August in cyberspace: fraudsters did not take a summer holiday

07.09.2025 | 18:10

The monthly overview of the Information System Authority (RIA) shows that various types of fraud are still prevalent. In August, the Information System Authority registered 759 incidents, 286 of which were scam websites.

According to Dorel Albin, Chief Analyst of the Analysis and Prevention Department of RIA, it seems that cybercriminals have not taken a summer break, as various types of fraud are still widespread in Estonia. ‘In August, it was reported that cybercriminals committed invoice fraud, posed as bank employees or police officers, and sent fraudulent emails and messages claiming to be sent on behalf of reputable companies,’ Albin explained.

For example, on 3 August, a sports association discovered that it had fallen victim to an invoice scam. The fraudster posed as an employee of a travel agency and offered athletes accommodation during competitions in Lithuania. When the invoice was paid, more than 3,000 euros were transferred to the fraudster’s account.

Last month, scam emails sent under the names of Elisa and Telia were particularly prevalent, concerning the overpayment or non-payment of invoices. Fraudulent messages were also sent claiming to be from SmartPosti, stating that the address needed to be updated for a parcel to be delivered.

According to Albin, all these schemes have the same goal – to obtain information and money from the victim. ‘Criminals use both technical means and psychology, stressing urgency or threatening additional charges, for example. Therefore, the most effective protection is awareness and critical thinking – especially when you are unexpectedly asked for payment, passwords, or other information. If you receive a suspicious email or phishing message, do not click on any links contained therein or enter your personal data, but forward the message to [email protected] and delete it,’ Albin advised.

Activities of RIA to improve cyber security in Estonia

In August, RIA organised the CyberWizards international cybersecurity summer camp for girls in Kehtna, Rapla County. The aim of the camp is to spark young people’s interest in technology and cybersecurity. This year, 87 girls aged 13–16 from ten different countries registered for the camp.

We published a threat assessment regarding a high-impact security vulnerability in Microsoft Exchange. The vulnerability allows an attacker to gain privileges in the cloud environment and affects the software versions Microsoft Exchange Server 2016, Microsoft Exchange Server 2019, and Microsoft Exchange Server Subscription Edition RTM. The threat assessment contains recommendations on how to mitigate the impact of this security vulnerability.

We have published a new online course, ‘Information Security for Managers’, at the Digital State Academy, which provides managers with practical knowledge on how to fulfil their role and responsibilities in ensuring the information security of their organisation, from strategic decisions to setting an example on a daily basis. The course takes approximately 30 minutes to complete, and all those interested are welcome to take it.

All users are advised to update their ID software to the latest version, available at id.ee. We released a new version of the ID software, 25.8, which improved the validation of digital signatures and updated the base libraries used in the software.

Annika Maksimov

kommunikatsioonispetsialist

open graph imagesearch block image