August in cyberspace: service disruptions, ransomware attacks, and phishing messages

03.09.2026 | 12:49

In August, the Information System Authority registered 899 cyber incidents with an impact. Over the course of the month, there were disruptions to several key services, a school in Harju County was hit by a ransomware attack, and a phishing campaign with the perpetrator purporting to be from the Transport Administration was circulating.

In August, technical problems caused disruptions to various services. For example, on 4 August, the ABC gates – i.e., the automated border control system – were not operational for outbound passengers at Tallinn Airport. The gates resumed operation after being restarted. The services of Swedbank were disrupted on two days – there were problems with making payments, logging into the bank, and withdrawing cash. Due to a configuration error, there was a network outage at Pärnu Hospital, and as a result, IT services were unavailable for nearly an hour and the normal operations of the hospital were disrupted. There were disruptions to GovSSO, the central sign-in service of the government, managed by the Information System Authority. This caused issues with logging into several e-services of the state. 

‘The incidents in August illustrate that not every disruption to a digital service is necessarily the result of a cyberattack. The service can also be affected by technical failures, configuration errors, or other IT issues. For the user, however, the impact may be the same – the service they need will be unavailable for some time,’ said Dorel Kiik, an analyst in the Analysis and Prevention Department of the Information System Authority.

On 28 August, a school in Harju County was hit by a ransomware attack, during which its file server, print server, and domain controller were encrypted. By now, the main services have been restored, and the exact circumstances of the incident are being investigated.

‘In the past, the start of the school has brought cyberattacks against schools and services in the education sector. Educational institutions should therefore take a critical look at the security, backups, and updates of their systems and ensure that a contingency plan is in place in the event of a potential incident,’ added Kiik.

In August, a phishing campaign took place where the perpetrator was purportedly from the Transport Administration. Messages claimed that the recipients had parked in a paid parking zone and received a fine. They were sent a link where they were asked to enter their card details for paying the fine. In reality, the link led to a website set up by fraudsters to gain access to the bank accounts of the victims to steal money.

‘Neither the police nor the Transport Administration send notices of fines by text messages. If an unexpected message requires you to act quickly and directs you to enter your bank details or bank card information via a link, you should treat it with utmost caution. It is always worth checking the legitimacy of a service or claim via the official website or another reliable source,’ emphasised Kiik.

Annika Müür

Communications Specialist

open graph imagesearch block image