January in cyberspace: technical glitches put several digital services to the test

06.02.2026 | 11:26

In January, the Information System Authority (RIA) registered 768 incidents with an impact that affected digital signatures, communications and banking services, as well as other companies.

The January summary reveals that the new year did not start off quietly in cyberspace. At midnight on 1 January, there were problems with providing digital signatures with Smart-ID, Mobile-ID, and ID cards. Among other things, it was not possible to digitally sign ambulance cards, so ambulance crews resorted to using pen and paper. It was also not possible to make bank transfers at Swedbank, SEB, LHV, and Coop. Some of the disruptions were resolved before midday while all services were back up and running by the afternoon. The disruption was caused by a software error – upon the arrival of 2026, the Digidoc4j base library no longer accepted responses from the validity confirmation service signed with the current key length.

The website tuuleliinid.ee, which sells tickets for ferries travelling between small islands and the mainland, was unavailable from 9 January until 12 January. The disruption was related to a change in the ticket sales service provider.

On 16 January, an electricity distribution company experienced a large-scale voice and data communication outage. The operation of vital services was not disrupted, but communication with customers was affected. The disruption was caused by a failure in the equipment of a telecommunications company.

In January, two companies reported ransomware attacks against them. On 12 January, a water company in Ida-Viru County was hit by a ransomware attack where data on 11 servers and some office computers was encrypted. The servers were restored from backup copies and there was no significant impact on the operations of the company. According to preliminary information, the attack originated from a device running an outdated operating system. On 13 January, an industrial company operating in Harju County was hit by a ransomware attack. The malware encrypted the data on one computer.

According to Dorel Kiik, an analyst at the RIA Analysis and Prevention Department, neither attack had a significant impact on the companies. ‘However, despite this, ransomware attacks can, in the event of a combination of unfortunate circumstances, bring the entire company to a standstill and cause significant losses. We recommend that all companies visit the IT-vaatlik cyber security prevention portal to learn how to prevent ransomware attacks and what to do if you fall victim to an attack,’ Kiik added.

On 22 January, card and cash transactions by some private and business clients of LHV were counted twice due to a technical error. The bank refunded the incorrectly reserved amounts to its customers.

On 23 January, disruptions occurred in the data and voice communications of Telia. International voice communications and some Internet services were also affected. The interruption was caused by a malfunction in the network equipment of an external partner of Telia.

On the night of 27 January, Elisa’s services were hit by a widespread outage. There were disruptions across Estonia in voice calls, mobile and cable internet, Elisa mobile-ID, self-service, website, and the streaming service Elisa Elamus. Services gradually began to recover during the night. The interruption began with a power failure at the data centre.

In addition, RIA warns that a new botnet called Kimwolf is spreading, through which cybercriminals use the home devices of ordinary users to carry out cyberattacks. Currently, there are an estimated two million infected devices connected to the Kimwolf network worldwide, including devices belonging to US government agencies. CERT-EE has identified the first infections in Estonia, but the exact number of infected devices is still being determined. The blog of the Information System Authority (in Estonian) provides more detailed information on how the botnet operates and which devices have been infected.

Annika Maksimov

Communications Specialist

open graph imagesearch block image