Cyber Incident Victim: Finnish Transport and Communications Agency
Date:
Sep 2023
Location:
Finland
Summary
The Finnish Transport and Communications Agency (Traficom) experienced a distributed denial-of-service (DDoS) attack targeting its electronic services, disrupting public access to critical platforms. This incident primarily affected motorists by blocking vehicle registration and traffic permit applications, though urgent matters could be redirected to insurance providers' digital services. The agency activated countermeasures to mitigate the attack and restore functionality promptly. This marked the second such disruption within a month, following a similar service outage earlier in the same period, though no data breaches or permanent damage were reported in either instance.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On September 23, 2023, the Finnish Transport and Communications Agency (Traficom) experienced a service-denial attack targeting its electronic services, disrupting public access to its systems. The agency confirmed the incident through official communications on its website and X (formerly Twitter), stating that mitigation measures were actively underway to restore functionality as quickly as possible. This disruption affected critical services for motorists, including vehicle registration and traffic commissioning processes. Traficom advised users requiring urgent assistance to contact their insurance providers directly, noting that these companies could handle certain transactions through their own digital platforms during the outage. The attack marked the second such incident within a month, following a previous cyberattack on September 7, 2023, though the article does not specify whether the same threat actor or methodology was involved in both events.

The agency did not disclose technical details regarding the attack vector, scale, or duration of the disruption beyond confirming it as a service-denial incident. No data breaches or system compromises were reported, with impacts limited to service availability. Traficom's public communications focused on operational updates, emphasizing restoration efforts without attributing blame or discussing preventative measures. The repeated targeting within a three-week period highlights persistent vulnerabilities in Traficom's public-facing infrastructure, though the article provides no evidence of successful data exfiltration or secondary attacks. Service restoration timelines and specific defensive actions taken during the September 23 incident remain unspecified beyond the agency's general assurance of ongoing mitigation efforts.
