Lyce · Hybrid Watch

hw_451abbbac769fef1

Finland’s Ministry of Defence website hit by DoS during a multi-day campaign.

The Finnish Ministry of Defence confirmed that its public website faced a sustained denial-of-service (DoS) attack, causing intermittent outages, user access failures and triggered protective shutdowns of some services. Finnish media and cybersecurity analysts noted that the disruption coincided with a broader wave of pro-Russian hacktivist activity targeting Finnish political and corporate websites, suggesting a coordinated campaign rather than a standalone incident. While the attack did not breach sensitive internal networks or exfiltrate data, the choice of target (the top defence-ministry portal) places it squarely on the edge of the defence-industrial base and the national command-and-control visibility chain. The geography is important: Helsinki hosts the key government cluster, national cyber-defence nodes and media presence – disrupting the gateway site imposes both operational and symbolic cost. The Finnish authorities responded by publicly raising the incident, accelerating mitigation & resilience measures for the DIB (defence-industrial base), and integrating the event into national hybrid-threat monitoring frameworks. Although no official public attribution to the Russian Federation was made in this instance, the context and timing point strongly to Russia-linked actors.

Occurrence
2025-09-24
Publication
2025-09-24T09:59:12Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
FI
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2025-09-24T09:59:12Z

    The Finnish Ministry of Defence confirmed that its public website faced a sustained denial-of-service (DoS) attack, causing intermittent outages, user access failures and triggered protective shutdowns of some services. Finnish media and cybersecurity analysts noted that the disruption coincided with a broader wave of pro-Russian hacktivist activity targeting Finnish political and corporate websites, suggesting a coordinated campaign rather than a standalone incident. While the attack did not breach sensitive internal networks or exfiltrate data, the choice of target (the top defence-ministry portal) places it squarely on the edge of the defence-industrial base and the national command-and-control visibility chain. The geography is important: Helsinki hosts the key government cluster, national cyber-defence nodes and media presence – disrupting the gateway site imposes both operational and symbolic cost. The Finnish authorities responded by publicly raising the incident, accelerating mitigation & resilience measures for the DIB (defence-industrial base), and integrating the event into national hybrid-threat monitoring frameworks. Although no official public attribution to the Russian Federation was made in this instance, the context and timing point strongly to Russia-linked actors.