Back to all lessons
Awareness Lessons
last month

Pro-Russian Group Launches 3-Day DoS Attack on Norwegian Government Services

The Server Killers group executed a sustained denial-of-service campaign against Norwegian public digital infrastructure, motivated by Norway's security cooperation with Ukraine. While services reportedly remained largely operational, a three-day disruption to citizen-facing portals like unified login systems highlights the real-world impact politically motivated cyberattacks can have on government continuity. This incident underscores that nation-state-aligned threat actors increasingly target allied nations' digital public services as an extension of geopolitical conflict. The ability to withstand the attack reflects the importance of pre-planned resilience measures, but also reveals that critical citizen services remain attractive and viable targets for prolonged volumetric attacks.

Tactical Insight

Immediate actions

  • Activate DDoS mitigation services (e.g., Cloudflare, Akamai, or national-level scrubbing centers) at the first sign of sustained volumetric attack traffic.
  • Coordinate with national cybersecurity agencies (e.g., NSM in Norway) and ISPs to filter malicious traffic upstream before it reaches government infrastructure.

Long-term improvements

  • Implement redundant, geographically distributed infrastructure for critical citizen-facing portals to ensure continuity during targeted attacks.
  • Establish formal threat intelligence sharing agreements with allied nations and CERTs to receive early warning of politically motivated threat actor campaigns.
  • Develop and regularly test a DDoS-specific incident response playbook that includes predefined escalation paths and communication protocols.

Detection & monitoring measures

  • Deploy real-time traffic anomaly detection to identify volumetric spikes indicative of DoS/DDoS activity before service degradation occurs.
  • Maintain continuous uptime and performance monitoring dashboards for all public-facing government services with automated alerting thresholds.