- A data breach occurred in dental practice management software. Several denial-of-service attacks targeted Estonian websites and services in September. The use of the state authentication service was disrupted on three occasions.
- A new Estonian information security standard entered into force in September. European trust service experts met in Tallinn. We warned about critical security vulnerabilities disclosed in WordPress software. We held an information day on information security and data protection for employees in the education sector.
- A ransomware group stole sensitive data from the systems of the Berlin state government and published it on the dark web. An OpenAI artificial intelligence agent breached the Medicare portal of Australia. Cybersecurity authorities from Japan, Australia, Germany, and the United States published an analysis of the activities of North Korea-linked threat actors on recruitment platforms.
Incidents reported to CERT-EE that had an impact on the confidentiality, integrity, or availability of data or information systems.
Phishing sites account for the largest proportion of incidents recorded by CERT-EE.
Situation in Estonian cyberspace
Innovaatik, a company providing information system services to dental care providers, announced that there had been repeated unauthorised access to the computer system it manages and that patients’ personal data, including health data, had been downloaded. Most of the downloaded data concerned dental treatment, but may also have included other medical history of patients. According to preliminary information, the data breach affected the data of more than 300 Estonian healthcare providers. Police detained a 45-year-old Estonian citizen suspected of the offence who had previously been associated with the company. According to current information, the suspect has not misused the data or disclosed it to anyone.
In early September, a campaign of denial-of-service attacks targeted Estonian websites. The range of targets was broad, but the volume of the attacks was relatively low. The main targets were the banking, healthcare, energy, transport, and water sectors, government websites, and the homepages of political parties. Some websites experienced short-term delays or disruptions, but the attacks had no significant impact. The attacks were purportedly carried out in response to the presidential election held on 2 September and the support of Estonia for Ukraine.
On 11 September, between 11:12 a.m. and 12:15 p.m., a distributed denial-of-service attack targeted the state authentication service TARA. From the beginning of the attack until 11:57 a.m., TARA experienced short-term disruptions and slowdowns. The attack attempted to overload the service with a large number of seemingly normal requests. More than 86 million requests were made during the attack, which is more than 100 times the usual volume. The protective measures blocked more than 90% of the requests, while the remaining requests temporarily overloaded the service.
On 11 September, the University of Tartu detected that attackers had gained access to its e-bookstore at raamatupood.utlib.ee. The attackers most likely downloaded customer data, including first and last names, email addresses, telephone numbers, online store usernames, and encrypted versions of the associated passwords, as well as data related to the use of the online store, such as purchase history, IP addresses, etc. According to initial reports, the attacker gained access to the site via an unpatched security vulnerability. After discovering the attack, the university shut down access to the e-bookstore and will reopen it once the website has been cleaned and the vulnerabilities have been eliminated.
On 16 September, between 1:46 p.m. and 2:59 p.m., the internal and external services of the Information Technology and Development Centre of the Ministry of the Interior (SMIT) experienced disruptions. Among other things, the operation of the Emergency Response Centre and calls to the emergency number 112 were affected, as were customer support call-handling solutions of SMIT and other internal services. The operation of websites administered by the Ministry was also disrupted, including rahvastikuregister.ee and eresident.politsei.ee. Calls to the emergency number 112 were disrupted between 1:50 p.m. and 2:33 p.m. During this period, calls entered a queue and the waiting time was longer than usual. The interruptions were caused by a technical failure: a configuration error occurred during scheduled maintenance work.
The use of the state authentication service was disrupted on four occasions. On 21 September between 10:45 a.m. and 12:15 p.m., on 24 September between 12:15 p.m. and 1:25 p.m., on 28 September between 3:30 p.m. and 4:25 p.m., and on 29 September between 1:44 p.m. and 2:11 p.m., GovSSO experienced disruptions, affecting the ability of users to log in to several state e-services, including the health portal, the Tax and Customs Board and the Transport Administration. We are conducting an analysis to determine the root cause of the disruptions.
Activities of the Estonian Information System Authority
A new Estonian information security standard entered into force on 1 September, which significantly reduces the involvement of the state in enforcing cyber defence requirements for public authorities and companies and places greater reliance on their own activities to protect data and systems. One major change is the removal of the previous rigid layer of measures prescribed by the state, which is expected to make implementation of the standard considerably faster and more logical. Another major change is a reduction in the obligation to commission external audits and a greater role for internal assessment in ensuring compliance with security measures for network and information systems. Read more on the RIA website and explore the Estonian information security standard on the https://eits.ria.ee/ portal.
European experts from regulatory authorities responsible for trust services gathered in Tallinn on 17–18 September to discuss developments related to eIDAS2, the digital identity wallet and post-quantum cryptography. At the meeting this year, Tais Vakrõõm, Lead Expert at the Supervision Department of the RIA, was also elected to the new ECATS (European Competent Authorities for Trust Services) Board. This gives Estonia greater opportunities than before to contribute to cooperation and shape developments in the European trust services sector. Nearly 70 experts from different European Union Member States attended the meeting. Over the course of two days, they discussed the new tasks arising from the NIS2 and eIDAS2 regulations and their implementation.
200,000 Mobile-ID users must replace the SIM card of their mobile operator before 19 May 2027. The need to renew Mobile-ID stems from amendments to the eIDAS Regulation of the European Union, which provide users with a modern and secure framework for managing their digital identity. The RIA blog explains when the SIM card should be replaced, how to do so, and what scams are circulating in connection with the replacement of Mobile-ID SIM cards. Read more about this on our blog.
We warned in our blog about critical security vulnerabilities disclosed in WordPress software. Due to the fact that a large number of Estonian websites use WordPress for their administration, the new security vulnerabilities may also affect our users. In the worst-case scenario, an attacker could gain full control over a website. To patch the vulnerabilities, WordPress must be updated to version 7.1.2 or later. Read more about the WordPress security vulnerabilities on the RIA blog.
We held an information day on information security and data protection for employees in the education sector. Employees of educational institutions received an overview of the cybersecurity situation in their sector, the new version of the Estonian Information Security Standard and the supervisory role of the RIA in the education sector. Gunnar Gabriel Einlo, a lawyer at the Estonian Data Protection Inspectorate, also gave a presentation on data protection in the education sector. The presentations from the information day are available for viewing on our YouTube channel.
RIA cybersecurity analyst Helena Jürgenson appeared on the ‘Küberruum’ radio programme of Äripäev to discuss how companies can genuinely reduce the risk of fraud. Together with Ivar Tennokes, Head of Digital Security Products at Elisa Eesti, and Urmo Keskel, Co-Founder of Phishbite, she discussed why cybersecurity starts with management, how fraudsters exploit email accounts, Teams, QR codes and artificial intelligence, and why even experienced specialists can make mistakes. Listen to the programme on the website of Äripäev.
International situation
The Rhysida ransomware group, which managed to infiltrate the networks of the Berlin state government in August and steal nearly six terabytes of data, has now published the stolen documents on the dark web. The documents include highly sensitive information on critical infrastructure, including vulnerabilities in the water supply network and the defence and crisis plans of the state, as well as the personal and salary data of several thousand people and court documents. The Berlin state government activated a crisis response plan following the leak to assess its extent and inform all affected individuals. The state government brought in the US company CrowdStrike to help assess the scope of the incident. However, granting the company access to municipal networks has itself caused controversy in Germany.
An international team of researchers discovered that spyware had been installed, or attempts had been made to install it, on the devices of a Serbian member of parliament, a local opposition politician and several students who had participated in anti-government protests. The infections took place in December last year and January this year, and the researchers identified two different types of spyware. One of them is the Israeli-developed Pegasus, while the other is a new type of malware for the Android operating system called NoviSpy. According to the international human rights organisation Amnesty International, Serbian authorities have previously used spyware to monitor protesters, investigative journalists and dissidents, but the current wave is considered the largest to date.
The cybercrime group ShinyHunters, which focuses on extortion, announced in August that it had stolen more than 284 million records from the US medical products wholesaler McKesson. The group demanded approximately USD 55 million in ransom in exchange for not publishing the data, but the company refused to pay. According to the data breach aggregation website Have I Been Pwned?, the group has since published the email addresses of approximately 6.4 million customers, along with other data. McKesson has confirmed the data breach in its statement and acknowledged that, for some customers, information about diagnoses, treatment, and test results was also exposed. Although the company primarily operates in the United States, the breach may also affect some European customers.
Cybersecurity authorities from Japan, Australia, Germany, and the United States published an analysis of the activities of North Korea-linked threat actors on recruitment platforms.The campaign is attributed to the WaterPlum group and involves contacting IT professionals seeking employment on recruitment platforms and social media groups, conducting a fake job interview with them and sending them a test assignment. When the assignment is downloaded, the device of the applicant becomes infected with malware. The purpose of the infection is to steal data and gain access to the cryptocurrency assets of the victim. According to the analysis, at least 30,000 devices in more than 100 countries, including the United States, Japan, and European countries, were infected in this way between December 2025 and July 2026, and cryptocurrency worth more than USD 10.7 million was stolen.
In mid-June, an artificial intelligence agent developed by OpenAI breached the Medicare portal of the Australian healthcare system. The AI agent was operating autonomously as part of a research task assigned to it, but independently found a way to bypass security measures and gain access to non-public files on the portal. These consisted mainly of statistical data, no sensitive health data was stored there. This is the first known case of an autonomous AI agent successfully breaching the database of a government agency. The Australian Prime Minister expressed concern over the incident, in part because OpenAI notified the Australian government of the incident three months later and did so via a general social services email address. OpenAI has since acknowledged that its AI agents may have accessed the systems of dozens of other organisations worldwide and government agencies in various countries in violation of applicable requirements.
In a recent cyberattack against the FBI, criminals managed to obtain sensitive data concerning the health and physical fitness of thousands of FBI agents. According to Reuters, the leaked data included information on agents involved in investigations concerning Russian and Chinese activities, as well as employees working on investigations into drug cartels. The attack has been claimed by the cybercrime group ShinyHunters, which focuses on data theft and extortion, and the group has also shared samples of the stolen data with journalists. According to the group itself, the attack was carried out through an Oracle cloud service used by the FBI, although the FBI has not confirmed this to date.
Last updated: 06.10.2026