RIA: May saw the highest number of cyber incidents with an impact recorded in the last six months

04.06.2026 | 09:28

In May, the Estonian Information System Authority (RIA) recorded 1,561 incidents with impact in Estonian cyberspace, which is highest of the last six months. Of these, 1,047 were scam and phishing websites. In addition, there were disruptions in the operations of several key public services, and attention was drawn to a case of fraud committed against the Estonian Artists Association, resulting in losses of nearly 700,000 euros.

‘May showed that in Estonian cyberspace, we must continue to address both the reliability of services and fraud. With over a thousand registered scam and phishing websites, and the case involving the Estonian Artists Association, it is clear that cybercriminals are increasingly focusing on manipulating people and abusing their trust,’ said Dorel Kiik, an analyst at the RIA Analysis and Prevention Department.

During May, there were disruptions to the operation of several public services. Short-lived disruptions were recorded on open data portals, the European Union’s Entry/Exit System (EES), the Health Insurance Fund’s partner management information system, the Commercial Register, and the Police and Border Guard Board’s identity verification and case management system, UUSIS. The causes of the disruptions ranged from technical faults and human error to partner system glitches.

In May, particular attention was drawn to a fraud committed against the Estonian Artists Association, as a result of which the organisation lost nearly 700,000 euros. According to Kiige, to prevent such incidents, organisations should regularly review their payment approval processes, set reasonable transfer limits, and use a multi-level approval process for larger payments. ‘It is also important to train staff to recognise telephone scams, phishing attempts, and other forms of social engineering,’ she added.

To raise cyber awareness, RIA recommends that organisations familiarise themselves with the materials on the IT-vaatlik prevention portal and sign up for the RIA Cyber Test, which helps to assess and improve the cyber security awareness of employees.

In May, several high-profile incidents came to light in the international cyberspace – hackers gained access to Lithuanian government databases; a report by the Polish Internal Security Agency highlighted attacks on the networks of water treatment plants in five cities; and data on customers of Zara and Škoda, as well as patients at several German university hospitals, was leaked.

 

Annika Maksimov

Communications Specialist

open graph imagesearch block image