Situation in cyberspace – June 2026

In June, we recorded 1,232 incidents with an impact, which is a slightly higher indicator than the average of the last six months.
  • In June, disruptions affected the operation of the Automated Biometric Identification System (ABIS), the Government Cloud, and the X-tee timestamping service provided by RIA. There was a number of high-impact denial-of-service attacks. A customer data breach occurred in the booking system of a company operating in southern Estonia.
  • We organised an international training exercise in which electricity and cybersecurity experts practised protecting critical infrastructure from cyber threats. The final CyberMeetUp of the season took place. The Latvian Minister of Defence recognised Gert Auväärt, Head of the National Cyber Security Centre of RIA, for his outstanding contribution to strengthening cyber cooperation between Estonia and Latvia.
  • Chinese military intelligence is using Western recruitment platforms to gain access to sensitive information. The US healthcare company DentaQuest and the University of Nottingham were hit by cyber attacks. French authorities are investigating the compromising of the state messaging application Tchap. A cyber incident affected an agency under the Ministry of Health of Lithuania.
Figure: Incidents reported in six months in 2025 and 2026. 1232 in June, 1561 in May, 1138 in April, 886 in March, 804 in February, 768 in January 2026.

Incidents reported to CERT-EE that had an impact on the confidentiality, integrity, or availability of data or information systems.
 

Fraudulent sites recorded by CERT-EE in six months. 456 in June, 648 in May, 308 in April, 326 in March, 280 in February, 347 in January 2026.

Fradulent wesites account for the largest proportion of incidents recorded by CERT-EE.
 

Situation in Estonian cyberspace

On 1 June, between 8.20 and 9.46 a.m., the Automated Biometric Identification System (ABIS) experienced technical issues. As all services retrieving biometric data from identity documents via X-tee were affected, applications for and issuance of identity documents at the service offices of the Estonian Police and Border Guard Board were unavailable. Visa processing was also disrupted during the outage. The disruption was caused by issues that emerged following a system update.

On 15 June, between 6.10 and 7.42 p.m., the Government Cloud experienced technical issues, making the websites of the Estonian Tax and Customs Board, the Health Insurance Fund, the Building Register, the information system of the Environmental Investment Centre, and the Port Register unavailable. The outage was caused by human error.

From 5.15 p.m. on 16 June until 12.38 p.m. on 17 June, Telia experienced service disruptions. Following a power outage, faults occurred at one location, affecting some voice calls and Mobile-ID requests. The Emergency Response Centre reported that, due to the Telia outage, callers dialling the emergency number 112 from the Telia network could not hear the ringing tone. However, their calls were successfully connected.

On 22 June, between 1.00 and 9.33 a.m., an interruption occurred in the the X-tee timestamping service of RIA (tsa.x-tee.ee). The incident affected the security servers of those X-tee members that had been configured to use only the timestamping service of RIA. The incident was caused by a third party automatically issuing new TLS certificates for the X-tee endpoint that relied on a certificate chain which had not yet been widely distributed. Consequently, most servers did not yet have the new root certificate installed and therefore did not trust tsa.x-tee.ee. To the knowledge of CERT-EE, the incident affected the Police and Border Guard Board, Ida-Viru Central Hospital, one software company, and two banks. The last affected customer had its services fully restored at 1.16 p.m. Following the incident, we also published a notice recommending that X-tee members configure their security servers to use an alternative timestamping service in addition to the timestamping service of RIA.

There was a number of high-impact denial-of-service attacks.

On 2 June, between 9.28 and 10.55 a.m., a denial-of-service attack targeted the name servers of CERT-EE. As a result, CERT-EE services experienced disruptions, and the name server service in the state network responded more slowly than usual or intermittently. Normal service was restored after mitigation measures were implemented.

On 9 June, between 12.48 and 4.13 a.m., a denial-of-service attack targeted politsei.ee. As a result, the response times of the website may have been longer than usual. The disruptions ended after mitigation measures were adjusted.

A customer data breach occurred in the booking system of a company operating in southern Estonia. The leaked data included the first and last names, identity document numbers, dates of birth, nationalities, addresses, email addresses, telephone numbers, and booking details of customers. The attackers compromised the user account of an employee in the booking system. Multi-factor authentication had not been enabled for the account of the employee, which was protected by a weak password. We recommend consulting RIA’s quick cybersecurity guide for businesses, which includes guidance on establishing a secure password policy and implementing multi-factor authentication.

Activities of the Estonian Information System Authority

We organised an international training exercise in which electricity and cybersecurity experts practised protecting critical infrastructure from cyber threats. The experience of the war in Ukraine has shown that physical attacks against critical infrastructure are often accompanied by cyber attacks, which is why the strengthening of the electricity sector has become increasingly important. Experts from the Estonian electricity sector – Elektrilevi, Elering, Viru Elektrivõrgud, and Enefit Power – participated in the training. Read more about the training on our website.

On 10 June, RIA hosted another CyberMeetUp, and for the first time in its history, the event took place in Tartu. The programme covered the roadmap of Estonia for the transition to post-quantum cryptography, the collaboration between cybersecurity and artificial intelligence, the Core Four methodology in digital forensics, and the importance of investing in cybersecurity. The Cyber Innovation Conference, organised by the University of Tartu Institute of Computer Science, was held on the same day, allowing participants to attend both events. Recordings of the event can be viewed on YouTube. This was the final RIA CyberMeetUp of the season. We look forward to seeing everyone again on 8 October in Tallinn.

On our Facebook page, we warned the public about scam calls in which fraudsters impersonate hospital staff. Over the past few months, we have received reports of scam calls in which callers claim to be hospital employees and inform victims that an appointment with a doctor has been cancelled or rescheduled, invite them to a follow-up consultation or additional procedures, or request payment for an upcoming operation or other medical service. Although the pretexts varied, they all had the same objective: to obtain the recipient’s personal or banking information or to persuade them to log in to an online service. We remind everyone that no public authority or trusted organisation – including banks, hospitals, or the police – will ever ask for PINs or instruct people to log in to an online service over the phone. If you receive such a call, you should end it immediately. If you are unsure whether the call was genuine, contact the organisation directly using its official telephone number.

The Latvian Minister of Defence recognised Gert Auväärt, Head of the National Cyber Security Centre of RIA, for his outstanding contribution to strengthening cyber cooperation between Estonia and Latvia. The recognition reflects the long-standing and trusted cooperation between the two neighbouring countries in the field of cybersecurity. Estonian and Latvian experts work together on a daily basis to strengthen the resilience of our digital societies and ensure secure digital services for people and organisations on both sides of the border.

Lauri Tankler, Head of the R&D Coordination Department of RIA, published an opinion piece on the Tehnopol blog discussing how cybersecurity needs to evolve. According to Tankler, cybersecurity must become simpler, more affordable, and more accessible – without compromising on quality. Effective solutions must also be suitable for organisations that do not have large IT departments, dedicated cybersecurity managers, or substantial budgets. Start-ups and emerging technologies have a key role to play in developing such solutions. One opportunity for developing a new cybersecurity product or service was to apply for the Cyber Accelerator programme, for which applications were open until 21 June.

International situation

The countries of the Five Eyes intelligence alliance warn that Chinese military intelligence is using Western recruitment platforms to gain access to sensitive information. Chinese intelligence agents pose as recruiters or consultants and contact government officials and individuals linked to the defence sector in countries of interest, for example via LinkedIn. They target both individuals who have access to sensitive information through their work, as well as journalists and members of think tanks. The MI5 domestic security service of the United Kingdom has also issued a separate guide on how to recognise suspicious approaches on recruitment platforms. It is further emphasised that disclosing sensitive information during recruitment interviews may expose candidates to criminal proceedings.

The US company DentaQuest, which primarily facilitates dental and vision benefits, fell victim to a cyber attack by the extortion group ShinyHunters in May. As the company did not comply with the extortion demand, ShinyHunters has now published part of the stolen data on a dark web forum. According to initial assessments, the breach may affect up to 2.6 million individuals, whose email addresses, names, phone numbers, and in some cases, medical data were accessed by the attackers. DentaQuest has an estimated annual revenue of approximately 100 million dollars, making it another high-profile organisation compromised by ShinyHunters.

The University of Nottingham in England announced on 9 June that one of its information systems had been subject to a major cyber attack, during which criminals stole data belonging to current and former students. The compromised data includes contact details, academic records, and payment information. The attack is believed to be linked to the group ShinyHunters, which focuses on targeting high-profile organisations and conducting extortion using stolen data. The incident occurred via third-party managed software, Campus Solutions, which the university uses for student administration.

French authorities are investigating the compromising of the state messaging application Tchap. Tchap is a secure national messaging application for French public sector employees, developed by the national cybersecurity agency ANSSI and the digital agency DINUM. It was designed to enable communication within the French state sector without relying on messaging applications provided by foreign technology companies. An incident is currently under investigation in which attackers succeeded in taking over a user account in the application, thereby gaining access to public chat rooms where conversations are not encrypted. Private conversations are, according to current information, still protected. Although the full scope of the impact is still being assessed, French authorities have stated that the incident affects more than 73,000 government employee accounts on Tchap, representing approximately 9% of registered users.

A cyber incident affected an agency under the Ministry of Health of Lithuania. During the incident, approximately 62,000 records containing personal data of physicians were leaked, along with information on the qualifications of 156 healthcare institution administrators and technical system metadata. According to the head of Lithuanian National Cyber Security Centre (NKSC), current evidence does not indicate a coordinated attack. Instead, the incidents appear to be separate events in which system vulnerabilities were exploited. The case followed a data breach that occurred a few weeks earlier, during which the real estate and registry data of more than 600,000 individuals were stolen from Lithuania’s central registry. Authorities had suspected foreign state involvement in the earlier incident.

The civil defence agency of Brazil was forced to temporarily shut down the emergency alert system of the country after it began sending out false alarms in various regions of Brazil on Saturday morning. The false alerts were sent at the highest severity level, meaning mobile phones triggered loud alarms even when set to silent mode. As a result, Brazilian authorities blocked access to the application of the alert system, and police are investigating a suspected cyber attack against it. The system is intended to be restored as quickly as possible, as it is used to inform the public about storms, floods, and landslides.

Since the US-Israeli military strikes on Iran, Iranian cyber attacks against Israel have increased significantly. Yossi Karadi, head of the National Cyber Directorate of Israel, told the German newspaper Die Welt that while around 1,600 Iran-linked hostile cyber incidents were recorded in June last year, the number rose to approximately 4,800 in June this year. The attacks target Israeli critical infrastructure, government institutions, as well as accounting and legal service providers. According to Karadi, some Iranian threat groups are relatively technically capable and have succeeded in destroying data and systems in organisations with weaker defences. So far, Israel has successfully repelled attacks against critical infrastructure.

Last updated: 06.07.2026

search block image