May in cyberspace: a rise in incidents with impact, more frequent fraud calls, and fake shops

09.06.2025 | 20:13

In May, the Estonian Information System Authority (RIA) recorded 1,107 incidents with impact, which is above the average of the last six months. In March, 336 phishing websites, mainly designed to steal user data, and 371 different types of fraudulent websites were discovered.

Among the cyber incidents with higher impact, the monthly overview of RIA highlights a ransomware attack on a company operating in Tallinn, disruptions at Tallinn Airport and East Tallinn Central Hospital, as well as an increase in fraudulent activities where criminals used fake online shops and made fraud calls on behalf of the Estonian Health Insurance Fund.

Major cyber incidents

In May, attackers managed to encrypt the data of a company operating in Tallinn, making its business applications unusable. According to initial information, the attackers penetrated the systems of the company through outdated software security vulnerabilities six months ago. Ransomware attacks often originate either from unpatched software or from a Remote Desktop Protocol (RDP) connection open to the internet. The threat assessment of RIA (in Estonian) provides recommendations on how to prevent ransomware attacks.

In the second half of May, there were two notable cases in Estonia where temporary IT failures disrupted public services. Both situations were resolved swiftly and the systems were back up and running within hours. During the night of 17 May, the automated border control system of Tallinn Airport was disrupted, affecting passengers on four different flights. On 29 May, East Tallinn Central Hospital was hit by a major IT failure, leading to a state of crisis being declared – the emergency department was rerouted and scheduled operations were postponed.

There were also a number of scams designed to phish for people’s data. Fake online shops were advertised on social media with promotional offers, for example, referring to the closure of the shop. In reality, these websites were set up to steal bank card and internet banking data. At the same time, fraud calls on behalf of the Estonian Health Insurance Fund continued – claiming that a person has an unused health benefit that can be transferred. The call asked for confirmation with Smart-ID or Mobile-ID PINs, which can grant access to a bank account.

We recommend to always check the background of online shops and disconnect suspicious calls immediately. Never share sensitive data or enter PINs. Detailed advice can be found on the IT-vaatlik portal.

Activities of RIA to improve cyber security in Estonia

To help companies take the first steps towards more cybersecure business processes, RIA has updated its cybersecurity quick guide for companies. The quick guide gives recommendations on how to protect the assets and employees of your company and how to recognise attacks and prepare for incidents.

A set of information security measures for small institutions and businesses (in Estonian) was also published. In addition, the E-ITS portal now offers the E-ITS support application (in Estonian, also known as ‘võlur’ (the wizard)), which aims to support organisations in implementing the requirements of the Estonian Information Security Standard.

RIA and Tehnopol Startup Incubator invite startups in the field of cybersecurity to participate in a new round of Cyber Accelerator, where they will have the opportunity to get advice from the best mentors in the field and 60,000 euros of support to develop their ideas. The programme will support early-stage cybersecurity companies with both product and business development for seven months. More information can be found on the Tehnopol website.

The monthly overview of RIA also includes a description of what is happening elsewhere in cyberspace. There is also information about the warning of the CISA, the FBI, and the Department of Energy, of an increase in attacks on the industrial equipment of US energy companies and the discovery of hidden communication devices in some Chinese solar inverters.

Information System Authority

open graph imagesearch block image