CSIDB logo
Incident

Finnish Transport and Communications Agency

Incident posture

Attack window
Sep 2023
Location
Finland
Status
Historical
CIA posture
Available to members
Updated
2026-07-14 08:41

Linked entities

Victim
Finnish Transport and Communications Agency
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Finnish Transport and Communications Agency (Traficom) experienced a distributed denial-of-service (DDoS) attack targeting its electronic services, disrupting public access to critical platforms. This incident primarily affected motorists by blocking vehicle registration and traffic permit applications, though urgent matters could be redirected to insurance providers' digital services. The agency activated countermeasures to mitigate the attack and restore functionality promptly. This marked the second such disruption within a month, following a similar service outage earlier in the same period, though no data breaches or permanent damage were reported in either instance.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 23, 2023, the Finnish Transport and Communications Agency (Traficom) experienced a service-denial attack targeting its electronic services, disrupting public access to its systems. The agency confirmed the incident through official communications on its website and X (formerly Twitter), stating that mitigation measures were actively underway to restore functionality as quickly as possible. This disruption affected critical services for motorists, including vehicle registration and traffic commissioning processes. Traficom advised users requiring urgent assistance to contact their insurance providers directly, noting that these companies could handle certain transactions through their own digital platforms during the outage. The attack marked the second such incident within a month, following a previous cyberattack on September 7, 2023, though the article does not specify whether the same threat actor or methodology was involved in both events.

The agency did not disclose technical details regarding the attack vector, scale, or duration of the disruption beyond confirming it as a service-denial incident. No data breaches or system compromises were reported, with impacts limited to service availability. Traficom's public communications focused on operational updates, emphasizing restoration efforts without attributing blame or discussing preventative measures. The repeated targeting within a three-week period highlights persistent vulnerabilities in Traficom's public-facing infrastructure, though the article provides no evidence of successful data exfiltration or secondary attacks. Service restoration timelines and specific defensive actions taken during the September 23 incident remain unspecified beyond the agency's general assurance of ongoing mitigation efforts.

Sources

Sources available to members: 1 source.

CSIDB