June in cyberspace: service disruptions and data breaches attracted attention

13.07.2026 | 13:51

The Information System Authority (RIA) registered 1,232 incidents with an impact in the Estonian cyberspace in June, which is slightly higher than the average for the last six months. During the month, disruptions affected several important public services, impactful denial-of-service attacks took place, and a customer data breach occurred in the booking system of a company operating in southern Estonia.

‘June showed that cybersecurity starts with reliable digital services as well as well-protected user accounts. The continuity of critical services and the basic security measures of organisations go hand in hand. Often, a single poorly protected user account is enough for attackers to gain access to sensitive data,’ said Dorel Kiik, analyst at the Analysis and Prevention Department of RIA.

In June, several important public services experienced disruptions. Incidents were recorded in the Automated Biometric Identification System (ABIS), the Government Cloud, and the X-tee timestamping service provided by RIA. In addition, denial-of-service attacks temporarily affected the CERT-EE name servers and the website politsei.ee. The causes of disruptions ranged from issues following software updates and human error to technical misconfigurations and denial-of-service attacks.

A data breach occurred in the booking system of a company operating in southern Estonia, exposing the personal and contact details of their customers. The cause of the incident was a compromised employee account, which was not protected by multi-factor authentication and was secured with a weak password. Kiik noted that to prevent such incidents, it is essential to implement multi-factor authentication for all accounts, use strong passwords, and regularly review access rights. ‘These are simple but highly effective measures that help to reduce both the risk of data breaches and account takeovers,’ Kiik added.

In June, RIA also contributed to strengthening cybersecurity resilience. An international training exercise was organised in which electricity and cybersecurity experts practised protecting critical infrastructure from cyber threats. The final CyberMeetUp of the season also took place, and the Latvian Minister of Defence recognised the Head of the National Cybersecurity Centre of RIA, Gert Auväärt, for his outstanding contribution to strengthening cyber cooperation between Estonia and Latvia.

In the international cyber landscape, attention in June was drawn to Chinese military intelligence attempts to use Western recruitment platforms to access sensitive information, cyber attacks against the US healthcare company DentaQuest and the University of Nottingham, and the investigation into the compromising of France’s national messaging application Tchap. A cyber incident also affected an agency under the Lithuanian Ministry of Health, involving the leak of approximately 62,000 records containing the personal data of physicians.

Bret-Maria Rikko

Communications Specialist

open graph imagesearch block image