This mistake was a human error. The RIA portal team, in cooperation with CERT-EE, upgraded the settings of the portal for protection against denial-of-service attacks to fix load failures. As a result of two incorrect settings, a situation arose for up to five minutes where a user logged into eesti.ee could, in some cases, see the previous user’s name, their contact details (email address and phone number) and information about related companies. The portal did not show any other data.
The error was identified by RIA staff and corrected immediately. After the changes made, eesti.ee should work faster and more reliably for users in the future.
We will also inform the Data Protection Inspectorate of the incident.
We apologise to users.