Lyce · Hybrid Watch

hw_6cd319f6c7b66e48

Pro-Russian DDoS cyberattack temporarily knocks out public and private Norwegian websites.

Norwegian authorities reported a distributed-denial-of-service (DDoS) attack that temporarily disrupted access to several public-sector and private websites across Norway, forcing suspension of online services for hours as cybersecurity teams scrambled to mitigate the flood of malicious traffic. The Norwegian National Security Authority (NSM) said the attack targeted a secure national data network, affecting both government and private portals, and that to its knowledge “it has not caused any significant damage” but clearly strained infrastructure and incident response capabilities. According to NSM and public statements, a criminal pro-Russian hacktivist group appeared to be behind the operation, with actors claiming responsibility in alignment with Russia’s wider cyber-pressure on Western states amid the war in Ukraine. The geography of the incident spans across Norway’s digital domain, including municipally hosted and nationally critical web services, reflecting how hybrid campaigns seek leverage points in interconnected infrastructure rather than physical borders. Officials quoted in the media suggested the incident was linked to political tensions arising from sanctions and allied responses to Russia’s invasion, making the attack a signal in the grey zone of hybrid conflict. Norway’s rapid mitigation and public messaging emphasised readiness, but the event underscored that even long-standing peaceful neighbours like Norway are subject to cross-border cyber pressure in contemporary conflict landscapes.

Occurrence
2022-06-29
Publication
2022-06-29T11:25:30Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
NO
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2022-06-29T11:25:30Z

    Norwegian authorities reported a distributed-denial-of-service (DDoS) attack that temporarily disrupted access to several public-sector and private websites across Norway, forcing suspension of online services for hours as cybersecurity teams scrambled to mitigate the flood of malicious traffic. The Norwegian National Security Authority (NSM) said the attack targeted a secure national data network, affecting both government and private portals, and that to its knowledge “it has not caused any significant damage” but clearly strained infrastructure and incident response capabilities. According to NSM and public statements, a criminal pro-Russian hacktivist group appeared to be behind the operation, with actors claiming responsibility in alignment with Russia’s wider cyber-pressure on Western states amid the war in Ukraine. The geography of the incident spans across Norway’s digital domain, including municipally hosted and nationally critical web services, reflecting how hybrid campaigns seek leverage points in interconnected infrastructure rather than physical borders. Officials quoted in the media suggested the incident was linked to political tensions arising from sanctions and allied responses to Russia’s invasion, making the attack a signal in the grey zone of hybrid conflict. Norway’s rapid mitigation and public messaging emphasised readiness, but the event underscored that even long-standing peaceful neighbours like Norway are subject to cross-border cyber pressure in contemporary conflict landscapes.