November in cyberspace: services disrupted by targeted attacks and technical mistakes

05.12.2025 | 10:20

The Information System Authority (RIA) registered 851 incidents in November. The most significant cases included denial-of-service attacks, a ransomware attack and technical failures. 

RIA’s monthly summary shows that in November, there were slightly more incidents with an impact in cyberspace than the average for the last six months. Estonia experienced service interruptions, targeted denial-of-service attacks against the Tallinn and Tartu official websites, one ransomware incident, and a Cloudflare technical failure that had a global impact on network services. Fraud, which causes enormous losses, is also still rampant. 

Major cyber incidents

On 1 November, the automated border control system, or ABC gates, were temporarily out of service. The interruption was caused by the expiration of a server certificate.

From the evening of 9 November until the afternoon of 10 November, the Health Insurance Fund’s public document register was unavailable. The incident was caused by a disruption in the certificate chain. 

In November there was a number of denial-of-service attacks against the Tallinn and Tartu official websites. On 11 November, tallinn.ee experienced several interruptions, the longest of which lasted 41 minutes. On 12 November, the tartu.ee website experienced several brief interruptions. A day later, tartu.ee was still experiencing interruptions caused by active mapping of the website. 

On 17 November, data stored on the server of a Tallinn-based company was encrypted, and the attackers sent a ransom demand to the victim. The company had a backup copy of the data, which was used to restore the services. Dorel Albin, analyst of the Analysis and Prevention Department at RIA, added that nine ransomware attacks have been reported to RIA this year and that anyone can fall victim to them. ‘There are telling examples from almost every sector where, at some point, a company’s systems are locked down and the question arises: pay the criminals or lose all the work done and a huge amount of data?" Albin described. ‘RIA advises not to pay criminals. Every ransom paid funds the next attack. Furthermore, there is no guarantee that you will actually get back the access you have lost.’

On 18 November, a technical failure lasting several hours affected the network services of global internet infrastructure company Cloudflare. The disruption affected services in many countries, including Estonia. For a few hours, websites such as Delfi, Eesti Ekspress, Õhtuleht, etv.ee, and vikerraadio.ee were unavailable. In addition, Enefit home page and LuxExpress and Elron websites were disrupted, making it impossible to purchase tickets. Cloudflare explained that the outage was caused by a mistake made during a routine database update, which triggered a technical chain reaction that affected a large part of the global internet. 

International situation

In November, a denial-of-service attack on websites linked to Belgian military intelligence, as well as a wave of denial-of-service attacks on the Danish government website and defence industry companies, was claimed by the pro-Kremlin hacker group NoName057. The attacks against Denmark took place in the week leading up to local elections and may have been intended to express discontent with Denmark’s strong support for Ukraine. 

French social services intermediary Pajemploi announced a major data breach in which sensitive personal data was stolen from their database. Potentially, 1.2 million people may be affected, and the leaked data includes names, dates of birth, addresses, social security numbers, and Pajemploi customer numbers. No ransomware group has yet claimed responsibility for the attack. 

On 24 November, three local authorities in West London announced that their services were being disrupted by a cyberattack. The affected local governments use the same IT infrastructure. The nature of the attack has not been officially commented on, but according to experts, there is reason to believe that it was a ransomware attack against an IT service provider.

Annika Maksimov

Communications Specialist

open graph imagesearch block image