Situation in cyberspace – May 2026

In May, we recorded 1,561 incidents with an impact, which is the highest indicator of the last six months.
  • In May, there were disruptions affecting open data websites, operations of the commercial register, the Health Insurance Fund services, as well as the border crossing system. The Estonian Artists Association fell victim to fraud and lost nearly 700,000 euros.
  • In May, it was possible to register for the international cybersecurity camp CyberWizards. We conducted cybersecurity training sessions, and the E-ITS engagement seminar and CyberMeetUp were also held. We published a new post about the AI model Claude Mythos Preview.
  • Hackers gained access to Lithuanian state databases. According to the annual report of the Polish Internal Security Agency, in 2025, attackers infiltrated the network of water treatment plants in five cities. Customer data from Zara and Škoda, as well as patient data from several university hospitals in Germany, was leaked. ESET published a report on a campaign by the Belarusian group Ghostwriter targeting Ukrainian government agencies.
Figure: Incidents reported in six months in 2024, 2025 and 2026. 1561 in May, 1138 in April, 886 in March, 804 in February, 768 in January, 998 in December 2025.

Incidents reported to CERT-EE that had an impact on the confidentiality, integrity, or availability of data or information systems.
 

Fraudulent sites recorded by CERT-EE in six months. 648 in May, 308 in April, 326 in March, 280 in February, 347 in January, 422 in December 2025.

Fradulent wesites account for the largest proportion of incidents recorded by CERT-EE.
 

Situation in Estonian cyberspace

On 1 May, between 12:10 a.m. and 1:52 a.m., the open data portal on the websites andmed.eesti.ee and avaandmed.eesti.ee was unavailable. The outage was caused by a forced restart during emergency maintenance in the Government Cloud, after which one necessary service component failed to resume operation.

On 12 May, between 2:45 p.m. and 3:40 p.m., there were disruptions in the Entry/Exit System (EES). EES is an EU-wide system for recording border crossings of third-country nationals. The disruptions hampered the work of the Police and Border Guard Board and slowed down the processing of border crossing for third-country nationals. The disruption was caused by an error in the connection between the Estonian and EU systems.

On 15 May, between 7 a.m. and 9:35 a.m., there were disruptions to the operations of the Partner Management Information System (PHIS) of the Health Insurance Fund. The system is used by the contractual partners of the Health Insurance Fund (family doctors, hospitals, and other healthcare providers) to manage contracts, monitor their fulfilment, and submit and verify medical invoices. The disruption was caused by a human error.

There were outages in the operations of the commercial register on five days. On 20 May, between 6:43 a.m. and 9:50 a.m., disruptions occurred in the commercial register. The same happened again on 21 May on three occasions (between 1:39 a.m. and 2:49 a.m., 6:37 a.m. and 10:18 a.m., and 1:34 p.m. and 2:22 p.m.). These were caused by a technical fault, but the exact circumstances are still unknown to CERT-EE. The disruptions recurred at the end of the month: On 29 May between 5:29 p.m. and 5:51 p.m., on 30 May between 7:38 a.m. and 8:02 a.m., and on 31 May between 7:54 p.m. and 8:44 p.m., there were outages in ariregister.rik.ee. According to initial reports, these were caused by unusually high traffic from web bots directed at the commercial register.

On 29 May, between 2:08 p.m. and 4:50 p.m., there were disruptions in the identity and procedural information system UUSIS of the Police and Border Guard Board, which is used for processing identity documents and citizenship applications. Due to the disruption, ID cards could not be issued at Police and Border Guard Board offices. The outage was caused by a fault in the system of a cooperation partner.

The Estonian Artists Association fell victim to fraud and lost nearly 700,000 euros. From 7 May and 15 May, fraudsters contacted the accountant of the Estonian Artists Association, impersonating a courier, a bank, and the police, resulting in multiple transfers being made from the SEB and Swedbank accounts of the association to foreign bank accounts. In the first call, it was stated that a registered letter needed to be delivered to the former president of the Artists Association. This was followed by calls purporting to be from the bank and the police. During the police call, it was claimed that the accountant would be involved in a covert operation aimed at apprehending the criminals. During the calls, the accountant was repeatedly asked to verify their identity and enter PIN codes. Over the course of the week, transfers totalling nearly 700,000 euros were made from the bank accounts of the Artists Association. The accountant was instructed to install software enabling remote access, which was used to carry out the transfers. In addition, the accountant was tricked into sending their personal bank cards to the criminals via a parcel locker. 

 

In light of this incident, we would like to remind organisations of the importance of reviewing their payment processes. For example, it is possible to change transfer limits at the bank and designate multiple approvers for payments. It is also important to raise awareness of cybersecurity and to train staff on these issues. We share information about common scams on the prevention portal IT-vaatlik and encourage everyone to explore the portal. We also recommend that all businesses and organisations sign up for RIA Cyber Test. The aim of the Cyber Test is to raise and maintain the awareness of employees of cybersecurity, and the training also highlights various types of scams. 

Activities of the Estonian Information System Authority

In May, it was possible to register for the international cybersecurity camp CyberWizards, organised by RIA, which is being held for the fourth time. This year, the event will take place from 3 to 8 August in Kehtna, and is aimed at girls aged 13 to 16 who would like to discover the fascinating world of hacking. During the camp, participants will learn essential cybersecurity skills through practical workshops, tackle engaging challenges, and take part in a Capture the Flag game at the end of the camp. It is an international camp, and the main language of communication is English.

If you are not already following our Facebook page, why not join in at https://www.facebook.com/riigiinfosysteemiamet. There we publish e.g. RIA job vacancies and information about upcoming events there. We also share alerts about ongoing scams and general advice on cybersecurity. This month, we posted on Facebook about what leaders can do to prevent cyber fraud, a phishing campaign circulating on Signal, and what spoofing means. 

On 21 May, another RIA CyberMeetUp took place. This time, the topics ranged from cybersecurity-focused defence industry business ideas and securing funding for innovative development projects to the challenges of detecting denial-of-service attacks and cyber education in space. There was also discussion about the next BSides event in Tallinn. Recordings of the event can be viewed on YouTube. The next RIA CyberMeetUp will take place on 10 June in Tartu.

We carried out cybersecurity training sessions and once again held an E-ITS engagement seminar. This time, the engagement seminar took place on 20 May and was primarily aimed at sharing best practices and experiences in the management and governance of information security. The seminar was intended for information security, IT, process and institution managers. We also visited various organisations to talk about the fundamentals of cybersecurity – for example, the Institute of the Estonian Language, the State Infocommunications Foundation, the courts, and the Estonian Chamber of Agriculture and Commerce. In addition, we spoke to 8th grade pupils at Peetri School about how to stay safe online. 

We published a post on the RIA blog highlighting new findings following the release of the Claude Mythos Preview. According to Anthropic, Claude Mythos is the most capable AI model ever created. The company states that Claude Mythos, in collaboration with around 50 partners, has identified over 10,000 major or critical security vulnerabilities. As powerful artificial intelligence models are capable of discovering new security vulnerabilities rapidly and on a massive scale, verifying and fixing these findings is now becoming an ever-greater challenge. Read more on our blog.

 

We released a new version 26.4 of the ID card software. This is a routine update designed to ensure the reliability, security, and a better user experience of the software. The new version of the ID software can be downloaded from the website id.ee. We would also like to remind that support for Windows 10 in the ID software will be discontinued from this autumn. Microsoft is also ending official support for Windows 10, which was extended in 2025 until this autumn. Read our blog to find out what you should do if you are still a Windows 10 user.

International situation

The Polish Internal Security Agency has published its annual report, which reveals that in 2025, hackers infiltrated the networks of water treatment plants in five cities. In some cases, they managed to gain access to industrial control systems, which could have led to disruptions in water supply. The report does not attribute the attacks to any specific state or group, but generally notes that Poland experienced increasing cyber pressure in 2024 and 2025, particularly from Russian intelligence services. The Polish cyber news portal CyberDefence24 has previously reported on a pro-Russian hacktivist group that claimed on its channel to be responsible for some of the attacks on water treatment facilities. The report also highlights a trend whereby Russian cyber threat actors are increasingly using structured networks linked to cybercriminals. 

Data belonging to Zara customers was leaked via a third party. Through a former service provider of the parent company of Zara, the fashion giant Inditex, data belonging to approximately 200,000 members of the international loyalty programme of Zara were leaked. The leaked information included email addresses and purchase histories; no other personal data was compromised. The ShinyHunters group is linked to the attack and has published some of the data on the dark web. 

Customer data was leaked from the sales portal of Škoda. Due to a vulnerability in the German customer-facing sales portal of the car manufacturer, criminals were able to access the portal and download the details of some customers, including their names, contact addresses, order numbers, account details, and password hashes. According to the company, they do not currently know how many customers were affected, but they advise all portal users to change their passwords as a precaution and to remain vigilant against phishing attempts. 

Cybersecurity companyESET has published a report on a campaign by the Belarusian group Ghostwriter targeting Ukrainian government agencies. The report describes a campaign that began in March and involves malware targeting Ukrainian government agencies. A PDF document is sent to the targets, mimicking customer communications from the Ukrainian telecommunications company Ukrtelekom regarding data protection issues. The document contains a link to download a reference to data protection regulations. If a user with a Ukrainian IP address opens the document, the PicassoLoader malware is downloaded. The malware automatically begins sending information discovered on the system to a server controlled by the attacker, after which the attacker assesses whether the target is of value. If so, further malware is delivered to the device. The campaign is targeting the armed forces, the defence sector, and government agencies. According to ESET, the group is active not only in Ukraine, but also in Poland and Lithuania.

Patient data from several German university hospitals was leaked following a cyberattack against the local service provider Unimed. Unimed is used by a number of hospitals and medical institutions in Germany as billing software for patients who pay for services themselves or have private health insurance. The attack took place in mid-April, and several university hospitals have since reported data breaches. For example, at Cologne University Hospital, nearly 30,000 patients have been affected, with their personal details, including addresses and information about treating physicians leaked. In 840 cases, the hackers also gained access to additional health-related information. Some other hospitals have now also confirmed that attackers gained access to patient data relating to diagnoses, treatment plans, and other matters. According to the service provider Unimed, attackers managed to obtain a limited amount of customer data before the attack was successfully thwarted.

The Lithuanian Prosecutor General’s Office launched criminal proceedings in connection with a cyber incident in which hackers gained access to more than 600,000 records in state databases managed by the Centre of Registers. The breach primarily affected the land registry and the business register. According to a statement from the Centre of Registers, the compromised data includes the names, dates of birth, and personal identification numbers of individuals, as well as related property information. The cyberattack was detected in April, but has only just been made public. According to the Lithuanian president, it is likely that ‘hostile countries’ are behind the attack. Adrijus Jusas, head of the Centre of Registers, resigned from his post following the incident and, in an interview with the local media, highlighted the problem of chronic underfunding of the IT infrastructure of the country – according to him, 60 million euros would be needed to bring the national registers up to the required level of cybersecurity. 

Last updated: 08.06.2026

search block image