Police have warned of a sharp increase in cyberattacks targeting government institutions, with malicious emails disguised as trusted correspondence, Mihaaru reported.
According to Mihaaru’s report, published on 6 October 2026, police issued the warning on their website after monitoring by the Cyber Security Operations Centre (CSOC).
The centre identified deceptive emails being sent to government offices and institutions. Police urged both state bodies and the public to exercise particular caution.
The messages are crafted to resemble legitimate correspondence from official institutions or familiar contacts, police said. Malicious links and files are presented as official invitations, documents or file-sharing links.
Police warned that opening these files or following the links could expose sensitive information, including usernames and passwords. Stolen credentials could then enable unauthorised access to institutional computer systems and networks, leaving them compromised.
According to police, CSOC assesses that the activity appears to form part of a planned campaign directed at specific targets. The report does not identify those responsible or name any affected institutions.
Police said the centre was closely monitoring the activity and sharing information needed to protect against the attacks. It was also working with relevant government agencies to block malicious websites and networks.
Investigations and technical analysis remained under way, according to the report. No figures were provided for the number of attacks or confirmed breaches.
Police advised recipients not to open email links or attachments unless they were sure these were safe. Even messages appearing to come from trusted institutions or known contacts should be checked if they contain unusual requests.
Recipients should verify such messages through another channel, such as a telephone call. Police also advised against entering usernames or passwords on pages reached through email links.
Other recommended precautions include enabling multi-factor authentication on email and official accounts, and keeping operating systems and applications updated. Suspicious emails should be reported promptly to an organisation’s IT or security team.
Anyone who has already opened a suspicious file or link should immediately disconnect their computer from the network and seek IT assistance, police said. They advised against attempting to resolve the issue without help.
Police described public awareness and vigilance as the first line of defence against these attacks. Further technical details were available through the cyber portal, they said.


