Cyberattack on the University of Tartu gift shop

Käed arvutiklaviatuuril
Author: Ines Pütsepp / ChatGPT

The University of Tartu was informed today that the University of Tartu webshop at shop.ut.ee had been the target of a cyberattack between 14 and 16 June 2026. The attacker installed malware on the website by exploiting a security vulnerability in the webshop software.

The software has now been cleaned and restored, and the security gap has been closed. The attacker’s access has been blocked, and the system has been thoroughly checked.

As far as we know, the attacker gained access to the shop administrator’s view and customer data. Therefore, the attacker may have been able to see customers’ names, email addresses, postal addresses, phone numbers, order histories, and encrypted versions of account passwords. The actual passwords were not accessible. All customers who may be affected have been individually notified by email.

It is important to note that payment card details are not stored on the webshop server and the attacker could not access them.

We recommend that customers remain cautious regarding suspicious emails, messages and phone calls, avoid opening unknown links or attachments, and change their webshop account password if the same password is used in other environments.

The University of Tartu notified the Data Protection Inspectorate and the CERT-EE department of the Estonian Information System Authority. We apologise for the incident and are doing everything possible to prevent similar situations in the future.

For any further questions, please contact Gift Shop Project Manager Juhan Kari ([email protected]).