Norway’s $9.2 Billion Pledge to Ukraine Just Triggered Its Worst-Ever Cyberattack

(SeaPRwire) – By: Marcus Sinclair
Europe has been sitting on a razor’s edge since Moscow launched its full-scale invasion of Ukraine. The sabotage campaign across the continent is not random. It is systematic. Russian operatives are testing response times. They are probing defensive gaps. They are mapping fault lines in critical infrastructure. Norway felt that pressure on Wednesday. A pro-Russian hacker collective called Server Killers took responsibility for a major cyber assault on a European government. The attack hit Norway’s Digitalization Agency, known as Digdir. It was the largest assault on Digdir’s solutions in the agency’s history. The timing is not accidental. It followed a very public commitment from Oslo to Kyiv. On August 23rd, Norway renewed its security cooperation with Ukraine. The very next day, the cyber war declaration appeared on Telegram. That sequence tells you everything you need to know about how Moscow calculates its costs and escalates its pressure. The calculus is cold and precise. Make the aid visible, then make the cost visible. Oslo understood that risk when it made the pledge. The question is whether other capitals understand it yet. NATO members are learning this lesson the hard way. The alliance spent two decades building conventional deterrence. It has yet to build an equivalent framework for the digital domain. Every new aid package extends the target list. And Moscow is well aware of the asymmetry. The attack on Digdir proves it.
The attack started on Monday. It has been running for three days. The group used denial-of-service tactics, flooding Digdir’s servers with massive traffic to knock services offline. The agency manages the common login system that Norwegian citizens use to access multiple public services. Disrupting that system is not just about temporary inconvenience. It is about hitting the nervous system of the modern welfare state. Are Kvistad, the spokesperson, confirmed the scale. He stated it was the biggest attack against Digdir solutions that they have ever experienced. The agency managed to keep services running practically all the time. That is a testament to their operational resilience. But the fact that it took a three-day sustained assault to test that resilience is itself a concern. Server Killers made no secret of their motivation. They declared cyber war on Norway in a Telegram post. They directly tied the attack to the security cooperation announcement on August 23rd. The same day Prime Minister Jonas Gahr Støre announced the 85 billion Norwegian crowns pledge during a visit to Kyiv. That is roughly 9.2 billion US dollars for the third consecutive year. The agreement also includes cooperation on drone technology and other modern warfare systems. Norway’s officials have not commented on the hackers’ claim by publication time. The attack represents a new escalation in the hybrid warfare playbook. Denial-of-service attacks are relatively crude tools. But they are effective when directed at the chokepoints of digital governance. A disrupted login system means citizens cannot access healthcare records, tax filings, or social services. The economic cost of three days of degraded public service access in a country the size of Norway is significant. It is also a message. The message is simple. Aid to Ukraine has a digital price tag. And Moscow is collecting on it. The question now is whether European governments are willing to pay that price without changing course. Or whether they will start looking for ways to reduce their exposure. This is not cybercrime for profit. This is warfare by other means.
The Norwegian case is not an isolated incident. It is part of a broader pattern of Russian hybrid warfare across Europe. In 2025, Norwegian authorities attributed suspected sabotage at a dam to Russian hackers. The attackers gained access to a digital control system, opened a valve, and increased water flow. A video showing the control panel with a pro-Russian group mark was published on Telegram at the time. Danish authorities have drawn similar conclusions about their own incidents. Z-Pentest carried out a destructive attack on a water utility in 2024. NoName057(16) targeted Danish websites ahead of the 2025 local elections. Both groups have links to the Russian state, according to Copenhagen. Server Killers have been linked to previous attacks in Norway and other European countries, according to Norwegian media. The pattern is unmistakable. Moscow is using hacktivist proxies to wage a shadow war on its western flank. The objective goes beyond disruption. It is to drain investigative resources, spread fear, and erode public confidence in European governments. The 9.2 billion dollar pledge was a visible act of solidarity. It was also a visible target. Norway’s response so far has been measured. Officials did not comment on the hackers’ claim by publication time. That silence speaks volumes. It suggests the government is treating this as a serious national security matter, not a public relations exercise. The real question is whether European digital infrastructure is being adequately protected against this kind of sustained, coordinated pressure. The answer, quite frankly, is still no. European governments have spent years building digital services that citizens depend on. They have not spent equivalent time hardening those systems against state-sponsored aggression. Every day without a coordinated continental defense framework for critical digital infrastructure is a day Moscow gains ground in its shadow war. The Server Killers attack on Digdir is a warning shot. The next one may not be so easily shrugged off. European defense planners need to stop treating cyber infrastructure as a secondary concern. It is now a primary battlefield. The infrastructure that delivers healthcare, taxes, and social services to citizens is just as strategic as any fighter jet or naval vessel. Losing that distinction is the fastest way to lose this war. The cost of inaction will be measured not in territory lost, but in trust eroded and institutions weakened. Europe cannot afford to keep reacting to the last war.
Author bio: Marcus Sinclair, Senior Fellow at a prominent European geopolitical and security think tank, with two decades of experience analyzing hybrid warfare and transatlantic defense policy.