This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Cyberattack Conditions 2026 | MAY
Hackers adapted their scenarios to everyday situations by using the names of well-known companies, media, and institutions to create trust and lure personal data, payment card information, or access to online banking. Criminals posing as representatives of Swedbank security services claimed that payments to foreign countries were being made from accounts and simultaneously sent SMS messages resembling bank notifications about withdrawn funds, thereby further reinforcing trust and creating a sense of urgency. In May, several incidents of compromising .lv websites were detected, characterized by outdated or poorly maintained content management systems, mainly WordPress, Joomla, and other CMS platforms, with unpatched plugins and themes. In some cases, visitors were redirected to gambling sites, while in others — to ClickFix schemes, which are particularly dangerous as they give the impression that legitimate actions are needed to fix issues, such as following instructions or downloading files. Given the current geopolitical situation and the public functions of the public transport company, such incidents pose risks to reputation, public order, disinformation, and can reduce trust in official information channels. In May, car manufacturer Škoda reported a security incident detected on the company's online store, during which cyberattackers possibly accessed some customer information, reports securityweek.com.