[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7M3lC5sGwk2Q93_iBvwW16DxXUVZLtYAUr5EV46-6FM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"1dcbeb3a-6f78-4744-96af-cec423a22622","pro-russian-group-launches-3-day-dos-attack-on-norwegian-government-services","9f2c6847-342d-44fe-8078-40a17db9200b","Pro-Russian Group Launches 3-Day DoS Attack on Norwegian Government Services","The Server Killers group executed a sustained denial-of-service campaign against Norwegian public digital infrastructure, motivated by Norway's security cooperation with Ukraine. While services reportedly remained largely operational, a three-day disruption to citizen-facing portals like unified login systems highlights the real-world impact politically motivated cyberattacks can have on government continuity. This incident underscores that nation-state-aligned threat actors increasingly target allied nations' digital public services as an extension of geopolitical conflict. The ability to withstand the attack reflects the importance of pre-planned resilience measures, but also reveals that critical citizen services remain attractive and viable targets for prolonged volumetric attacks.","**Immediate actions:**\n- Activate DDoS mitigation services (e.g., Cloudflare, Akamai, or national-level scrubbing centers) at the first sign of sustained volumetric attack traffic.\n- Coordinate with national cybersecurity agencies (e.g., NSM in Norway) and ISPs to filter malicious traffic upstream before it reaches government infrastructure.\n\n**Long-term improvements:**\n- Implement redundant, geographically distributed infrastructure for critical citizen-facing portals to ensure continuity during targeted attacks.\n- Establish formal threat intelligence sharing agreements with allied nations and CERTs to receive early warning of politically motivated threat actor campaigns.\n- Develop and regularly test a DDoS-specific incident response playbook that includes predefined escalation paths and communication protocols.\n\n**Detection & monitoring measures:**\n- Deploy real-time traffic anomaly detection to identify volumetric spikes indicative of DoS\u002FDDoS activity before service degradation occurs.\n- Maintain continuous uptime and performance monitoring dashboards for all public-facing government services with automated alerting thresholds.",[12,13,14,15,16,17,18,19,20],"CIS Control 13 – Network Monitoring and Defense","CIS Control 17 – Incident Response Management","NIST SP 800-61 Rev. 2 – Computer Security Incident Handling Guide","NIST SP 800-53 SC-5 – Denial-of-Service Protection","NIST SP 800-53 IR-4 – Incident Handling","NIST SP 800-53 SI-7 – Software, Firmware, and Information Integrity","ITIL 4 – Major Incident Management Practice","EU NIS2 Directive – Article 21 (Cybersecurity Risk Management Measures)","EU NIS2 Directive – Article 23 (Reporting Obligations for Significant Incidents)","published","2026-08-27T10:21:48.190962+00:00","2026-08-27T10:21:48.097+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.securityweek.com\u002Fpro-russian-hackers-claim-responsibility-for-major-cyberattack-on-norways-public-digital-services\u002F","pro-russian-hackers-claim-responsibility-for-major-cyberattack-on-norway-s-publi-8fd9c1","Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":36,"name":37,"slug":38,"description":39,"color":40},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]