September in cyberspace: fewer incidents, but plenty of frauds

07.10.2025 | 09:59

The Information System Authority (RIA) registered 680 cyber incidents with impact in September, which is slightly lower than the average for the last six months. Although there was a slight decrease in the number of incidents, last month still saw some notable cases, such as disruptions to banking services and the continued widespread of phishing messages.

On the evening of 1 September, a command chain was launched via outdated WordPress software on the Laagri School website, blocking access to the site. The web server of the school was cleaned up and the software was updated.

Dorel Albin, an analyst at the Analysis and Prevention Department of RIA, reminds that cybercriminals constantly scan the network, trying to find devices and websites with security vulnerabilities. ‘To avoid such situations, we recommend keeping yourself informed about important security vulnerabilities. A good opportunity for this is the RIA blog, where we report on the most important security vulnerabilities every week,’ she added. 

On 16 and 25 September, there were disruptions in the operation of the ticket sales system on Elron’s website, and the timetable search function was also unavailable. The disruptions were caused by technical faults in the system of the service provider.

There were also disruptions in the operations of several banks. For example, on 3 September the login function, card payments, and payment terminals of Swedbank were disrupted. On 8 September, SEB’s website was unavailable or opened more slowly than usual. On the same day, some Luminor customers in the Baltic states experienced problems with Visa card payments. On 11 September, Swedbank’s website was temporarily unavailable and there may have been disruptions to card payments and ATM services. All incidents were caused by various technical faults. 

In September, phishing messages sent on behalf of Omniva and scam emails sent on behalf of Telia continued to spread rapidly. The messages claim e.g., that the expected shipment was in quarantine and that a customs duty had to be paid to receive it. The scam emails claim that a Telia bill has not been paid. The accompanying link directs the person to a phishing page to enter their bank card details and pay the corresponding fee.

Albin emphasised that fraudsters prey on people’s trust and haste. ‘If a letter or message asks you to pay an unexpected bill or enter your bank details, you should always pause for a moment and think critically. The safest thing to do is not to make transfers via links,’ she advised. 

In addition, the monthly summary provides an overview of RIA’s contribution to improve cyber security in Estonia and of other developments in the cyberworld. For example, you can read about the results of a study on the cyber security behaviour of Estonian residents and what influences it, as well as the largest denial-of-service attack in history, with a volume of 22.2 terabits per second.

Annika Maksimov

Communications Specialist

open graph imagesearch block image