THIS CONTENT IS BROUGHT TO YOU BY NTNU Norwegian University of Science and Technology - read more

Professor: Why we should expect cyberattacks during major events

"They may want to spread a particular message, reinforce a particular ideological narrative, or simply create unrest and spread fear,” the professor says.

Portrait of Basel Katt
“Following the death of Queen Elizabeth II in 2022, fairly sophisticated phishing attacks were carried out," says Professor Basel Katt.
Published

Along with heads of state and royalty from around the world, large crowds gathered in Oslo during King Harald’s funeral on September 9, 2026. The capital was therefore subject to extensive security measures.

There were snipers on rooftops and police checkpoints controlling access to the city centre. Around 3,000 police officers were mobilised in total. Incident commander Tomm Berger of the Oslo Police District described the security operation as one of the most extensive in Norwegian history, according to Norwegian news agency NTB.

But it was not only the physical space that came under pressure during events like these.

“The security authorities will also significantly step up their digital preparedness,” says Basel Katt, a professor and cybersecurity expert at NTNU.

He believed this meant they were well equipped to deal with any potential cyberattacks.

At the same time, there was little doubt that the risk of attacks increases considerably when so much attention and so many resources are focused on a single event.

The professor warned of attacks with serious consequences.

Not the first time

“You don’t have to look far to find examples of cyberattacks carried out in connection with major events,” says Katt.

One of the best-known attacks targeted the 2018 Winter Olympics in South Korea.

“The event was attacked by a computer worm called Olympic Destroyer. Among other things, it disrupted Wi-Fi access at the various venues as well as ticketing systems,” he says.

Royal funerals have also been targeted by cyberattacks in the past.

“Following the death of Queen Elizabeth II in 2022, fairly sophisticated phishing attacks were carried out. Many British citizens received emails that appeared to have been sent by Microsoft, encouraging them to share personal memories of the Queen with the public,” says Katt.

The format resembled the kind of initiative recently launched by Norwegian public broadcaster NRK, inviting people to share their memories. But the emails were fake and required people to provide sensitive information before they could share their memories, fooling many in the process.

Risk of disinformation campaigns

The likelihood of disinformation campaigns also increases during events like this, explains the NTNU professor.

“This could involve newly created social media accounts spreading false information or manipulated images and videos to create a misleading impression of how events are unfolding,” says Katt.

The motivation for attacking events like this is not necessarily to disrupt the event itself, he explains. In other words, the attacks are not necessarily personal campaigns against the royal family or the deceased King.

“More often, it's about exploiting the attention these events attract to promote their own agenda. They may want to spread a particular message, reinforce a particular ideological narrative, or simply create unrest and spread fear,” he says.

More attacks may be coming

In the period leading up to the funeral, several public-sector IT services in Norway had been subjected to so-called denial-of-service (DoS) attacks. The Norwegian Digitalisation Agency and a number of universities and university colleges were among those affected.

“A DoS attack involves taking services offline by overwhelming them with traffic,” Katt explains.

Unlike phishing attacks, the purpose of these attacks is not to gain access to sensitive information or data.

“For example, it could involve a state military or non-military actor seeking to take our digital services and websites offline. The aim could be to send a signal that Norway as a nation is vulnerable to attack and that the authorities are not strong enough to protect us,” says Katt.

Denial-of-service attacks are relatively simple and inexpensive to carry out. Their most obvious consequence is often no more than a service being unavailable for a few hours.

“Nevertheless, such attacks can appear serious and therefore have a destabilising effect on the population,” says Katt. He describes this as a form of psychological warfare.

As with phishing attacks and disinformation campaigns, new AI tools have also made it much easier to carry out DoS attacks on a large scale, the professor explains.

"Don’t take everything at face value"

The cybersecurity expert has two pieces of advice during major events:

“Check where the information or requests you receive are coming from. It's generally perfectly safe to share memories and photos with an established public-service broadcaster. But if you receive a request to do so from an email address or phone number you don’t recognise, and it also requires you to log in, that should set alarm bells ringing.”

Katt also advises people to always be critical of what they read or see on social media:

“Don’t take everything at face value. Be aware that disinformation campaigns are often spread through social media, frequently by fake profiles and automated accounts designed to manipulate perceptions and create confusion.”

Reference:

Lundli et al. A Design Science Approach to Bridging Operational Cyber Detection and Strategic Crisis Management, IEEE Access, 2026. DOI: 10.1109/ACCESS.2026.3716866

———

Read the Norwegian version of this article on forskning.no

Powered by Labrador CMS