A pro-Russian hacker group calling itself Server Killers has claimed responsibility for a sustained denial-of-service campaign against Norway’s public digital services, an attack that officials say is the largest of its kind ever aimed at the country’s Digitalization Agency (Digdir).
Are Kvistad, a Digdir spokesperson, told the Associated Press the attack began Monday and continued for three consecutive days. The flood of traffic targeted services including the platform that lets Norwegian citizens use a single login across multiple government systems. Despite the volume of traffic, Kvistad said Digdir managed to keep its services running for nearly the entire duration of the assault.
Attack Tied to Ukraine Support
In a Telegram post widely reported by Norwegian media, Server Killers said it had declared cyber war on Norway following the country’s decision to renew security cooperation with Ukraine on August 23. That announcement came during a visit to Kyiv by Norwegian Prime Minister Jonas Gahr Stoere, who pledged 85 billion Norwegian crowns (roughly 9.2 billion dollars) in support for Ukraine from next year’s state budget, marking a third consecutive year of major funding. Norway and Ukraine also agreed to deepen cooperation on drone technology and other modern warfare capabilities.
Norwegian officials had not commented on the hackers’ claim as of publication.
Part of a Broader Pattern
The incident fits a pattern of escalating hybrid activity across Europe since Russia’s full-scale invasion of Ukraine in 2022. Officials across the continent say such attacks aim to undermine public support for Ukraine, sow fear and discord, and tie up scarce cybersecurity resources.
Norway has already faced suspected Russian-linked sabotage this year, after authorities said hackers likely gained remote access to a dam’s control system and opened a valve to increase water flow, an incident accompanied by a video posted to Telegram bearing the mark of a pro-Russian cybercriminal group.
Denmark has reported similar activity, with officials blaming the group Z-Pentest for a destructive attack on a water utility in 2024, and NoName057(16) for disrupting Danish websites ahead of 2025 local elections. Danish authorities said both groups have links to the Russian state.
For security teams supporting government or critical infrastructure services, the episode underscores the need for resilient DDoS mitigation and monitoring around politically sensitive announcements, particularly those tied to support for Ukraine.
