Situation in cyberspace – July 2026

In July, we recorded 1,044 incidents with an impact, which is slightly below the average for the last six months.
  • In early July, we identified several Estonian websites that had been defaced. Disruptions occurred in the operation of several services. In July, phishing emails purporting to be from Swedbank circulated once again.
  • We published posts on the RIA blog about the continuation of the Windows 10 security update programme and phishing attempts on the Signal messaging app. We updated the Traffic Light Protocol on the RIA website.
  • At the start of the month, news emerged of a cyber attack on Latvia’s State Forests (LVM), the company that manages Latvian state forests. Accenture, a technology and IT services company, fell victim to a cyber incident and data theft. Russian intelligence used ordinary people’s surveillance cameras connected to the Internet to track the route of military aid destined for Ukraine.
Figure: Incidents reported in six months in 2025 and 2026. 1044 in July, 1232 in June, 1561 in May, 1138 in April, 886 in March, 804 in February 2026.

Incidents reported to CERT-EE that had an impact on the confidentiality, integrity, or availability of data or information systems.
 

Phishing sites recorded by CERT-EE in six months. 375 in July, 355 in June, 399 in May, 210 in April, 255 in March, 219 in February 2026.

Phishing sites account for the largest proportion of incidents recorded by CERT-EE.
 

Situation in Estonian cyberspace

Once again, disruptions occurred in the operation of several services.

There were two instances of disruptions to the operation of the website of the e-Business Register, ariregister.rik.ee. On 8 July, between 12.59 and 9.52 a.m., and from 6.57 p.m. on 8 July until 8.07 a.m. on 9 July, there were disruptions to the operation of the website of the e-Business Register. In both cases, the issue involved the website being scanned, and the problems were resolved after the settings were changed.

On 11 July, between 7.12 and 8.12 p.m., several websites experienced disruptions – lennuilm.ee, ilmateenistus.ee, airport.ee, kemit.ee, geoportaal.ee, kalaluba.ee, minu.kataster.ee, and riigimaaoksjon.ee. The disruption was caused by increased traffic on the websites due to poor weather and a storm warning.

At 11.53 a.m. on 15 July, disruptions to Telia’s services began in the small towns of Kambja, Ülenurme, and Roiu in Tartu County. Some home internet users were affected, and problems with mobile phone coverage in the area also occurred. The disruption was caused by a damaged data cable. Services were restored following the repair of the cable at 4.50 p.m.

From 6.08 p.m. on 20 July until 4.44 p.m. on 21 July, several disruptions occurred in the operation of websites managed by the Centre of Registers and Information Systems (RIK). The websites affected were konkurentsiamet.ee, oiguskantsler.ee, prokuratuur.ee, vanglateenistus.ee, and rik.ee. The disruption was caused by a technical fault that occurred during a software update.

In early July, we identified several Estonian websites that had been defaced. A defacement attack involves an attacker first gaining access to a website and then adding content of their own choosing to it. Often, for example, a message is added stating that the website has been hacked. Sites affected included the websites of a driving school, a company specialising in the hire of construction machinery, and an online shop. No malicious content was displayed on the websites, and it was most likely a case of cyber vandalism. We also sent a notification to the contact details for more than 90 websites on which a malicious file was displayed. All of the compromised websites used the Joomla content management system, and access was likely gained via security vulnerabilities in Joomla’s plugins. In the notification we sent, we recommended first removing the malicious content, then updating the software and changing the login details of the website administrators.

In the last week of July, we also identified 24 defaced websites where attackers had compromised the sites via unpatched vulnerabilities and added their own messages. We notified the administrators of the defaced websites and asked them to clean up the sites and update their software.

In July, phishing emails purporting to be from Swedbank circulated once again, claiming that it was time to update personal details and that to do so, recipients needed to log in via the link provided in the email and confirm the accuracy of their details with their signature. The letter emphasised urgency and recommended updating the details immediately, so that it would not have to be done on a day when the user wished to make a transfer. Letters were sent from suspicious domains, such as [email protected], which does not belong to Swedbank. We have been seeing letters like this for years, and they are sent out regularly posing as all the banks. Their content is usually the same, and the email includes a phishing link asking you to enter your bank login details. We wish to remind you once again that banks do not ask you to update your details via email, nor do they send you suspicious links for this purpose.

Activities of RIA to improve cybersecurity in Estonia

We published a post about the continuation of the Windows 10 security update programme. At the end of June, it was revealed that Windows 10 users will receive security updates through the ESU programme until 12 October 2027. Microsoft originally ended product support for the widely used Windows 10 on 14 October 2025, but first extended it by one year and has now extended it further until October 2027. Read more on our blog to find out what you should do if you are still a Windows 10 user.

We wrote in our blog about phishing attempts occurring in the Signal messaging app. Signal is a well-known app that is widely used in Estonia, and has been rated by several security audits as one of the most secure messaging apps available. In recent months, a series of phishing attacks targeting Signal have spread across several European countries; these are believed to be the work of the secret services of hostile states. In our article, we explained what these phishing attempts look like, what their purpose is, and how to use Signal safely.

We also wrote about the risks associated with the development of artificial intelligence and recommendations for organisations. The Five Eyes intelligence alliance has published a set of principles that organisations are advised to follow in light of the rapid development of artificial intelligence and the associated risks. The recommendations highlight, for example, the importance of management responsibilities and the actions they need to take, as well as various practical measures that should be implemented in the systems. Read more about it on our blog.

We published several posts on RIA’s Facebook page. For example, we warned people about fake QR codes stuck onto parking signs, which directed users to phishing websites where they were asked to enter their bank details. We also wrote about secure remote working, protecting your personal data online, and scams in online marketplaces. Read about these and many other topics on our Facebook page.

Moonshot AI, a Chinese artificial intelligence company, has released a new state-of-the-art model, Kimi K3, which the company itself describes as an open-weight model. In our blog post, we described the model, its price advantage, and how Kimi K3 compares to other leading models. Read more on our blog.

We have updated the article on the RIA website explaining the labelling of the Traffic Light Protocol (TLP). The article explains when TLP markings should be used, how to choose the correct marking, and how information marked with different classifications may be shared. Read more on the RIA website.

Mai Kraft took over as head of the Cyber Security Centre of RIA on 1 August. Mai Kraft is a recognised cyber security expert and leader with extensive experience in both the technology and information security sectors, and holds a Master’s degree in cyber defence from Tallinn University of Technology. For the past eight years, Kraft has worked as Head of Information Security at Elisa Estonia, where she has been responsible for the overall management of the company’s cyber security. More detailed information can be found on our website.

International situation

In June, a cyber attack targeted LVM, the company that manages Latvia’s state forests, during which hackers managed to breach the company’s network and steal data from it. According to the Latvian CERT, this appears to be a financially motivated attack, and an international ransomware group has claimed responsibility for it. The incident has sparked a debate within the Latvian government regarding the state of cyber security at state-owned enterprises – LVM had not fulfilled the obligations imposed on it by the Cyber Security Act, and an audit had failed to identify any shortcomings. There is also criticism of the lack of coordination regarding cyber incidents within the country. LVM is also one of the three companies involved in the development of the electronic electoral register.

The Citizen Lab, a research group based at the University of Toronto, published a report stating that, between 2022 and 2023, the Pegasus spyware had been installed on a device belonging to Stelios Kouloglou, then a Member of the European Parliament. Pegasus is spyware developed by the Israeli company NSO Group, which was originally intended for strictly controlled use by government agencies but quickly came to be used more widely and abused. It is worth noting that Stelios Kouloglou was, amongst other things, a member of the European Parliament’s working group tasked with investigating the misuse of Pegasus in Europe. The report does not state who may have been behind the infection and considers it likely that several individuals of interest in Europe were targeted at the same time.

According to the Dutch Military Intelligence Service (MIVD) and the General Intelligence and Security Service (AIVD), Russian intelligence used internet-connected CCTV cameras belonging to members of the public to monitor the route of military aid destined for Ukraine. The targets were primarily cameras and video intercom systems in residential buildings located along known logistics routes in NATO member states and Ukraine, via which military equipment was being transported to Ukraine. The main aim of the operation was to gather intelligence on the types and quantities of weapons being supplied to Ukraine by Western countries. According to the Dutch intelligence services, hackers are exploiting the fact that many Internet-connected cameras are inadequately protected: owners have not changed the factory default passwords, and the cameras’ software is often out of date and lacks security patches.

Laundry Bear, also known as Void Blizzard, a Russian state-sponsored cyber group, exploited a security vulnerability in the Zimbra email platform to steal emails from Western organisations. In the case of the attack known as ‘Beehive’ or ‘Ulej’, simply opening a malicious email in a vulnerable email service is enough. No other user action is required to trigger the malware. The campaign was first tested on targets in Ukraine and later targeted organisations in NATO member states. The attacks reportedly began in July 2025 and affected government agencies, as well as the defence, energy, education, technology, and media sectors. The successful attack enabled the hackers to gain persistent access to the victims’ emails and steal sensitive information. Zimbra fixed the vulnerability in November 2025, but attacks against unpatched servers are continuing.

OpenAI announced that, during an internal cyber capability assessment, their models compromised Hugging Face’s infrastructure. It was not until several days later that the incident was linked to an OpenAI agent. The evaluation utilised GPT-5.6 Sol and an even more capable, unpublished model, the safety constraints of which had been relaxed for testing purposes. According to OpenAI, the models identified several security vulnerabilities within their own research environment and on the Hugging Face platform, and chained these together to gain access to the solutions for the ExploitGym cyber capability test in the Hugging Face database. According to a statement from Hugging Face, the incident was managed from start to finish by an autonomous artificial intelligence agent system. OpenAI and Hugging Face are investigating the incident together, and, according to the artificial intelligence company, the isolation of evaluation environments, monitoring, and access controls will be strengthened following the incident.

Accenture, a technology and IT services company headquartered in Dublin and operating in more than 120 countries (including Estonia), has confirmed that it has fallen victim to a cyber incident and data theft. The confirmation came after some of the data stolen from the company was put up for sale on the dark web. In total, the criminals claim to be in possession of 35 gigabytes of the company’s technical and development environment-related data (cryptographic keys, Azure Storage access keys, source code, etc.). The company did not comment on the nature of the data that had been stolen, but stated that there was no threat to its services or operations.

Between 26 and 27 July, cyber attacks targeted around thirty municipal water systems in the US state of Minnesota, disrupting the water supply in at least one town for several hours. The attackers targeted operational technology (OT) systems rather than conventional IT networks. There is no information about the attacker, but the authorities are investigating a possible link to Iran. That same week, Michigan and five other states also reported attacks on their water supply systems. On 28 July, the US Cybersecurity and Infrastructure Security Agency (CISA), together with partner organisations, issued guidance to critical infrastructure operators, warning of increasing attack pressure from state-sponsored threat actors and providing recommendations for isolating operational technology devices from the public Internet and third-party services.

Last updated: 06.08.2026

search block image