• Sources: status page, discussion
  • Summary: Digdir's status page records a denial-of-service attack against ID-porten that began about 01:00 on 2026-08-03 and degraded login into a second day. The page lists the affected services as ID-porten and MinID, eFormidling, ELMA, Selvbetjening, Altinn, Kontakt- og reservasjonsregisteret, eInnsyn, Maskinporten and Ansattporten. ID-porten is operated by Digdir's operating partner Vivicta. The status page reports all services back in normal operation from about 01:30 on 2026-08-04, a partial regression posted 09:45 CEST affecting connections from data centres in Germany, Switzerland, the Netherlands and Belgium, and normal operation declared again at 13:03 CEST.
  • Why it matters: One identity provider degraded login to Norwegian public services across roughly ten named dependent services, which is the concentration risk of national single sign-on in practice.
  • Follow-up: Track Digdir's post-incident report for attack volume and mitigation.

send feedback on this story