HECAVEX Labs / Baltic Threat AtlasDownload JSON
Lab 01 · selected observations

Baltic Threat Atlas

A compact index of public cyber observations concerning Lithuania, Latvia and Estonia. It separates what an authority reported from what HECAVEX infers—and usually leaves the second part blank.

Not a prevalence map. Reporting practices, visibility and classification differ by country. Thirteen selected records cannot measure which country is “most attacked”, and an unnamed foreign presence is not an actor attribution.
reported

Broadcast content replaced in two incidents

Lithuania’s NCSC reported two cyber incidents affecting online music streams, where original playlists were allegedly replaced with recorded disinformation. The report does not attribute these two incidents to a named actor.

NKSC/RCDC Q3 report ↗
Type: incident
Sector: media
Attribution: none
reported

63% increase in recorded incidents

The 2024 CTAC report says Lithuania recorded a 63% increase, connected to improved identification and more active reporting. It also says 59% of recorded incidents involved social-engineering techniques.

NKSC/RCDC 2024 report ↗
Type: statistic
Technique: social engineering
Caveat: reporting effect
reported

2,888 incidents recorded, including 19 major incidents

Lithuania's NCSC recorded 19 major incidents, 380 minor incidents and 2,489 near misses. The lower total than 2024 does not by itself establish lower exposure because reporting and classification effects matter.

NKSC/RCDC 2025 report ↗
Type: annual statistic
Coverage: national
Caveat: classification effects
reported

Phishing remained dominant while fraud reports increased

The NCSC recorded 1,551 social-engineering incidents, 49% of the annual total, down from 2,288 in 2024. Illegal activity and fraud increased from 444 to 907 records.

NKSC/RCDC 2025 report ↗
Type: annual statistic
Technique: phishing
Trend: fraud increased
reported

Foreign intruder presence found during threat hunts

CERT.LV reported analysing more than 140,000 installations in 31 organisations. It identified foreign intruder presence with high confidence in eight organisations and said that access was removed. The public summary did not identify those actors.

CERT.LV Q2 review ↗
Type: threat hunt
Coverage: 31 organisations
Actor: undisclosed
reported

Continued politically motivated DDoS waves

CERT.LV described DDoS waves against public authorities and selected sectors by Russia and proxy hacktivists. The attacks were largely repelled and had no significant lasting societal impact in the reporting period.

CERT.LV Q2 review ↗
Type: campaign
Technique: DDoS
Impact: limited
reported

846 incidents and record device visibility

CERT.LV processed 846 incidents and identified 757,286 compromised or weakly configured devices. The authority cautioned that expanded SOC visibility also contributes to the observed increase.

CERT.LV Q1 review ↗
Type: quarterly statistic
Coverage: national
Caveat: improved visibility
reported

DNS firewall blocked more than 2.5 million malicious-site visits

CERT.LV reported a 139% quarter-over-quarter increase in blocks and said automated detection stopped 266 fraudulent campaigns before they became incidents.

CERT.LV Q1 review ↗
Type: defensive observation
Control: DNS firewall
Prevention: 266 campaigns
reported

84 DDoS attacks registered in one month

RIA said September 2023 set a record with 84 registered DDoS attacks. Public-sector, financial, transport and media services were among the wider politically motivated target set; most attacks had limited impact.

RIA annual summary ↗
Type: campaign
Technique: DDoS
Actor class: pro-Kremlin
government attribution

Unit 29155 operations jointly attributed

Estonia joined a multinational advisory attributing cyber operations against several countries to Russian GRU Unit 29155. This is a government attribution, not an independent HECAVEX attribution.

Joint advisory via CISA ↗
Type: attribution
Actor: Unit 29155
Confidence: official
government attribution

Estonia co-sealed Laundry Bear Zimbra advisory

Estonia's Foreign Intelligence Service joined a multinational advisory attributing a Zimbra email-collection campaign to Russian state-supported actors primarily tracked as Laundry Bear. The advisory does not report an Estonian victim.

Joint advisory ↗
Type: attribution
Actor: Laundry Bear
Caveat: no Estonian victim stated
reported

Record 756 DDoS attacks, fewer than 100 with impact

RIA recorded more than one-third growth in DDoS attempts while reporting that fewer than 100 affected target services. More attack volume did not translate directly into equivalent service impact.

RIA 2026 yearbook release ↗
Type: annual statistic
Technique: DDoS
Impact: under 100
reported

1,232 incidents with impact recorded in June

RIA reported high-impact DDoS activity, national digital-service disruptions and a customer-data breach in a southern Estonian booking system. These were separate events, not one campaign.

RIA June situation report ↗
Type: monthly statistic
Coverage: national
Attribution: no common actor
Method

How to read this dataset

One record, one claim

Each row captures a bounded public observation. Nearby events are not merged into a campaign without evidence.

Attribution stays attributed

Government or vendor attribution is labelled as such. An unnamed APT presence remains unnamed.

Known coverage gap

The MVP favours national authorities and joint advisories. It is not an exhaustive incident census.