July in cyberspace: hacked websites, service disruptions, and phishing emails

05.08.2026 | 14:14

The Information System Authority (RIA) registered 1,044 cyber incidents in July. Over the course of the month, several websites experienced disruptions, defacements of Estonian websites became more frequent, and phishing emails sent posing as banks continued.

In July, RIA identified over a hundred Estonian websites that had been defaced. ‘Defacement means that an attacker gains access to a website and adds content of their own choosing to it. Often, for example, a message is added stating that the website has been hacked,’ explained Dorel Kiik, analyst at the Analysis and Prevention Department of RIA. ‘On this occasion, no malicious content was displayed to website users, but a malicious file had been uploaded to a web server. It was most likely a case of cyber vandalism,’ said Kiik.

The majority of the defaced websites used the Joomla content management system, and initial assessments suggest that access was gained via security vulnerabilities in Joomla’s plugins. RIA notified the administrators of the defaced websites of the threat.

‘We advise all website administrators who have received this notification to remove the malicious content as soon as possible, update their software, and change the login details of the website administrators,’ added Kiik.

In July, there were two instances of disruptions in the operation of the website of the Business Register. In both cases, the issue involved the website being scanned, and the problems were resolved after the settings were changed.

Due to poor weather and a storm warning, traffic to weather forecast websites increased on 11 July, and disruptions also occurred on other websites within the same administrative domain, such as lennuilm.ee, ilmateenistus.ee, airport.ee, kemit.ee, geoportaal.ee, kalaluba.ee, minu.kataster.ee, and riigimaaoksjon.ee.

A damaged data cable caused disruptions to Telia’s services in the small towns of Kambja, Ülenurme, and Roiu in Tartu County. Some home internet users were affected, and problems with mobile phone coverage in the area also occurred.

There were also disruptions to the websites managed by the Centre of Registers and Information Systems (RIK), caused by a technical fault that occurred during a software update.

Phishing emails purporting to be from Swedbank have been circulating again, claiming that it is time to update customer details and that the recipient needs to log in via the link provided in the email and confirm the accuracy of their details with their signature. The letter emphasised urgency and recommended that the details be updated immediately to avoid any potential problems with future bank transfers. The emails were sent from suspicious domains not owned by Swedbank.

‘We have been seeing letters like this for years, and they are sent out regularly posing as all the banks. The content is usually similar, and the email contains a phishing link designed to obtain Internet bank login details. This is a scam – banks never ask you to update your details by email,’ Kiik warned.

Annika Müür

Communication Specialist

open graph imagesearch block image