The website of Norway's parliament went down for 80 minutes. It was inaccessible from most of the world for nearly four hours after Oslo reported a return to normal
The website of the Norwegian parliament stopped working on Monday shortly after three in the afternoon. TV 2 reports that by 3:03 p.m. the pages were already unavailable and that they apparently returned to normal at 4:23 p.m. The pro-Russian group Server Killers claimed the attack on Telegram, announcing it would last three hours. TV 2 ↗
The Storting itself spoke more cautiously. "We are registering some instability on our pages and are working on stabilization measures," the parliament's head of IT, Bjarne Østby, wrote to NRK. The public broadcaster also noted that at that point it had not yet been confirmed whether the cause was indeed a denial-of-service attack, and that with this type of attack some users manage to reach the site despite the problems. VG's own journalists saw this on their screens too, alternately managing to get in and failing to. NRK ↗
A denial-of-service attack, abbreviated as DDoS, works on the principle of overload. A large number of devices send so many requests to a site at once that an ordinary user cannot reach it. The attack itself does not involve either a system breach or a data leak. Nettavisen ↗ The Digitalisation Agency emphasized exactly this when the group attacked its services three weeks earlier. According to the agency, the systems were not breached and nothing indicated that users' personal data had leaked. The Barents Observer ↗
Server Killers describes itself as a pro-Russian group active since 2023, specializing precisely in this type of attack against authorities and public services. According to the Barents Observer, it has previously claimed attacks on websites in Denmark, Britain, Romania, and Canada, and is often linked to another pro-Russian group, NoName057(16). The same report adds that independent confirmation that it is indeed behind the attacks in Norway does not yet exist. The only source of the claim is its own Telegram channel. The Barents Observer ↗
The reason the group gives is Norwegian support for Ukraine. In late August it declared "cyber war" on Norway and justified it on Telegram with a specific date. "Reason for the attack: on August 23, Norway and Ukraine signed a new agreement on defense and security cooperation focused on a drone agreement, under which Norway continues to strengthen Ukraine's defense capability through the Nansen Programme," it wrote, according to TV 2. Forsvarets forum ↗
In the background is also the sum Oslo intends to send to Kyiv next year. Prime Minister Jonas Gahr Støre has announced an intention to allocate 85 billion Norwegian kroner to Ukraine in next year's state budget, which at Monday's European Central Bank exchange rate amounts to roughly 7.9 billion euros. The budget has not yet been approved. European Central Bank ↗
The parliament is so far the latest in a line of Norwegian public targets. The biggest strike came on the night of August 24, when an attack hit the Digitalisation Agency and lasted three days. According to Forsvarets forum, for the agency itself this was not the first case, but already the third attack in quick succession on its shared infrastructure, and also the strongest. It affected about ten services, including the electronic identification systems ID-porten and MinID, the Altinn portal, and digital mail. Agency spokesperson Are Kvistad told the NTB news agency on Wednesday morning that the attack was still ongoing, that solutions were running and stable, but that ID-porten still had limitations, and that this was becoming critical for several customers and services. The investigation was taken over by the criminal police unit Kripos, and the Police Security Service PST was monitoring the situation. The Barents Observer ↗
In early September, universities followed, among them the universities of Agder and Oslo, NMBU, the University of South-Eastern Norway, and OsloMet. On Friday, September 4, the website of the Directorate of Immigration UDI stopped working, which Server Killers claimed, and on the same day Feide, the national solution for secure login to digital services in education, also went down. Regarding Feide, VG explicitly wrote that it was not certain the same group was behind it, but the method was identical. Last week it was the turn of the services of the state lottery company Norsk Tipping. VG ↗
On Monday, the parliament was not the only one affected. At 10:43 a.m., the state agency Sikt, which operates shared systems for Norwegian higher education, published an operational notice about an ongoing denial-of-service attack. According to the notice, among other things the student portal Studentweb, the university application system Samordna opptak, and again Feide could have been intermittently unavailable. The notice is marked as resolved and last updated at 1:31 p.m., less than two hours before the Storting's problems began. Sikt ↗
Norway's National Security Authority, NSM, does not consider these attacks a threat to state security. "In general, we unfortunately have to say that denial-of-service attacks are part of the normal picture," the agency's expert director, Andreas Skjøld-Lorange, told VG. According to him, the motives can vary, from seeking attention to undermining trust in public authorities and important institutions. If the public repeatedly and over a long period cannot access needed services, trust declines. He added that the scale varies — some attacks are so small almost no one notices them, others knock out services for days at a time, which is why it is important to have both a response procedure and backup solutions ready. VG ↗
The Storting knows the difference between this and an actual breach from its own experience. In August 2020, it learned of an extensive network operation against itself and reported it to the police in early September. PST concluded its investigation on December 8, 2020, and stated that the operation was likely carried out by actors known in open sources as APT28 and Fancy Bear, linked to Russian military intelligence GRU and its 85th Main Special Service Center. The attackers used brute force to try passwords against a large number of accounts in the parliament's email systems and gained access to some of them. Emails and personal data of staff and members of parliament were stolen. The Norwegian government publicly identified Russia as responsible as early as October 2020. PST ↗
Norway also has experience with an intrusion from outside that did not stay confined to a screen. On April 7, 2025, someone gained control of a valve at the Risevatnet dam near Bremanger between 12:57 p.m. and 4:49 p.m. and opened it fully, so that approximately five hundred liters of water per second drained from the reservoir. No physical damage occurred, and the volume of water was far below what the dam can withstand. It was not, moreover, a technically demanding attack: the control panel was accessible from the internet and protected by a weak password. The pro-Russian group Z-Pentest Alliance claimed the act on Telegram, and in June 2025 it also published a three-minute video of the intrusion. VG ↗
PST head Beate Gangås attributed responsibility for this case to pro-Russian actors in August 2025 and also explained why she said so publicly. According to her, the purpose of such acts is to exert influence and generate fear or unease among a country's inhabitants, and the public has a right to know about this risk. The Russian embassy in Oslo rejected the attribution. According to a case overview compiled by NATO's CCDCOE center in Tallinn, no official report with a formal state attribution has been issued. PST and Kripos concluded their investigation in October 2025 with the finding that pro-Russian hackers were behind the attack, but shelved the case because it was not possible to identify specific individuals. iLaks ↗ CCDCOE ↗
One aspect of Monday's case remains open. While Norwegian media reported that the sites had returned to normal by 4:23 p.m., it was still not possible to access the parliament's server from abroad many hours later. In our own measurement at 8:25 p.m. Central European time, a connection on port 443 failed to go through from our server and from thirty-eight of the forty measurement points of the check-host service located around the world. The connection succeeded only from Kyiv and from Shiraz, Iran. The server thus does respond on that port, and it is not a complete outage, though an open connection alone cannot confirm whether the page would actually load. The Wayback Machine archive, which downloads the site from the United States, still showed a normal response of 200 on September 12, and no new record has been added since September 13. Internet Archive ↗
Restricting traffic from certain networks is among the common defensive measures against denial-of-service attacks, but the Storting did not comment on this, and the cause cannot be determined from the measured data. All that is certain is that "resolved" in Norwegian news reporting and the site's accessibility from the points we measured from were not the same thing on Monday evening.
Read also: Hackers published data from the Berlin administration after a ransom refusal
Photo: The building of the Norwegian Storting in Oslo. Author: Ryan Hodnett / Wikimedia Commons, CC BY-SA 4.0.
The Storting itself spoke more cautiously. "We are registering some instability on our pages and are working on stabilization measures," the parliament's head of IT, Bjarne Østby, wrote to NRK. The public broadcaster also noted that at that point it had not yet been confirmed whether the cause was indeed a denial-of-service attack, and that with this type of attack some users manage to reach the site despite the problems. VG's own journalists saw this on their screens too, alternately managing to get in and failing to. NRK ↗
A denial-of-service attack, abbreviated as DDoS, works on the principle of overload. A large number of devices send so many requests to a site at once that an ordinary user cannot reach it. The attack itself does not involve either a system breach or a data leak. Nettavisen ↗ The Digitalisation Agency emphasized exactly this when the group attacked its services three weeks earlier. According to the agency, the systems were not breached and nothing indicated that users' personal data had leaked. The Barents Observer ↗
Server Killers describes itself as a pro-Russian group active since 2023, specializing precisely in this type of attack against authorities and public services. According to the Barents Observer, it has previously claimed attacks on websites in Denmark, Britain, Romania, and Canada, and is often linked to another pro-Russian group, NoName057(16). The same report adds that independent confirmation that it is indeed behind the attacks in Norway does not yet exist. The only source of the claim is its own Telegram channel. The Barents Observer ↗
The reason the group gives is Norwegian support for Ukraine. In late August it declared "cyber war" on Norway and justified it on Telegram with a specific date. "Reason for the attack: on August 23, Norway and Ukraine signed a new agreement on defense and security cooperation focused on a drone agreement, under which Norway continues to strengthen Ukraine's defense capability through the Nansen Programme," it wrote, according to TV 2. Forsvarets forum ↗
In the background is also the sum Oslo intends to send to Kyiv next year. Prime Minister Jonas Gahr Støre has announced an intention to allocate 85 billion Norwegian kroner to Ukraine in next year's state budget, which at Monday's European Central Bank exchange rate amounts to roughly 7.9 billion euros. The budget has not yet been approved. European Central Bank ↗
The parliament is so far the latest in a line of Norwegian public targets. The biggest strike came on the night of August 24, when an attack hit the Digitalisation Agency and lasted three days. According to Forsvarets forum, for the agency itself this was not the first case, but already the third attack in quick succession on its shared infrastructure, and also the strongest. It affected about ten services, including the electronic identification systems ID-porten and MinID, the Altinn portal, and digital mail. Agency spokesperson Are Kvistad told the NTB news agency on Wednesday morning that the attack was still ongoing, that solutions were running and stable, but that ID-porten still had limitations, and that this was becoming critical for several customers and services. The investigation was taken over by the criminal police unit Kripos, and the Police Security Service PST was monitoring the situation. The Barents Observer ↗
In early September, universities followed, among them the universities of Agder and Oslo, NMBU, the University of South-Eastern Norway, and OsloMet. On Friday, September 4, the website of the Directorate of Immigration UDI stopped working, which Server Killers claimed, and on the same day Feide, the national solution for secure login to digital services in education, also went down. Regarding Feide, VG explicitly wrote that it was not certain the same group was behind it, but the method was identical. Last week it was the turn of the services of the state lottery company Norsk Tipping. VG ↗
On Monday, the parliament was not the only one affected. At 10:43 a.m., the state agency Sikt, which operates shared systems for Norwegian higher education, published an operational notice about an ongoing denial-of-service attack. According to the notice, among other things the student portal Studentweb, the university application system Samordna opptak, and again Feide could have been intermittently unavailable. The notice is marked as resolved and last updated at 1:31 p.m., less than two hours before the Storting's problems began. Sikt ↗
Norway's National Security Authority, NSM, does not consider these attacks a threat to state security. "In general, we unfortunately have to say that denial-of-service attacks are part of the normal picture," the agency's expert director, Andreas Skjøld-Lorange, told VG. According to him, the motives can vary, from seeking attention to undermining trust in public authorities and important institutions. If the public repeatedly and over a long period cannot access needed services, trust declines. He added that the scale varies — some attacks are so small almost no one notices them, others knock out services for days at a time, which is why it is important to have both a response procedure and backup solutions ready. VG ↗
The Storting knows the difference between this and an actual breach from its own experience. In August 2020, it learned of an extensive network operation against itself and reported it to the police in early September. PST concluded its investigation on December 8, 2020, and stated that the operation was likely carried out by actors known in open sources as APT28 and Fancy Bear, linked to Russian military intelligence GRU and its 85th Main Special Service Center. The attackers used brute force to try passwords against a large number of accounts in the parliament's email systems and gained access to some of them. Emails and personal data of staff and members of parliament were stolen. The Norwegian government publicly identified Russia as responsible as early as October 2020. PST ↗
Norway also has experience with an intrusion from outside that did not stay confined to a screen. On April 7, 2025, someone gained control of a valve at the Risevatnet dam near Bremanger between 12:57 p.m. and 4:49 p.m. and opened it fully, so that approximately five hundred liters of water per second drained from the reservoir. No physical damage occurred, and the volume of water was far below what the dam can withstand. It was not, moreover, a technically demanding attack: the control panel was accessible from the internet and protected by a weak password. The pro-Russian group Z-Pentest Alliance claimed the act on Telegram, and in June 2025 it also published a three-minute video of the intrusion. VG ↗
PST head Beate Gangås attributed responsibility for this case to pro-Russian actors in August 2025 and also explained why she said so publicly. According to her, the purpose of such acts is to exert influence and generate fear or unease among a country's inhabitants, and the public has a right to know about this risk. The Russian embassy in Oslo rejected the attribution. According to a case overview compiled by NATO's CCDCOE center in Tallinn, no official report with a formal state attribution has been issued. PST and Kripos concluded their investigation in October 2025 with the finding that pro-Russian hackers were behind the attack, but shelved the case because it was not possible to identify specific individuals. iLaks ↗ CCDCOE ↗
One aspect of Monday's case remains open. While Norwegian media reported that the sites had returned to normal by 4:23 p.m., it was still not possible to access the parliament's server from abroad many hours later. In our own measurement at 8:25 p.m. Central European time, a connection on port 443 failed to go through from our server and from thirty-eight of the forty measurement points of the check-host service located around the world. The connection succeeded only from Kyiv and from Shiraz, Iran. The server thus does respond on that port, and it is not a complete outage, though an open connection alone cannot confirm whether the page would actually load. The Wayback Machine archive, which downloads the site from the United States, still showed a normal response of 200 on September 12, and no new record has been added since September 13. Internet Archive ↗
Restricting traffic from certain networks is among the common defensive measures against denial-of-service attacks, but the Storting did not comment on this, and the cause cannot be determined from the measured data. All that is certain is that "resolved" in Norwegian news reporting and the site's accessibility from the points we measured from were not the same thing on Monday evening.
Read also: Hackers published data from the Berlin administration after a ransom refusal
Photo: The building of the Norwegian Storting in Oslo. Author: Ryan Hodnett / Wikimedia Commons, CC BY-SA 4.0.
🔥 You might also like
World Politics
Norway's PM speaks of a drone near Zelensky's plane. His own office quickly softened it to a threat that delayed the flight
Støre told NRK a drone nearly hit Zelensky's plane leaving Moldova; the finance minister calls it an attack attempt. The PM's office is more cautious.
Ukraine
Plane carrying Zelensky nearly hit by drone during departure to Norway
The plane carrying Ukrainian President Volodymyr Zelensky nearly collided with a drone on Tuesday while departing from Moldova to Oslo. Zelensky was traveling t …
Music
Stevie Wonder to perform the entire Songs in the Key of Life album. He won't be coming to Czechia or Slovakia
Eighteen concerts for the album's 50th anniversary. In Germany he'll play October 24 in Hanover and October 26 in Cologne; presale opens September 9.
Geographic locations
From our newsroom original
All →
Le Pen launches campaign, holds significant lead in polls

Pellegrini asked parliament to deliver a State of the Republic address

Boris Johnson condemned the drone attack near the Polish-Ukrainian border

He was sentenced to 19 years for weapons trafficking and complicity in war crimes. He died before South Africa extradited him to the Netherlands

What Slovakia is writing about: Danko offered Taraba a seat, the dispute over Hotel Bobrovník peaks. Fico threatens government collapse

OpenAI agents cheated on a test and broke into Hugging Face. Sixteen states are now investigating the company

What Europe is writing about: Pavlohrad under attack, Vance the favorite for 2028, Israel shook Lebanon

Diesel is the most expensive in Slovakia since November 2022. Bratislava rejects lower tax, Prague a cap on margins