for a national login layer, who has tested it, and how long can Norway run without one?
And underneath that, the question for you. Sixty-four hours is two working days. What were you going to do?
1. What is down
From 03:38, Digdir’s shared national services stopped answering:
ID-porten · MinID · Maskinporten · Kontakt- og reservasjonsregisteret · eFormidling · ELMA · eInnsyn · Ansattporten · the self-service solutions
Digdir’s own 06:41 update sets out the blast radius, and the phrasing matters:
“Altinn, eSignering and Digital postkasse are also affected, as a consequence of login via ID-porten not being possible. The same applies to logins to public bodies that use ID-porten.”
Altinn, eSignering and Digital postkasse were not attacked. They failed because the login they depended on was gone, and so did every public body that outsources identity to ID-porten.
Norsk helsenett reported HelseID login failures over the same period. We have not established what that reached downstream, and we do not assert anything about it. Digdir noted that for some services, such as Helsenorge, the mobile app remained a route in.
The cause is not in dispute. Digdir, at 08:11:
“Our operating partner Vivicta confirms that this is a denial-of-service attack.”
2. The first day, and one reversal that was not the attacker
Mon 03:38 down
04:13 investigating
06:41 full scope published
07:25 availability returns
08:11 identified, Vivicta confirms denial-of-service
08:50 increased stability across all solutions
12:08 degradation: ID-porten, Ansattporten, KRR
12:20 stabilising
13:25 degradation again, several solutions
14:14 improving
16:09 "the attack is still going on", roughly twelve and a half hours in
21:13 stable, same restrictions as 16:00
22:01 "we are seeing the situation worsen"
23:49 reversed: the worsening was their own measures, not the attacker
Tue 08:15 "the attack has continued through the night and is still going on"
Wed 19:30 attack activity stops. Digdir confirms it the following morning
The 22:01 worsening was self-inflicted, and this is the correction that matters most. At 23:49 Digdir wrote:
“Some measures that worsened the situation for our solutions have been reversed. We are back to the same status as around 21:00.”
Some measures that worsened the situation for our solutions have been reversed. We are back to the same status as around 21:00.
That degradation was a defensive countermeasure going wrong, and Digdir said so themselves within two hours. It was not the attacker escalating. Reporting it as an attack wave would have presented a defender’s own reversed measure as enemy action. It is the single most useful thing on that status page, and the reason a live incident should not be written up from a single snapshot.
And the two earlier degradations, at 12:08 and 13:25, are now unexplained. Digdir has accounted only for the 22:01 one. They may be the same mechanism; they may be the attacker. This piece does not characterise them. It states the times and what Digdir said, and stops.
One phrasing worth noting: at 23:49 Digdir switched to the plural, “the attacks are still ongoing”. Their earlier updates said angrepet, singular. That may be loose writing at midnight, or it may not be. We are not building anything on it.
Digdir also said there would be no further updates overnight, and there were none. The 08:15 statement was the next.
3. This is the second attack in three weeks
On Monday 3 August, beginning around 00:50, the same infrastructure went down the same way: ID-porten, Altinn, Helsenorge, Skatteetaten, Maskinporten. Most services returned by 21:00 that evening.
Digdir’s own eFormidling notice refers to the denial-of-service attack against Digdir of 3 and 4 August, so that event ran across two days, not one.
Two attacks. Both Mondays. Both beginning in the small hours. Same target, same method, three weeks apart. That describes a pattern and nothing more. Who did it, and whether the two are one operation, are questions this piece leaves open.
4. What we measured, briefly, including where we got it wrong
We sampled two Digdir hostnames from a Norwegian consumer line and a foreign hosting network, every few minutes, from 23:23 on Monday to 11:58 on Wednesday. 2,236 measurements. The attack had already been running nineteen hours when we started, so this describes the middle of it.
Our first analysis was wrong and we are publishing that rather than burying it. We found ID-porten responding far more slowly than MinID and led on it. The gap was a one-second penalty in our own resolver, and it landed on all 144 of our ID-porten samples and one of 144 MinID samples, so it never cancelled out. Recomputed clean, ID-porten is marginally the faster of the two. We also printed a 7.4 second maximum that turned out to be timestamped inside the eleven minutes our probe was dying. Both withdrawn.
One finding survives. From 13:53 on Tuesday, ID-porten failed to answer in 366 rounds where MinID, from the same machine in the same second, answered normally. A resolver cannot do that. A path problem specific to one hostname could, and we did not capture the timing detail that would separate the two. What we can say is that traffic from one commercial hosting network was refused by ID-porten for most of a day and a half while the same network reached MinID freely.
What that is not. A hosting network is not a person. We never probed a foreign consumer line, so we have nothing to say about travellers, and the first version of this piece implied otherwise.
The raw data ships with this piece. 2,236 samples, including every failure of our own. Download the raw samples and check the arithmetic yourself.
5. A claim, and why a claim is not an answer
On Wednesday 26 August a pro-Russian group calling itself Server Killers claimed the attack on Telegram, and declared what it called “cyberwar” on Norway.
Their stated motive is Norway’s support for Ukraine, and they point at one thing in particular: a defence agreement signed on 23 August.
That agreement is real, and we checked it independently of the claim. On 23 August in Kyiv, President Zelenskyy and Prime Minister Jonas Gahr Støre signed a defence cooperation agreement and a joint declaration on strategic partnership, the Ellisiv Accord. Ukrainska Pravda reported it at 21:19 that evening.
On the money, be careful. Zelenskyy said he was grateful for the decision to “maintain a high level of support and allocate around US$9 billion for 2027”. That is his characterisation, not a figure inside the agreement. Barents Observer notes separately that Støre had previously announced an intention to allocate NOK 85 billion in next year’s budget, and that the budget has not yet been adopted.
ID-porten went down at 03:38 the next morning, six hours and nineteen minutes later.
The timing is now independently verified. That still falls a long way short of attribution. Barents Observer, which reported the claim, states plainly that there is no independent confirmation. As of Wednesday, no official source had named an actor, and it was not established whether the August incidents are connected.
A named expert has since said the same thing in public. André Schackt, quoted by digi.no on 27 August, made the sharper version of the point: you cannot be sure of anything here, and what Server Killers published reads as a declaration rather than an acceptance of responsibility. No verifiable evidence accompanied it.
Claiming a denial-of-service attack is free. It requires no access, no evidence and no capability, it cannot be checked from outside, and it cannot be disproved. Groups in this space claim each other’s work routinely, because attention is the product. A claim tells you who wants the credit. It does not tell you who sent the packets.
One detail cuts against the claim rather than for it. Barents Observer reports that Server Killers has itself been linked to NoName057(16), the group most associated with denial-of-service attacks on Nordic government targets. Groups in this space borrow each other’s reputations, and a claim from an actor already associated with a better-known one is worth less, not more.
One measurement from Digdir is worth more than the claim. Their press officer, quoted by The Record, comparing this attack with the one on 3 August:
“two to three times larger than what we experienced last time”
We report the claim because it was made and because it is now in the record. We are not reporting it as attribution, and neither should anyone else yet.
6. NSM published advice on exactly this, twenty days earlier
On 4 August, while the first attack was still running, the National Security Authority published advice. Its headline is an argument: denial-of-service attacks are disruptive, not dangerous. Martin Albert-Hoff, department director for operational cyber security, was blunt:
“Denial-of-service attacks are not dangerous. They are irritating.”
His analysis of the mechanism is correct. His analogy is a motorway with finite capacity: send enough traffic one way and you get a jam, then a stop. You reroute or block classes of traffic until flow returns. Nothing is broken; the road is full. And critically:
“In other words, nobody has got into the computer systems.”
Nobody got in. Nothing was read, altered or destroyed. Of confidentiality, integrity and availability, only the third was touched. DDoS is the loudest and least sophisticated thing in the catalogue, it is rentable by the hour, and treating each one as a national emergency hands the megaphone to whoever is paying. NSM’s refusal to supply that headline is deliberate and defensible.
But NSM did not stop at reassurance, and this is the part that matters now:
“Albert-Hoff adds that the attacks can have consequences for time-critical systems, and lead to financial losses.”
“Make sure you have a plan for handling it, as well as good fallback solutions. Another option is to test whether the measures you have put in place actually work.”
Time-critical systems. Financial loss. Have a plan. Have good fallbacks. Test that they work.
That is a correct diagnosis followed by specific advice, published twenty days before this attack. It was general guidance to Norwegian organisations rather than a directive to any one agency. It is quoted here because it asked the right question three weeks early.
7. The question we are actually asking
Not who did it. Not even how long it lasted.
What do you do when BankID is down?
Not the state, not Digdir, you. Standing at a counter, or in front of a form, or at a pharmacy, on the day the login does not work. Most people have never had to answer that, because for fifteen years the answer has been: click, sign in, done. It has worked so well that the question stopped being asked.
Norway built one clean, well-designed, universally adopted identity layer instead of forty poor ones. It is better than what most countries have. The cost of that success is that we retired the alternatives. The counter, the posted form, the phone line with a person on it, all of it went as inefficiency, and it was inefficiency, right up until the single remaining door was the thing under attack.
NSM put the question to Norwegian organisations on 4 August: have a plan, have good fallback solutions, and test that they work. Three weeks later the door shut for the second time in three weeks, for sixty-four hours.
So the question is whether that advice was taken, and nobody has said. Not what the fallback is for you personally, either, which is a question no directorate can answer on your behalf.
8. This is not armageddon, it is just war, and we have been here before
Self-preparedness is being discussed in Norway more than at any point in living memory. Emergency stores, cash at home, water for three days, iodine tablets. The advice has been issued across the Nordics and the Baltics, and it is not theatre. It is a state telling its citizens plainly that the buffer used to be its job and is now partly theirs.
Carry the buffer. Even two hundred kroner in a pocket, so you can eat for a couple of days without a card reader agreeing to it. That is not survivalism. That is the same arithmetic your grandparents did without needing to be told.
Because this is the territory we are in now: somewhere between bullets and ones and zeros. Nothing was destroyed this week. Nobody was hurt. A login was made unavailable for sixty-four hours, twice in a month, in a country whose entire relationship with its own state runs through that login. That is a cheap, deniable, rentable act, and it is aimed at exactly the thing we made indispensable.
Times have changed, and yet it rhymes.
Coda
The King died today.
He was three years old when the country he would one day be head of was occupied, and he spent the war abroad while his father and grandfather worked from London. He came home at eight to a place he could not remember unoccupied.
He was the last Norwegian head of state who was actually there. The last official person whose own memory reached back past 1945. That link is now archive and other people’s accounts, and it went on the same week somebody switched off the country’s front door to make a point about a defence agreement.
Long live the King. Rest in peace, grandfather.
Sources
- Quotations. Digdir’s and NSM’s statements were published in Norwegian. They are given here in English translation, and the Norwegian originals are held with the captures.
- status.digdir.no: the incident timeline. Page captured 26 August 23:05 CEST and held. Every Digdir quotation in this piece was checked against that capture, character for character. The NSM quotations in section 6 are from a separate NSM page which we hold locally but which is not part of that capture.
- NSM, “Tjenestenektangrep er forstyrrende, ikke farlig”, 04.08.2026, quoting Martin Albert-Hoff. Full Norwegian text held locally; the page is JavaScript-rendered behind Cloudflare and cannot be fetched with ordinary tools.
- Dagsavisen: 24 August incident, Digdir/Vivicta confirmation.
- VG, 3 August 2026 21:28: the earlier attack, ~00:50 start.
- Own measurements: dual-vantage sampling from a Norwegian consumer line and a Swiss hosting exit, plus a one-off twelve-node international probe at 23:29 to 23:31, which is a separate exercise from the Nordic spot checks and from the continuous two-vantage sampling. Continued to 2,236 samples through Wednesday 26 August. Exit host confirmed as Swiss by RIPE whois, not by IP geolocation.
- Ukrainska Pravda, 23 August 2026 21:19: the signing of the Ellisiv Accord in Kyiv, and Zelenskyy’s remark about US$9 billion for 2027. Page captured 28 August and held. Independent of the attacker’s claim.
- The Barents Observer, 26 August 2026: the Server Killers claim and the “cyberwar” declaration, with that publication’s own note that there is no independent confirmation. Page captured 26 August 23:05 CEST and held.
- digi.no, 27 August 2026 09:16: Digdir’s Are Kvistad confirming the attack stopped at 19:30 on 26 August, Kripos police attorney Birgitte Valen on treating the attacks as connected, and André Schackt’s assessment of the claim. Page captured 28 August and held.
- The Record / Recorded Future News, updated 25 August: scale, and Digdir stating no actor identified. Page captured 26 August 23:05 CEST and held.
- Raw measurement data: 2,236 samples, released alongside this piece so the analysis in section 4, including the part that failed, can be checked independently. Download the raw samples, TSV, 102 KB.
- kode24: excluded; date unconfirmed and content matches the 3 August event.