A compact index of public cyber observations concerning Lithuania, Latvia and Estonia. It separates what an authority reported from what HECAVEX infers—and usually leaves the second part blank.
Not a prevalence map. Reporting practices, visibility and classification differ by country. Thirteen selected records cannot measure which country is “most attacked”, and an unnamed foreign presence is not an actor attribution.
reported
Broadcast content replaced in two incidents
Lithuania’s NCSC reported two cyber incidents affecting online music streams, where original playlists were allegedly replaced with recorded disinformation. The report does not attribute these two incidents to a named actor.
The 2024 CTAC report says Lithuania recorded a 63% increase, connected to improved identification and more active reporting. It also says 59% of recorded incidents involved social-engineering techniques.
Type: statistic Technique: social engineering Caveat: reporting effect
reported
2,888 incidents recorded, including 19 major incidents
Lithuania's NCSC recorded 19 major incidents, 380 minor incidents and 2,489 near misses. The lower total than 2024 does not by itself establish lower exposure because reporting and classification effects matter.
Type: annual statistic Coverage: national Caveat: classification effects
reported
Phishing remained dominant while fraud reports increased
The NCSC recorded 1,551 social-engineering incidents, 49% of the annual total, down from 2,288 in 2024. Illegal activity and fraud increased from 444 to 907 records.
Foreign intruder presence found during threat hunts
CERT.LV reported analysing more than 140,000 installations in 31 organisations. It identified foreign intruder presence with high confidence in eight organisations and said that access was removed. The public summary did not identify those actors.
CERT.LV described DDoS waves against public authorities and selected sectors by Russia and proxy hacktivists. The attacks were largely repelled and had no significant lasting societal impact in the reporting period.
CERT.LV processed 846 incidents and identified 757,286 compromised or weakly configured devices. The authority cautioned that expanded SOC visibility also contributes to the observed increase.
Type: quarterly statistic Coverage: national Caveat: improved visibility
reported
DNS firewall blocked more than 2.5 million malicious-site visits
CERT.LV reported a 139% quarter-over-quarter increase in blocks and said automated detection stopped 266 fraudulent campaigns before they became incidents.
Type: defensive observation Control: DNS firewall Prevention: 266 campaigns
reported
84 DDoS attacks registered in one month
RIA said September 2023 set a record with 84 registered DDoS attacks. Public-sector, financial, transport and media services were among the wider politically motivated target set; most attacks had limited impact.
Type: campaign Technique: DDoS Actor class: pro-Kremlin
government attribution
Unit 29155 operations jointly attributed
Estonia joined a multinational advisory attributing cyber operations against several countries to Russian GRU Unit 29155. This is a government attribution, not an independent HECAVEX attribution.
Type: attribution Actor: Unit 29155 Confidence: official
government attribution
Estonia co-sealed Laundry Bear Zimbra advisory
Estonia's Foreign Intelligence Service joined a multinational advisory attributing a Zimbra email-collection campaign to Russian state-supported actors primarily tracked as Laundry Bear. The advisory does not report an Estonian victim.
Type: attribution Actor: Laundry Bear Caveat: no Estonian victim stated
reported
Record 756 DDoS attacks, fewer than 100 with impact
RIA recorded more than one-third growth in DDoS attempts while reporting that fewer than 100 affected target services. More attack volume did not translate directly into equivalent service impact.
Type: annual statistic Technique: DDoS Impact: under 100
reported
1,232 incidents with impact recorded in June
RIA reported high-impact DDoS activity, national digital-service disruptions and a customer-data breach in a southern Estonian booking system. These were separate events, not one campaign.