Skip to content

Estonian E-Services Target Catalog: Comprehensive Security Research Report

Generated: 2026-04-07 | Confidence: High-Medium

Executive Summary

Estonia operates one of the world's most advanced digital societies, with virtually all government services available online. This comprehensive catalog identifies valuable targets for threat analysis, organized by sector. Key findings:

  • Smart-ID phishing is the dominant attack vector against Estonian financial services, with €42+ million in fraud losses reported
  • Government e-services (eesti.ee) are transitioning to Smart-ID+ (as of Feb 26, 2026) but remain high-value targets
  • Healthcare sector experienced massive breach affecting ~50% of population (Allium UPI OÜ, 2024)
  • Critical infrastructure (Elering power grid) facing both physical and cyber threats
  • Estonian banks (Swedbank, SEB, LHV) under unprecedented fraud pressure withSmart-ID vulnerabilities actively exploited

1. FINANCIAL SERVICES

1.1 Major Banks

ProviderAuthentication MethodsData SensitivityNotable Incidents
Swedbank EstoniaSmart-ID, Mobile-ID, ID-card, PasswordCRITICAL€27M+ fraud losses (2025); phishing attacks targeting Smart-ID users
SEB EstoniaSmart-ID, Mobile-ID, ID-cardCRITICALFIU damages claim filed; ongoing fraud litigation
LHV BankSmart-ID, Mobile-ID, ID-cardCRITICALSmart-ID security features added (2019); pension fund management
Coop PankSmart-ID, Mobile-IDHIGHPart of cooperative banking network

Confidence: HIGH

Security Incidents:

  • Swedbank reported "unprecedented fraud pressure" (Dec 2025) with phone scams impersonating trusted institutions
  • Cybersecurity researcher Arnis Paršovs (University of Tartu) documented banks' failure to implement Smart-ID phishing protections
  • Banks slow to adopt Smart-ID+ upgrade (announced Jan 2026 rollout)
  • €42 million total fraud losses reported against Estonian banks

Attack Vectors:

  • Smart-ID phishing via fraudulent calls requesting PIN codes
  • Social engineering exploiting trust in banks and government institutions
  • The RIA Cyber Security Yearbook 2025 documented doubled incident counts

1.2 Pension Funds

ProviderAuthenticationData Sensitivity
Pensionikeskus (II & III pillar registry)Smart-ID, ID-cardCRITICAL (Financial + Identity)
Swedbank PensionSmart-IDHIGH
ERGO PensionSmart-IDHIGH
TulevaSmart-IDHIGH

Confidence: HIGH

Incidents:

  • Pensionikeskus issued fraud alerts (Sep 2025)
  • Temporary access closures documented (June 2024)
  • Government legislation drafted to restrict pension fund tampering by politicians

1.3 Insurance Companies

ProviderAuthenticationData Sensitivity
ERGO Insurance SESmart-ID, PasswordHIGH (Health, Property, Life)
If KindlustusSmart-ID, PasswordHIGH
Salva KindlustusPasswordMEDIUM
Elama KindlustusPasswordMEDIUM

Confidence: MEDIUM-HIGH


2. GOVERNMENT E-SERVICES

2.1 State Portal & Authentication

ServiceURLAuthenticationData Sensitivity
eesti.eeeesti.eeSmart-ID+, Mobile-ID, ID-card, TARACRITICAL
GovSSOe-gov.github.io/GOVSSOID-card, Mobile-ID, Smart-ID, EU eIDCRITICAL
TARA (State Auth Service)ria.eeVarious OAuth/OIDCHIGH

Confidence: HIGH

Key Developments:

  • Smart-ID+ became mandatory for state e-services (Feb 26, 2026)
  • Eesti.ee mobile app launched (July 2025) for smartphone-based digital ID
  • RIA Cyber Security Yearbook 2025 documented record cyber incidents

Incidents:

  • 286,000 ID photos stolen from government database via vulnerability (2021)
  • Ministry of Economic Affairs failed to patch vulnerabilities after cyberattack (2024)
  • Russian GRU linked to theft of thousands of confidential documents from ministries (2024)
  • DDoS attacks on state institutions in March 2024 (largest to date)

2.2 Tax & Customs

ServiceURLAuthenticationData Sensitivity
e-MTAemta.eeSmart-ID+, Mobile-ID, ID-card, PasswordCRITICAL (Financial + Identity)

Confidence: HIGH

Notes:

  • Estonian Tax Board transitioning to Smart-ID+ (Feb 2026)
  • Requires valid PIN codes for authentication
  • Online services security guidance published

2.3 Police & Border Guard

ServiceURLAuthenticationData Sensitivity
Politsei.ee Portalpolitsei.eeSmart-ID, Mobile-ID, ID-cardHIGH
E-residencylearn.e-resident.gov.eeDigital ID cardMEDIUM

Confidence: HIGH

Incidents:

  • Police arrested Tallinn resident for stealing 286,000 ID scans from government database (2021)
  • Estonian Citizenship Database breach affected Have I Been Pwned (2018)

3. TELECOM & ISP

3.1 Major Providers

ProviderServicesAuthenticationData Sensitivity
Telia EstoniaMobile, Internet, TV, ITAccount passwordHIGH (Communications)
Elisa EstoniaMobile, Internet, TV, CableAccount passwordHIGH
Zone.eeDomain, Hosting, EmailAccount credentialsMEDIUM-HIGH
Starman (acquired by Elisa 2016)Cable TV, InternetAccount credentialsMEDIUM

Confidence: HIGH

Security Notes:

  • Telia launched "Turvavork Kodu" home网络安全服务 (Nov 2025)
  • Elisa blocked double the cyber threats in 2025 vs 2024
  • Zone.ee offers SSL certificates and security guidance to customers
  • Starman: acquired by Elisa; no major security incidents on record

Incidents:

  • Elisa Estonia detected 331 cyber incidents per customer monthly in 2025 (20M+ threats in Dec 2025)
  • Increase from 177 per customer in 2024, 99 in 2023

3.2 Email & Domain Providers

ProviderServicesData Sensitivity
Zone.eeEmail, Domain registration, Web hostingMEDIUM (Communications + Business)

Confidence: MEDIUM-HIGH

Security: Provides SSL/TLS certificates, security best practices documentation


4. CLOUD/HOSTING PROVIDERS

ProviderTypeData SensitivityNotes
PilvioLocal cloud platformHIGHEstonian data residency emphasis
RIIGIPILVGovernment cloudCRITICALState systems
WaveComVMware Cloud, DRaaSHIGHEnterprise services
Infonet DCColocation, Tier 3HIGHCarrier neutral
EstNOCDedicated servers, hostingMEDIUM-HIGHGovernment clients
LeviraData center (TV Tower)MEDIUM-HIGHState-affiliated
Tet CloudCloud servicesMEDIUMFormerly Lattelecom

Confidence: MEDIUM-HIGH

Security: Estonian providers emphasize GDPR compliance and local data sovereignty


5. UTILITIES & ENERGY

5.1 Electricity Grid

ProviderRoleData SensitivityIncidents
EleringGrid operator (transmission)CRITICAL (Infrastructure)Undersea cable sabotage; drone threats

Confidence: HIGH

Security Incidents:

  • EstLink 2 cable damage suspected as sabotage (Dec 2024)
  • €200M+ infrastructure protection investment planned
  • €700M investment plan through 2028
  • Drone attacks on power infrastructure (2026)
  • Concrete shielding being installed at substations

5.2 Energy Companies

ProviderServicesData Sensitivity
Eesti Energia / EnefitElectricity, heatingHIGH
Väike功夫District heatingMEDIUM

Confidence: MEDIUM


6. HEALTHCARE

6.1 Major Providers

ProviderTypeAuthenticationData Sensitivity
North Estonia Medical Center (PERH)HospitalInternal systemsCRITICAL (Health records)
West Tallinn Central Hospital (LTKH)HospitalInternal systemsCRITICAL
Tartu University HospitalHospitalInternal systemsCRITICAL
Health Insurance Fund (Tervisekassa)Public health portalSmart-ID, PasswordCRITICAL
Allium UPI OÜHealthcare supplierUnknownCRITICAL (breached)

Confidence: HIGH

Security Incidents:

  • Allium UPI OÜ breach (2024): ~700,000 customer data stolen (half of Estonian population); €3M fine
  • West Tallinn Central Hospital (2026): Patient sent home with USB containing other patients' data
  • Asper Biogene (2023): 10,000 people's genetic/health data stolen
  • Software glitch: Faulty data in hundreds of patient records (2023, 5-year span)
  • Family medicine centers: 25% experiencing cyberattacks; struggling to meet cybersecurity standards
  • Healthcare incidents: ~7,000 incidents recorded in first year of tracking (2024)

6.2 Pharmacies

ProviderTypeIncidents
ApothekaPharmacy chain700,000 customer data breach; €3M fine (2025)

7. RETAIL & E-COMMERCE

ProviderTypeAuthenticationData Sensitivity
Kaup24.eeE-commerceAccount passwordMEDIUM (PII, Financial)
Barbora.eeOnline groceryAccount passwordMEDIUM
Osta.eeMarketplaceAccount passwordMEDIUM
HansapostE-commerceAccount passwordMEDIUM
Zalando EstoniaFashion e-commerceAccount passwordLOW-MEDIUM
220.lvE-commerce (Latvia)Account passwordMEDIUM

Confidence: MEDIUM

Notes:

  • 70% of Estonians shop online (highest in Baltics)
  • 14,500+ e-commerce stores analyzed

8. CRITICAL INFRASTRUCTURE

8.1 Government Systems

SystemDescriptionRisk Level
X-RoadData exchange layer connecting all гос servicesCRITICAL
KMAPopulation registerCRITICAL
SDKPopulation documentsCRITICAL
MISPMissing Persons systemHIGH

Confidence: HIGH

8.2 Recent Major Incidents

DateIncidentImpact
2024GRU attacks on ministriesThousands of documents stolen
2024RIA photo database breach286,000 ID photos
2024Apotheka/Allium breach700,000 records
2024DDoS on state institutionsLargest recorded
2024Ministry unpatched after attackContinued vulnerabilities

AUTHENTICATION METHODS SUMMARY

MethodProviderSecurity LevelVulnerabilities
Smart-ID+SK ID SolutionsHIGH (upgraded Feb 2026)Phishing if PIN disclosed
Mobile-IDTelia, ElisaHIGHSIM cloning risk
ID-cardState-issuedHIGHBrowser compatibility issues
PasswordVariousMEDIUM-LOWCredential stuffing, phishing
TARARIAHIGHOAuth/OIDC implementation

Smart-ID phishing concerns:

  • Six years of documented Smart-ID phishing scams
  • Banks slow to implement protections
  • New Smart-ID+ roll-out aims to address this (Feb 2026)

SOURCES

  1. Arnis Paršovs: Banks fail to implement measures against Smart-ID phishing (ERR, Jan 2026)
  2. Cyber Security in Estonia 2025 - RIA PDF
  3. Estonian banks face scrutiny as fraud losses hit €42 million (shortl.ee, Jan 2026)
  4. Half of Estonian Population affected in Data Breach at Healthcare Supplier Allium UPI OÜ (ICSSTRIVE, Dec 2024)
  5. Company fined €3 million over Apotheka loyalty program data breach (ERR, Sep 2025)
  6. Russia's GRU stole thousands of confidential documents from Estonia's ministries (ERR, Sep 2024)
  7. Estonia's state institutions hit by largest cyberattack to date (Postimees, Mar 2024)
  8. Smart-ID+ introduced on 26 February for more secure login to state e-services (ID.ee, Mar 2026)
  9. Elering plans to invest €200 million to protect infrastructure from drones (ERR, Jan 2025)
  10. Estonian hospital sends patient home with other peoples' health data (ERR, Mar 2026)
  11. Applied Cyber Security Group - List of Estonian e-services using eID (UT.ee)
  12. Elisa Estonia sees number of cyber threats blocked double in 2025 (Telecompaper, Jan 2026)
  13. Swedbank: Estonia seeing unprecedented fraud pressure (ERR, Dec 2025)

CONFIDENCE RATINGS METHODOLOGY

  • HIGH: Multiple independent sources, official statements, recent data (2024-2026)
  • MEDIUM: Limited sources or some dated information
  • LOW: Single source, unverified claims, or significantly dated information

Report compiled from open-source intelligence. Data accuracy dependent on source reliability.

Research content licensed under CC-BY-4.0. Code licensed under MIT.