portraits of professor in grey jacket outside
Professor Basel Katt believes it is likely that the Norwegian King’s funeral will prompt further cyberattacks. Fortunately, there are steps you can take to reduce the risk of being personally affected. Photo: Karen Stampen

Why we should expect cyberattacks during major events

When Norway’s attention turns to Oslo for the King’s funeral on Wednesday, it creates a vulnerable moment in the digital sphere that hostile actors may seek to exploit. NTNU professor Basel Katt advises people to be alert.

Large crowds are expected to gather in Oslo for King Harald’s funeral today (Wednesday 9 September 2026), alongside heads of state and members of royal families from around the world. Extensive security measures are therefore in place across the capital.

There will be snipers on rooftops and police checkpoints controlling access to the city centre. Around 3,000 police officers have been mobilised in total, and incident commander Tomm Berger of the Oslo Police District has described the security operation as one of the most extensive in Norwegian history, according to NTB.

But it is not only the physical environment that comes under pressure during events like this.

“The security authorities will also significantly step up their digital preparedness,” says Basel Katt, Professor and cybersecurity expert at NTNU.

Katt, who is also Head of the Department of Information Security and Communication Technology at NTNU in Gjøvik, believes this means the authorities are well prepared to deal with potential cyberattacks.

At the same time, there is little doubt that the risk of attacks increases considerably when so much attention and so many resources are focused on a single event. The professor warns of attacks with serious consequences.

Not the first time

“You don’t have to look far to find examples of cyberattacks carried out in connection with major events,” says Katt.

One of the best-known attacks targeted the 2018 Winter Olympics in South Korea.

“The event was attacked by a computer worm called ‘Olympic Destroyer’. Among other things, it disrupted Wi-Fi access at the various venues as well as ticketing systems,” says the cybersecurity expert.

Royal funerals have also been targeted by cyberattacks in the past.

“Following the death of Queen Elizabeth II in 2022, fairly sophisticated phishing attacks were carried out. Many British citizens received emails that appeared to have been sent by Microsoft, encouraging them to share personal memories of the Queen with the public,” says Katt.

The format resembled the kind of initiative recently launched by Norwegian public broadcaster ‘NRK’, inviting people to share their memories. But the emails were fake and required people to provide sensitive information before they could share their memories, fooling many in the process.

Risk of disinformation

The likelihood of disinformation campaigns also increases during events like this, explains the NTNU professor.

“This could involve newly created social media accounts spreading false information or manipulated images and videos to create a misleading impression of how events are unfolding,” says Katt.

The motivation for attacking events like this is not necessarily to disrupt the event itself, he explains. In other words, the attacks are not necessarily personal campaigns against the Royal Family or the late King.

“More often, it is about exploiting the attention these events attract to promote their own agenda. They may want to spread a particular message, reinforce a particular ideological narrative, or simply create unrest and spread fear,” he says.

More attacks may be coming

In recent weeks, several public-sector IT services in Norway have been subjected to so-called denial-of-service (DoS) attacks – a cyberattack designed to make a website, network or digital service unavailable to legitimate users. The Norwegian Digitalisation Agency and a number of universities and university colleges were among those affected.

Katt believes it would not be surprising to see more attacks of this kind during the king’s funeral.

“A DoS attack involves taking services offline by overwhelming them with traffic,” he explains.

Unlike phishing attacks, the purpose of these attacks is not to gain access to sensitive information or data.

“For example, it could involve a state military or non-military actor seeking to take our digital services and websites offline. The aim could be to send a signal that Norway as a nation is vulnerable to attack and that the authorities are not strong enough to protect us,” says Katt.

DoS attacks are relatively simple and inexpensive to carry out, and their most obvious consequence is often no more than a service being unavailable for a few hours.

“Nevertheless, such attacks can appear serious and therefore have a destabilising effect on the population,” says Katt. He describes this as a form of psychological warfare.

As with phishing attacks and disinformation campaigns, new AI tools have also made it much easier to carry out DoS attacks on a large scale, the professor explains.

Don’t take everything at face value

Many people will follow King Harald’s funeral digitally on Wednesday, whether through television broadcasts or social media. The cybersecurity expert has two pieces of advice:

“Check where the information or requests you receive are coming from. It is generally perfectly safe to share memories and photos with an established public-service broadcaster. But if you receive a request to do so from an email address or phone number you don’t recognise, and it also requires you to log in, that should set alarm bells ringing.”

He also advises people to be critical of what they read or see on social media:

“Don’t take everything at face value. Be aware that disinformation campaigns are often spread through social media, frequently by fake profiles and automated accounts designed to manipulate perceptions and create confusion,” the professor concludes.

Reference:
S. Lundli, E. Hashmi, M. M. Yamin and B. Katt, “A Design Science Approach to Bridging Operational Cyber Detection and Strategic Crisis Management,” in IEEE Access, vol. 14, pp. 114052-114071, 2026, doi: 10.1109/ACCESS.2026.3716866.