A pro-Russian hacking group calling itself Server Killers claimed responsibility on Wednesday, August 26, 2026 for a distributed denial-of-service attack that disrupted Norwegian government digital services for several days, according to the Associated Press and multiple cybersecurity outlets including BleepingComputer and The Record. The group said in a Telegram post, widely reported by Norwegian media, that it had “declared cyber war” on Norway after the country renewed its security cooperation with Ukraine on August 23.
Are Kvistad, a spokesperson for the Norwegian Digitalization Agency (Digdir), told the AP that the attack began Monday, August 24, and had affected multiple government digital services over three days. BleepingComputer reported that the attack started at 03:38 CEST that morning and targeted infrastructure supporting services operated by Digdir and its operations provider, Vivicta.
The Record reported that the incident disrupted roughly ten digital services used for identity verification, logging into public services, exchanging data and documents between government agencies and businesses, accessing public records, and managing employee access. Among the affected systems was ID-porten, Norway’s digital identification gateway, which the outlet said has more than 4.5 million users and provides access to services including BankID and MinID.
Security Affairs, which first reported the incident on August 25, characterized it as a DDoS attack rather than an intrusion resulting in data theft. The Server Killers group’s Telegram claim, cited by ABC News, tied the timing directly to Norwegian Prime Minister Jonas Gahr Støre’s meeting with Ukrainian President Volodymyr Zelenskyy around Ukraine’s National Flag Day on August 23.
Norwegian officials had not, as of the claim’s publication, independently confirmed Server Killers as the responsible party, and cybersecurity researchers caution that DDoS attribution based solely on a threat actor’s own claims should be treated carefully. The incident nonetheless illustrates how European governments’ digital-identity infrastructure has become a recurring target for politically motivated disruption tied to support for Ukraine.







