Last year in cyberspace will be remembered for the record 10,185 cyber incidents registered by RIA, most of which were fraud, phishing, and malicious redirects.
Gert Auväärt, Director of the National Cyber Security Centre, NCSC-EE, said that cyber threats are becoming a bigger concern for the ordinary people, as mass fraud does not only mean a loss of money, but also a loss of trust and sense of security. ‘How safe or unsafe people perceive cyberspace depends largely on their personal experience with cybercrime,’ said Auväärt.
The number of denial-of-service (DDoS) attacks directed at Estonia also increased in 2025: RIA registered a record of 756 attacks, which is more than one third higher than the year before. However, only slightly less than a hundred of these attacks had any impact on targeted services. This is a significant improvement compared to the past, when nearly every fifth attack was successful from the attackers’ point of view.
In addition to the increase in the extent and technical complexity of attacks, another significant development of the last year was the expansion of the list of attackers. Whereas Estonia used to be a popular target for pro-Kremlin hacktivists, last year we were also targeted by pro-Palestinian groups from countries in the Middle East, North Africa, and Southeast Asia. The most extensive attack campaigns against Estonia, which caused the most service interruptions, took place in April and May.
Ransomware attacks are still prevalent, with the number of attacks and the damage they cause on the rise worldwide. For example, ransomware attacks affected millions of air travellers last year, as well as several large and well-known industries. There were also attacks in Estonia that were concerning. For example, a logistics company fell victim for the second time, and a family medicine centre had its patient data, medical records, and appointment times encrypted by criminals.
In 2025, over 48,000 security vulnerabilities were registered, which is a fifth more than the previous year. Failure to install security updates that address vulnerabilities in a timely manner resulted, for example, in compromised VPN devices at two government authorities, a ransomware attack on an Estonian company, malware in an Estonian library system, and much more.
However, last year’s most extensive global disruptions were actually caused by technical failures in large cloud services. ‘It reminded us that even experts are unable to prevent disruptions. There are no borders in the cyberspace, and a weak link anywhere can affect people in Valga County and California alike,’ said Auväärt.
Seeing how criminals with ever-increasing capabilities are constantly devising new and successful schemes, the Director of the NCSC-EE predicts that new records will be broken in the cyberspace next year. ‘The question is whether we are ready for this and how much damage we are willing to suffer. Artificial intelligence and large language models are continuously developing, and criminals and aggressive regimes are using AI to attack their targets ever more quickly and effectively. At the same time, artificial intelligence is undoubtedly a powerful tool that makes everyday life easier for both people and organisations. However, we must not forget the risks involved and allow technology to take control away from people,’ warned Auväärt.