July in cyberspace: continuing denial-of-service attacks and scams

08.08.2025 | 10:48

The Information System Authority (RIA) registered 783 incidents with an impact in July, of which almost half featured scam websites. The monthly overview of RIA lists disruptions in the functioning of Mobile-ID, several denial-of-service attacks, and continuing scam calls, mainly in the name of the Estonian Health Insurance Fund, as cyber incidents with the greatest impact.

More critical incidents

In the last day of June, the SOS2 emergency call handling system was down for about an hour. During that time, emergency response centres processed emergency notifications on paper, which took longer than usual and resulted in call queues. The incident was caused by the response to a complex event: many users were simultaneously opening and updating the event, causing the system to continuously recalculate new dispatch plans. Due to a significantly higher than usual load, the server cache filled up, causing disruptions in the operation of SOS2.

Due to a denial-of-service attack, there were disruptions in the networks of various telecommunications operators in the functioning of Mobile-ID in the afternoon of 3 July. There were also disruptions in Mobile-ID service of Telia in the afternoon of 5 July, but the cause remains unknown to us.

In the morning of 8 July, the Eesti app failed to process queries for identity documents and other services for about an hour. As an option to use the app as a proof of identity had been added a day before, the number of users of the app and the number of queries grew steeply. This revealed a configuration error that did not manifest itself under lighter loads.

In July, denial-of-service attacks took place against the websites managed by the Estonian Centre of Registers and Information Systems (RIK), the name server of the Estonian Ministry of Defence and the Ministry of Justice and Digital Affairs, the website of Enterprise Estonia, as well as the border queue management information system eestipiir.ee. As a result, brief interruptions occurred in their operations, but the attacks did not have any wider imact. Once again, denial-of-service attacks were carried out against RIA, CERT-EE, SMIT, and TEHIK name servers, but they had no impact.

Scam calls seemingly on behalf of the Estonian Health Insurance Fund have continued actively over the summer. While a few months ago, the scam calls were mostly in Russian, we are now hearing more and more about fraudsters speaking fluent Estonian. In the call, it is claimed that the person has an unused benefit offered by the Estonian Health Insurance Fund, which they now wish to either refund or carry over to the next year. The employees of the Estonian Health Insurance Fund do not actually contact people on their own initiative, nor do they ask for document numbers, PINs, or other personal information. Such calls must be disconnected and no personal data should ever be provided.

Main updates and risks in the digital environment

Starting from 7 July, users of the Eesti app have been able to prove their identity directly via their smartphone by providing the service provider with digital ID card or passport data in the app. The use of the solution is voluntary for all, and will be rolled out gradually in cooperation with service providers. It should be noted that the document data in the Eesti app can only be used on the territory of Estonia and does not replace a physical document at the international level.

In a few months, Microsoft will discontinue the Windows 10 product support. Starting from 14 October 2025, there will be no security updates, new features, or technical support for Windows 10 Enterprise, Education, Home, and Pro. We also published a story on the RIA blog (in Estonian) about the risks associated with using outdated software and outlined various options for prepare for the end of Windows 10 support.

Annika Maksimov

Communications Specialist

open graph imagesearch block image