CSIDB logo
Incident

Finland Election Result Service

Incident posture

Attack window
Apr 2019
Location
Finland
Status
Historical
CIA posture
Available to members
Updated
2025-11-04 00:00

Linked entities

Victim
Finland Election Result Service
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A denial-of-service attack targeted Finland's official election results portal, causing intermittent disruptions to the service during early hours. The attack did not impact vote casting or counting, as the affected platform was separate from core electoral systems and primarily used by smaller news outlets for results dissemination. Authorities launched an investigation into the incident as aggravated interference with communications, though no suspects were identified. Officials noted that such cyberattacks against high-profile public services are common and emphasized preparedness for such threats during elections. The incident highlighted broader concerns about safeguarding electoral infrastructure against cybersecurity risks.

Motives

Detailed motive labels are available to members.

4 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On the weekend of April 6, 2019, Finland’s official election results portal (vaalit.fi) experienced intermittent disruptions due to a denial-of-service (DoS) attack. The National Bureau of Investigation (KRP) confirmed the attack occurred in the early hours of that weekend, characterizing it as short in duration and low in volume. The targeted service provided real-time election results to the public but operated independently from vote casting and counting systems, ensuring no impact on electoral integrity. Arto Jääskeläinen, head of electoral administration at the Ministry of Justice, clarified that vaalit.fi primarily served smaller news outlets, while major media organizations like YLE and Helsingin Sanomat received results through a separate secure connection. The attack caused temporary accessibility issues but did not compromise data accuracy or availability for critical stakeholders.

KRP launched an investigation into the incident, tentatively classifying it as aggravated interference with communications under Finnish law. No suspects were identified during the initial phase. Detective Chief Inspector Marko Leponen of KRP’s Cybercrime Centre noted authorities had anticipated potential cyber threats during elections, emphasizing that high-profile public services often attract such attacks. The incident drew public attention when Green League chairperson Pekka Haavisto described it as a serious threat to democratic processes, advocating for continued reliance on paper-based voting safeguards. The disruptions remained confined to the public-facing portal, with no evidence of data manipulation or broader system infiltration. Finnish officials reiterated the resilience of election infrastructure while acknowledging the persistent risk of cyber incidents targeting visibility-focused platforms.

Sources

Sources available to members: 1 source.

CSIDB