Situation in Cyberspace – August 2026

In August, we recorded 899 incidents with an impact, which is slightly below the average for the last six months.
  • In August, there were further disruptions to the operation of several services: for example, the ABC gates at an airport were not working, there were interruptions in the GovSSO system, and there was a network outage at Pärnu Hospital. A school in Harju County was hit by a ransomware attack. A phishing campaign took place where the perpetrator purported to be from the Transport Administration. 
  • CyberWizards – an international cyber camp for girls – took place at the beginning of August. We published a post about device code phishing in the blog of the Information System Authority. We published an analysis of the cybersecurity of drones.
  • Latvia was once again hit by a cyberattack. New security breaches were discovered whilst auditing models of OpenAI and Anthropic. President Trump issued a memorandum that will allow cybersecurity firms to carry out offensive operations against international criminal networks going forward. The digital infrastructure of the Norwegian government was hit by a massive denial-of-service attack.
Figure: Incidents reported in six months in 2025 and 2026. 899 in August, 1044 in July, 1232 in June, 1561 in May, 1138 in April, 886 in March 2026.

Incidents reported to CERT-EE that had an impact on the confidentiality, integrity, or availability of data or information systems.
 

Phishing sites recorded by CERT-EE in six months. 596 in August, 375 in July, 355 in June, 399 in May, 210 in April, 255 in March 2026.

Phishing sites account for the largest proportion of incidents recorded by CERT-EE.
 

Situation in Estonian cyberspace

Unfortunately, August did not pass without disruptions to key services.

On 4 August, the ABC gates – i.e., the automated border control system – were not operational for outbound passengers at Tallinn Airport from 1:11 p.m. Service was restored in three of the four gates at 3:22 p.m., and in the fourth at 5:50 p.m. The gates resumed operation after a restart; the incident was caused by technical failures.

There were disruptions to the operation of Swedbank services on two separate days. On 7 August between 4:13 p.m. and 7:45 p.m., there were disruptions to payment transactions, and on 8 August between 11:41 a.m. and 1:23 p.m., there were disruptions to logging into the bank in addition to issues with payments (via the web browser and the app) and cash withdrawals. The incidents were not caused by a cyberattack, but by a technical failure. 

On 10 August between 11:35 a.m. and 12:26 p.m., there was a network disruption at Pärnu Hospital, and as a result, it was not possible to use IT services. The disruption, which caused problems with the day-to-day operations of the hospital, was caused by a configuration error. 

On 24 August between 10:30 a.m. and 4:50 p.m., there were disruptions to GovSSO, the central sign-in service of the government, managed by the Information System Authority. As a result, there were disruptions when accessing several national e-services, including eesti.ee and the health portal. It is not yet clear what caused the interruptions.

On 28 August, ransomware encrypted a file server, a print server, and a domain controller at a school in Harju County. By now, the main services have been restored. The exact circumstances of the incident are still being established. In past, the start of the school year has brought cyberattacks against schools and services in the education sector as well. For example, a few years ago, denial-of-service attacks were regularly carried out against eKool platform. It is thought that students were behind the attacks.

We released new ID software on August 18. After installing the latest version of DigiDoc4, some Windows users experienced issues when opening the application, verifying signatures, and signing documents. The problem could occur on Windows computers where the username or the name of the user profile folder contains letters with diacritical marks or special characters. We have identified the cause of the issue and released a new version of the ID software (version 26.8) on September 1, in which the bug has been fixed.

In August, a phishing campaign took place where the perpetrator purported to be from the Transport Administration. Users were sent a message stating that they had parked in a paid parking zone and had been fined for doing so. The message instructed the recipients to enter their card details and pay the alleged fine. However, the link led to a page set up by fraudsters to gain access to bank accounts and steal money from these. We would like to remind you that neither the police nor the Transport Administration send notices about fines by text messages. 

You can recognise a phishing message by the following characteristics:

  • it is often sent from a suspicious foreign number;
  • it contains an arbitrary web link that redirects users to a page where they are prompted to enter their details or to log in;
  • the message instructs the recipient to do something urgently;
  • the message contains dubious and incorrect use of language.

Activities of RIA to improve cybersecurity in Estonia

Due to the update of the EU’s eIDAS regulation on electronic identification and trust services, all Mobile-ID users must replace their SIM card before 19 May 2027 in order to continue using the service. For users, the principles of using Mobile-ID will remain unchanged. They will continue to be able to log in to e-services and provide digital signatures in the same way as before. Mobile-ID users will be notified of the need to replace their SIM card by their mobile network operator; the operator will also provide more detailed instructions. Read more about this on the website of the Information System Authority. Cybercriminals were quick to pick up on this information, and as early as the day after the official announcement was published, phishing emails regarding Mobile-ID updates began to circulate. The emails claimed that users should check their Mobile-ID and banking service settings, and directed them to a phishing page to enter their details.

From 3 until 8 August, an international cyber camp for girls, called CyberWizards, took place in Kehtna. This year marks the fourth time the camp took place, with 93 girls from nine different countries taking part this time. In addition to Latvia, Poland, the Czech Republic, Hungary, Ukraine, and Cyprus, for the first time there were also participants from the Bahamas and Fiji. The main objective of the camp is to introduce girls to cybersecurity and IT as potential options for further study and careers. Over the course of a week, participants tackled practical cybersecurity tasks, learned the basics of programming and digital security, took part in workshops, and developed their teamwork and problem-solving skills. Read more about the camp on our website.

Cybercriminals are constantly finding new ways to circumvent even the strongest authentication measures. One of the attack methods that has become increasingly common in recent times is device code phishing where the perpetrator does not steal user passwords or MFA codes, but exploits the legitimate authentication process of Microsoft. Consequently, even users and organisations that use phishing-resistant authentication methods may fall victim to such attacks. We wrote in our blog about how such attacks take place, how to recognise these, and how to minimise the risks.

As drones are becoming increasingly common tools and aids in the workplace and their use also entails cyber risks, we have compiled a cybersecurity analysis of drones, in collaboration with the International Centre for Defence and Security. A drone is like a flying computer – it has software, communication links, sensors, and data that can be attacked or misused, just like in other IT devices. In addition to vulnerabilities and data breaches, you should also take into account the risks specific to drones, such as the jamming or spoofing of communications and satellite navigation. Find out more on the website of the Information System Authority.

Once again, schools have the opportunity to order free educational materials to help children recognise and avoid the dangers of using the internet. The workbook is suitable for children aged 7–11 and it introduces topics related to the safety of the internet and smart devices in a manner that is clear and appealing for children, using crosswords, exercises, and games. For example, it covers topics such as protecting your accounts and smart devices, communicating with strangers online, and cyberbullying, as well as smartphone addiction and other issues. You can order study guides until 14 September; further details can be found on our website

International situation

The UK-based AI Security Institute (AISI) announced in a blog post that new security breaches were discovered whilst auditing models of OpenAI and Anthropic. AI agents carried out unsanctioned activities on their own initiative; for example, one agent created fake online identities in order to gain access to secure systems. The incidents occurred during safety tests organised by the AISI to assess the actual capabilities of the models. The most serious of the incidents involved an artificial intelligence agent that wrote malicious code and attempted to carry out a supply chain attack via GitHub. According to the AISI, no actual damage resulted from the incidents, but they highlight serious risks associated with the autonomy of artificial intelligence agents. Meta, the company that owns Facebook, also announced that a problem that arose in a test environment had enabled one of its artificial intelligence models to connect to the internet and hack into the system of another organisation. 

President Trump issued a memorandum, as a result of which US cybersecurity firms that have passed a preliminary vetting process will be able to carry out offensive operations against international criminal networks in the future. The memorandum establishes a programme under the National Coordination Centre, through which approved organisations will be granted the right to carry out cyberattack operations against the networks of cybercriminals, subject to certain conditions. Such operations require prior approval from the US Department of the Interior and the Department of Justice and must not endanger anyone’s life or amount to an armed attack or the use of force under international law. The aim of the initiative is to step up the fight against cybercrime, due to which Americans lost nearly 21 billion dollars last year. 

In August, it was discovered that the ransomware attack against Latvian State Forests had been made possible by a vulnerability that had gone unpatched for two years. On 11 June, the ByteToBreach group managed to breach GeoServer, an internal system used by Latvian State Forests (company responsible for managing the national forests of Latvia) for processing spatial data. The attackers used it to access other systems, and on 22 June, carried out a wide-scale attack where they encrypted the files of the company and stole its data. On 16 August, experts confirmed on Latvian state television that initial access had been gained through an unpatched vulnerability that the Latvian CERT had highlighted as long as two years ago. The Director of IT Infrastructure of Latvian State Forests admitted that the information had been overlooked because they had failed to interpret the CERT warning correctly.

The Road Traffic Safety Directorate (CSDD), operating in the administrative area of the Latvian Ministry of Transportation, reported a cyberattack, as a result of which criminals gained access to the data of 1.2 million people and 200,000 businesses, contained in payment receipts issued since 2008. The data includes names, personal identification codes, vehicle registration numbers, addresses, and payment details. The identity of the suspected perpetrator of the attack has not been disclosed, and as far as is currently known, the perpetrators have not published the stolen data. In the wake of the incident, the prime minister of Latvia forced both the supervisory board and the management board of the CSDD to resign, citing negligence in the implementation of cybersecurity requirements. The CSDD is a public limited company owned by the Latvian state, and one issue that has been highlighted is the fact that the CSDD did not use the security services provided by the Latvian CERT (instead, it used the cybersecurity service provided by the telecoms company TET that carried out monitoring, which failed to detect the attack).

Iranian hackers shut down a British power station for four days. The Telegraph (a British newspaper) reported on a previously undisclosed cyberattack against the critical infrastructure of the country, which government agencies believe was carried out by hackers working on behalf of the Iranian government. As a result of the attack, a British power station was out of service for four days, and according to the British authorities, this is the first successful cyberattack on the energy infrastructure of the UK. According to the newspaper, it was a small-scale power station and the incident had no impact on the power supply of the country. The attack took place in July and coincided with a period during which hackers with links to Iran attacked several water infrastructure facilities in the US. The timing gave rise to speculation that Iranian hackers were carrying out a wider, coordinated campaign of attacks against the critical infrastructure of Western countries.

The digital infrastructure of the Norwegian government was hit by a massive denial-of-service attack that disrupted many public services. The attack targeted the Norwegian digital agency Digdir and its service provider Vivicta, and affected e.g., digital signatures, data exchange between authorities, and logins to public services. This is the third time this summer that Norwegian public services have been disrupted by denial-of-service attacks. The pro-Russian hacktivist group Server Killers has claimed responsibility for the attack and declared ‘cyberwar’ on Norway in retaliation for the new defence and security cooperation agreement signed by Norway and Ukraine on 23 August, and for financial support to develop Ukrainian defence capabilities. 

The state government of Berlin reported that it had been hit by a cyberattack and received a ransom demand. The Rhysida ransomware group confirmed the attack on its dark web site. The group also claims to be in possession of 5.79 terabytes of stolen data, including the personal details of more than 12,000 people, and is threatening to put it up for auction. The Mayor of Berlin has confirmed that they will absolutely not give in to the demands of the blackmailers. The timing of the attack is somewhat politically sensitive, as the State of Berlin is due to hold its parliamentary elections in a few weeks. Rhysida is a criminal group that emerged in 2023 and has previously carried out attacks on public sector targets; its other victims include the British Library and the Chilean Armed Forces, for example.

Last updated: 03.09.2026

search block image