Major Public Events Trigger Sharp Spikes in Cyber Threats and AI-Driven Attacks, Experts Warn
Cybersecurity researchers point to elevated risks of DoS attacks, credential harvesting, and AI-enabled disinformation during high-profile global gatherings.

As national focus centers on major public gatherings, municipal and federal infrastructure faces a sharp rise in digital threat activity alongside heightened physical security operations. During high-profile international events—such as the state funeral for King Harald in Oslo on Wednesday, Sept. 9, 2026—cybersecurity experts warn that malicious actors routinely leverage extreme public attention to launch coordinated cyber operations targeting digital infrastructure, public sector systems, and private citizens.
The physical scale of such events often requires unprecedented law enforcement deployment. In Oslo, approximately 3,000 police officers were mobilized alongside rooftop snipers and security checkpoints across the city center, an operation described by Oslo Police District incident commander Tomm Berger as among the largest in Norway’s history, according to Norwegian news agency NTB. However, as first reported by TechXplore, security officials must simultaneously enact significant increases in digital preparedness to counteract parallel cyber risks running alongside physical operations.
Basel Katt, a professor of cybersecurity and head of the Department of Information Security and Communication Technology at the Norwegian University of Science and Technology (NTNU) in Gjøvik, noted that while defensive teams prepare extensively, the concentration of global visibility severely heightens threat activity. Katt pointed to previous incidents where global events served as catalysts for disruption, including the 2018 Winter Games in South Korea. During that event, a malicious software strain known as the "Olympic Destroyer" computer worm disabled venue Wi-Fi networks and disrupted digital ticketing infrastructure.
Similar patterns emerged following the death of Queen Elizabeth II in 2022, when attackers executed sophisticated phishing schemes designed to harvest user credentials. Fraudulent communications masquerading as official notices from Microsoft prompted citizens to submit personal tributes, leveraging public sentiment to steal sensitive personal information. Katt highlighted that these tactics mirror risks surrounding current public engagements, such as digital memory-sharing drives hosted by legitimate outlets like Norwegian public broadcaster NRK, which scammers can spoof to compromise user accounts.
Beyond credential theft, high-visibility events routinely coincide with intensified disinformation campaigns and public service disruptions. Threat actors employ newly registered social media profiles, manipulated imagery, and synthetic video content to alter public perception and foster confusion regarding live events. According to Katt, the primary objective of these campaigns is rarely direct sabotage against specific figures or institutions; rather, adversaries exploit heightened public attention to broadcast specific ideological positions, project systemic instability, and induce widespread societal anxiety.
The vulnerability of public services is underscored by recent network disruptions across Norway's administrative infrastructure. In the weeks preceding the Oslo event, several public sector digital platforms—including the Norwegian Digitalisation Agency along with multiple colleges and universities—were targeted by distributed denial-of-service (DoS) attacks. Designed to overwhelm servers with artificial traffic spikes and render digital portals inaccessible, DoS operations represent an accessible and low-cost method for state-backed and independent actors to signal institutional vulnerability.
Advances in technology have further amplified the reach and speed of these threat vectors. Katt explained that modern artificial intelligence applications have significantly reduced the technical effort required to execute large-scale DoS attacks, automate phishing campaigns, and mass-produce convincing disinformation. Although typical DoS disruptions cause temporary site outages lasting only a few hours without compromising internal data, their visible nature produces a disproportionate psychological impact, serving as a form of low-intensity digital warfare.
To mitigate risk during high-profile national moments, cybersecurity experts emphasize vigilance among both network operators and the general public. Katt advised users to scrutinize unsolicited messages requesting login credentials or personal data, even when appearing to align with legitimate public memory initiatives. He further urged individuals to critically evaluate information encountered on social networks, noting that automated accounts and synthetic profiles are regularly deployed during high-visibility events to skew public narrative and sow distrust.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



