Watch

Baltic Watch

Threat L3/5
State 2026-10-07 22:05
Threat GUARDEDL3/5 score 10 · L4 high at 12
Active 3/16 0 hard · 3 context
Official warnings 3 latest 2026-09-24 · Polish Special Services
Air picture 15 0 military · ADS-B live
Collection 15/15 official 7/7 · OSINT 20 posts
Monitor · RUNNING Public reporting and regional measurements, not an early-warning system. “Not observed” does not mean “not happening”.
Limits

Connectivity measurements, satellite thermal pixels and imagery catalogues supplement reporting; they do not detect troop movements or establish attacks. No live AIS; no push alerts. Follow official LT72 warnings.

The score is an uncalibrated heuristic, not an attack probability. Related indicators may describe the same event. ADS-B density contributes zero points.

Reporting

Situation

Sonnet · 3 min ago

The snapshot presents a moderately elevated but sub-crisis posture in the Baltic region. The most operationally significant developments are Lithuania deploying military to the Kaliningrad border (a defensive response to possible Russian mobilisation, not a Russian offensive indicator), armed Belarusian-linked escorts pushing migrants across the Latvian border, and the US Embassy urging citizens to leave Russia citing plague risk — which meets the embassy_departure threshold. The Oct 3 Lithuanian air alert was fully cancelled within its TTL and no active alert remains. No confirmed hard indicators of Russian offensive buildup, airspace violation, infrastructure sabotage, or NATO emergency consultation are present in the snapshot.

Cross-signal reading · 3

Lithuania's military deployment to the Kaliningrad border and its parliament removing the constitutional nuclear weapons ban are mutually reinforcing signals of heightened deterrence posture, driven by Russia's nuclear rhetoric over Kaliningrad rather than confirmed Russian offensive action.

The US Embassy evacuation-style warning for Russia and Latvia's persona non grata process against a Russian journalist together reflect deteriorating diplomatic conditions, but neither confirms military escalation.

Armed Belarusian escorts at the Latvian border and Lithuanian minister warnings of spillover suggest a coordinated hybrid pressure campaign, consistent with the provocation warning context but not meeting the hard by_border threshold of troop concentration.

Automated reading of 160 items. Interpretation, not verified fact; no combined danger level.

Aircraft

Air Picture

15 tracked · 0 mil · 22:04
Aircraft table · 14
CallsignCountryAltitudeVelocityStatus
DLH2466 Latvia 8,496 m 896 km/h Airborne
SAS1428 Sweden 7,345 m 749 km/h Airborne
NSZ72FK Sweden 2,651 m 543 km/h Airborne
BRU922 Belarus 868 m 410 km/h Airborne
DFL5840 Sweden 358 m 231 km/h Airborne
SWR41P Latvia 289 m 270 km/h Airborne
NSZ4MF Sweden 30 m 264 km/h Airborne
NSZ4608 Sweden n/a 12 km/h Ground
WZZ26JT Hungary n/a 4 km/h Ground
SAS2744 Sweden n/a 4 km/h Ground
LOT3827 Poland n/a 24 km/h Ground
RYR34AP Poland n/a 15 km/h Ground
DLH6VP Germany n/a 1 km/h Ground
RYR8XM Ireland n/a 0 km/h Ground
What to watch for
NATO ISR and transport surges from Siauliai, Amari, Malbork and Lask; Russian military or Russian-registered aircraft in sensitive Baltic zones; anomalous low-density traffic over the Baltic Sea.
Maritime

Maritime Picture

bases · chokepoints · no live AIS
Russian Military NATO Airbase EFP Battlegroup Infrastructure Risk
What to watch for
Russian ship activity near Kaliningrad and Baltiysk, survey or shadow-fleet behaviour near cable corridors, and naval repositioning that changes access through Suwalki-adjacent and central Baltic chokepoints.
Measurements

Regional observations

9/9 streams · W0

Measured connectivity and satellite observations, not military attribution; zero weight in the score. Missing data never means “nothing happened”.

9/9 streams usable
Internet connectivityLT · LV · EE · 0 sustained drops · 6/6 streams usable

Lithuania · BGP route visibility

No sustained drop

0.0% below baseline · median 10600.0 · 288 reference bins

No sustained ≥15% drop in this measurement. Not proof of uninterrupted connectivity.

Measured:
Fetched: · refresh 15 min

Method, limits & provenance

Local rule: every bin for at least 20 min is ≥15% below a trailing baseline median (previous 24h, excluding latest hour). Minimum 72 baseline bins spanning 12h. Latest bin ≤45 min old.

Route visibility / probe responses, not cyberattack attribution. Country aggregation can miss local outages.

IODA / Georgia Tech Research Corporation

Inspect original source ↗

Lithuania · Active probing reachability

No sustained drop

0.3% below baseline · median 4684.0 · 144 reference bins

No sustained ≥15% drop in this measurement. Not proof of uninterrupted connectivity.

Measured:
Fetched: · refresh 15 min

Method, limits & provenance

Local rule: every bin for at least 20 min is ≥15% below a trailing baseline median (previous 24h, excluding latest hour). Minimum 72 baseline bins spanning 12h. Latest bin ≤45 min old.

Route visibility / probe responses, not cyberattack attribution. Country aggregation can miss local outages.

IODA / Georgia Tech Research Corporation

Inspect original source ↗

Latvia · BGP route visibility

No sustained drop

0.0% below baseline · median 7355.0 · 288 reference bins

No sustained ≥15% drop in this measurement. Not proof of uninterrupted connectivity.

Measured:
Fetched: · refresh 15 min

Method, limits & provenance

Local rule: every bin for at least 20 min is ≥15% below a trailing baseline median (previous 24h, excluding latest hour). Minimum 72 baseline bins spanning 12h. Latest bin ≤45 min old.

Route visibility / probe responses, not cyberattack attribution. Country aggregation can miss local outages.

IODA / Georgia Tech Research Corporation

Inspect original source ↗

Latvia · Active probing reachability

No sustained drop

0.3% below baseline · median 4171.0 · 144 reference bins

No sustained ≥15% drop in this measurement. Not proof of uninterrupted connectivity.

Measured:
Fetched: · refresh 15 min

Method, limits & provenance

Local rule: every bin for at least 20 min is ≥15% below a trailing baseline median (previous 24h, excluding latest hour). Minimum 72 baseline bins spanning 12h. Latest bin ≤45 min old.

Route visibility / probe responses, not cyberattack attribution. Country aggregation can miss local outages.

IODA / Georgia Tech Research Corporation

Inspect original source ↗

Estonia · BGP route visibility

No sustained drop

0.0% below baseline · median 6211.0 · 288 reference bins

No sustained ≥15% drop in this measurement. Not proof of uninterrupted connectivity.

Measured:
Fetched: · refresh 15 min

Method, limits & provenance

Local rule: every bin for at least 20 min is ≥15% below a trailing baseline median (previous 24h, excluding latest hour). Minimum 72 baseline bins spanning 12h. Latest bin ≤45 min old.

Route visibility / probe responses, not cyberattack attribution. Country aggregation can miss local outages.

IODA / Georgia Tech Research Corporation

Inspect original source ↗

Estonia · Active probing reachability

No sustained drop

0.6% below baseline · median 2909.0 · 144 reference bins

No sustained ≥15% drop in this measurement. Not proof of uninterrupted connectivity.

Measured:
Fetched: · refresh 15 min

Method, limits & provenance

Local rule: every bin for at least 20 min is ≥15% below a trailing baseline median (previous 24h, excluding latest hour). Minimum 72 baseline bins spanning 12h. Latest bin ≤45 min old.

Route visibility / probe responses, not cyberattack attribution. Country aggregation can miss local outages.

IODA / Georgia Tech Research Corporation

Inspect original source ↗
Thermal observationsNASA FIRMS · 1 pixels in 24h

Satellite thermal observations

Thermal pixels observed

1 qualifying pixels · not a count of separate fires

1 thermal pixels in the regional window; cause unassigned.

Measured:
Fetched: · refresh 60 min
Latest timestamp anywhere in source dataset: 2026-10-07T13:33:00Z (not local coverage)

Method, limits & provenance

Nominal/high-confidence thermal pixels acquired within 24h inside 20.9–28.3°E, 53.9–59.8°N. Rectangle includes neighbouring territory; pixels are not distinct fires.

One polar-orbiting sensor, not continuous coverage. Clouds and overpass gaps hide events. Industry and vegetation fires are common; cannot identify explosions, sabotage or troop movement.

NASA FIRMS / LANCE, S-NPP VIIRS Collection 2 NRT

Inspect original source ↗
Satellite acquisition catalogueCopernicus · radar + optical · catalogue, not image analysis

Radar acquisitions

Catalogue only

6 recent catalogue samples. No automated image interpretation.

Measured:
Fetched: · refresh 360 min

Method, limits & provenance

Latest six catalogue items intersecting the Baltic regional rectangle, within 14 days. Not a complete coverage inventory. Acquisition time is not publication time.

Metadata and quicklook access only; no full-resolution pixel comparison, object recognition or movement detection. Whole-scene cloud percentage is not local cloud cover.

Copernicus Sentinel data / Copernicus Data Space Ecosystem

Inspect original source ↗

Optical acquisitions

Catalogue only

6 recent catalogue samples. No automated image interpretation.

Measured:
Fetched: · refresh 360 min

Method, limits & provenance

Latest six catalogue items intersecting the Baltic regional rectangle, within 14 days. Not a complete coverage inventory. Acquisition time is not publication time.

Metadata and quicklook access only; no full-resolution pixel comparison, object recognition or movement detection. Whole-scene cloud percentage is not local cloud cover.

Copernicus Sentinel data / Copernicus Data Space Ecosystem

Inspect original source ↗

No troop/object recognition, garrison-refill detection, private intelligence access or push alerting. Connectivity dips and thermal pixels need independent explanation. Satellite items are discovery/quicklooks only.

Official

Document timeline

51 stored · 19 in 30d

51 stored documents

Official bulletinPolish Special Servicesautomated
Minister Tomasz Siemoniak na konferencji InSec 2026: Trzeba patrzeć na bezpieczeństwo w sposób całościowy

Polish Special Services Coordinator Minister Tomasz Siemoniak addressed the opening of the 28th International Internal Security and Border Security Conference and Exhibition (InSec 2026) in Warsaw, emphasising the need for comprehensive, immediate security readiness to protect national interests and citizens.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Trzeba być zawsze gotowym do ochrony własnych interesów i obrony własnych obywateli - podkreślił koordynator służb specjalnych w środę, 7 października br., na otwarciu XXVIII Międzynarodowej Konferencji i Wystawy Bezpieczeństwa Wewnętrznego i Bezpieczeństwa Granic InSec 2026 w Warszawie.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Strategic assessmentRIA / Estoniaautomated
September in cyberspace: data breaches and disruptions to government e-services

Estonia's RIA registered 964 cyber incidents in September, including data breaches affecting a dental care information system and the University of Tartu's online bookshop, denial-of-service attacks, and repeated disruptions to state authentication services. No perpetrator is identified.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Among the more serious incidents this month were data breaches affecting the dental care information system and the University of Tartu’s online bookshop, denial-of-service attacks, and repeated disruptions to the state’s authentication services.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Investigation / allegationVDD / Latviaautomated
VDD in cooperation with MIDD detain couple for espionage on behalf of Russia’s GRU

On 28 June 2026, Latvia's VDD and MIDD detained a couple on suspicion of unlawfully collecting information about Latvia's defence sector on behalf of Russia's GRU. The matter is at investigation/detention stage; no conviction recorded.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

On 28 June 2026, Latvian State Security Service (VDD) in cooperation with Defence Intelligence and Security Service (MIDD) detained a couple on suspicion of unlawful collection of information about Latvia’s defence sector on behalf of Russia’s military intelligence service (GRU).

Attribution: Source attribution claim — see excerpt; not a court finding

On 28 June 2026, Latvian State Security Service (VDD) in cooperation with Defence Intelligence and Security Service (MIDD) detained a couple on suspicion of unlawful collection of information about Latvia’s defence sector on behalf of Russia’s military intelligence service (GRU).

Automated reading of one official document; not independent verification.

Official bulletinPolish Special Servicesautomated
Minister Tomasz Siemoniak w TVP INFO o Marcinie Romanowskim: Wszystkie zarzuty pozostają w mocy

Polish Minister Tomasz Siemoniak stated on TVP INFO that all charges against former Deputy Minister Marcin Romanowski remain in force and that he should appear before Polish justice as soon as possible, regardless of legal manoeuvres.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

- Przede wszystkim chodzi o sprawę kryminalną i o to, że przed polskim wymiarem sprawiedliwości ucieka ktoś, kto był wysokim urzędnikiem, wiceministrem i powinien jak najszybciej, niezależnie od różnych sztuczek prawniczych, pojawić się i zeznawać - mówił o sprawie Marcina Romanowskiego minister koordynator służb specjalnych w programie „Gość Poranka” na antenie TVP INFO.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinPolish Prime Ministerautomated
Premier z apelem do Prezydenta o podpisanie korzystnych dla obywateli ustaw

Polish PM Donald Tusk appealed to President Karol Nawrocki to sign legislation on budget increases for security and healthcare and PIT tax reductions affecting 3.5 million people. Tusk also referenced a growing threat from Russia and attacks near the Polish-Ukrainian border, stating the military remains on constant readiness and cooperation with Ukraine is exemplary.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Premier odniósł się także do rosnącego zagrożenia ze strony Rosji i ataków przy polsko-ukraińskiej granicy.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

1 prior captured revision(s) retained.

Official bulletinPolish Special Servicesautomated
Minister Tomasz Siemoniak gościem programu „Jeden na jeden”

Polish Special Services coordinator Tomasz Siemoniak stated on TVN24 that Russia believes a strategy of strangling Ukraine's economy is effective, citing strikes on border crossings and daytime air raids, and noted Ukraine's economic losses in recent weeks are very significant.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

- Rosja uważa, że strategia zaduszenia gospodarki Ukrainy jest skuteczna, stąd uderzenia w przejścia graniczne i naloty dzienne.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official warningPolish Special Servicesautomated
Minister koordynator w Polsat News: Rosja może eskalować swoje działania na terytoria innych państw

Polish Minister Tomasz Siemoniak stated that authorities must prepare for worst-case scenarios, warning that Russia, having attacked Ukraine and violated international law, may repeat such aggression against other states.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Natomiast poważnie należy się liczyć z tym, że Rosja, która prowadzi taką politykę, że napada na inne państwa, napadła na Ukrainę, pogwałciła prawo międzynarodowe, może to zrobić raz, drugi, trzeci i czwarty - mówił minister Tomasz Siemoniak w programie „Gość Wydarzeń”.

Attribution: Not established by this reading

Automatically identified prospective warning, not independent verification or evidence that an attack occurred. Check the original wording and geography.

Automated reading of one official document; not independent verification.

Official bulletinPolish Special Servicesautomated
Współpraca sojusznicza gwarantem bezpieczeństwa

Polish intelligence coordinator Tomasz Siemoniak met with NATO Deputy Secretary General for Intelligence and Security Scott W. Bray. Discussions focused on regional security and allied intelligence service cooperation within NATO.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Bezpieczeństwo w regionie i współpraca sojusznicza służb specjalnych w ramach NATO były głównymi tematami rozmowy ministra - członka Rady Ministrów, koordynatora służb specjalnych Tomasza Siemoniaka i Scotta W.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinPolish Special Servicesautomated
Minister Tomasz Siemoniak o amerykańskiej bazie w Polsce: Ważny sygnał w bardzo ważnym momencie

Polish Minister Coordinator Tomasz Siemoniak stated on Radio Trójka that the US military presence in Poland is more than a military matter — it is a political signal demonstrating US commitment to Poland's defence.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

To jest pokazanie przez Stany Zjednoczone: „Tak, jesteśmy obecni w Polsce, nie pozwolimy Polski ruszyć” - podkreślił minister koordynator Tomasz Siemoniak na antenie radiowej Trójki.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinPolish Special Servicesautomated
Minister koordynator gościem Radia TOK FM

Minister Tomasz Siemoniak stated on Radio TOK FM that the United States recognises the threats facing Poland and is ready to cooperate, following his consultations in Washington.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

- Amerykanie są z nami, dostrzegają te wszystkie zagrożenia i są gotowi do współdziałania z nami - mówił o kulisach swoich rozmów w Waszyngtonie minister Tomasz Siemoniak na antenie Radia TOK FM.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official warningPolish Prime Minister’s Office
Polish PM relays intelligence warning about possible hybrid drone and missile strikes

Tusk relayed an intelligence assessment of planned hybrid drone and missile strikes against Ukraine-supporting states, including Poland. The statement discusses the coming months and a critical late-autumn/winter period in the Ukraine war. It does not report that the projected strikes on Poland have occurred.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Attribution: Prospective assessment attributed to intelligence services by the Polish PM; underlying evidence not public.

Underlying intelligence and a precise attack date are not public. Do not convert this warning into a personal attack probability or a confirmed strike.

Investigation / allegationLatvian State Security Service (VDD)
Latvia: investigation into threats against companies supplying Ukraine

VDD reports a criminal case opened on September 9 over threats against Latvia-based companies supplying armaments to Ukraine, and a detention. The September 17 publication describes an investigation, not a completed terrorist attack.

Read original publication ↗
Evidence, attribution & limits

Reported event/procedural date: 2026-09-09. Publication: 2026-09-17.

Attribution: Group described by VDD as pro-Kremlin; Russian state direction not established here.

The source describes a pro-Kremlin group. That label alone does not establish Russian state direction or a conviction.

Official bulletinRIA / Estoniaautomated
Estonian experts develop cyber defence doctrine for the AI era

Estonian experts from government agencies, universities, technology companies and banks published a comprehensive cyber defence policy paper with recommendations for protecting digital society in the AI era.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Experts and researchers from Estonian government agencies, universities, technology companies and banks have developed a comprehensive cyber defence policy paper setting out recommendations for countries seeking to protect digital society in the age of artificial intelligence.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinPolish Special Servicesautomated
Spotkanie ministra Tomasza Siemoniaka z Ihorem Klymenko, sekretarzem Rady Bezpieczeństwa Narodowego i Obrony Ukrainy

Polish Special Services Minister Tomasz Siemoniak met with Ihor Klymenko, Secretary of the National Security and Defence Council of Ukraine, on 16 September.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

W środę, 16 września br., minister - członek Rady Ministrów, koordynator służb specjalnych Tomasz Siemoniak spotkał się z Ihorem Klymenko, sekretarzem Rady Bezpieczeństwa Narodowego i Obrony Ukrainy.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Strategic assessmentPolish Special Servicesautomated
Minister Tomasz Siemoniak w TVN24: Rosja testuje naszą odporność

Minister Coordinator Tomasz Siemoniak stated on TVN24 that Russia is acting more boldly, seeking to intimidate and pressure NATO states supporting Ukraine into withdrawing that support.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Chce zastraszyć - mówił o rosyjskich działaniach wymierzonych w państwa NATO koordynator służb specjalnych Tomasz Siemoniak na antenie TVN24.

Attribution: Source attribution claim — see excerpt; not a court finding

- Rosja zaczyna sobie śmielej poczynać.

Automated reading of one official document; not independent verification.

Official bulletinNKSC / Lithuaniaautomated
Keičiasi kibernetinio saugumo taisyklės gamintojams: įsigalioja naujos pranešimų teikimo pareigos pagal Kibernetinio atsparumo aktą

Lithuania's NKSC announced that Cyber Resilience Act (CRA) mandatory reporting obligations for manufacturers of products with digital elements came into force on 11 September 2026.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Cyber Resilience Act, CRA) nustatytos pranešimų teikimo prievolės.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Source-reported incidentPolish Prime Ministerautomated
Eskalacja rosyjskich działań staje się faktem

On the morning of 13 September, an attack occurred 2 km from the Polish-Ukrainian border, striking a petrol station or nearby area and a freight train on a siding. PM Tusk convened an emergency security briefing, warned of intensified Russian actions in coming weeks, and noted Russia's use of jet drones. Services were placed on heightened alert.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Dziś rano, 2 km od granicy polsko-ukraińskiej, doszło do ataku na stację benzynową lub teren w jej pobliżu oraz na skład pociągu towarowego znajdujący się na bocznicy.

Attribution: Source attribution claim — see excerpt; not a court finding

Poranny atak pokazuje, że Rosja jest gotowa do użycia groźniejszego niż dotychczas sprzętu - dronów odrzutowych.

Automated reading of one official document; not independent verification. Occurrence, cause and attribution are separate questions.

Official bulletinPolish Prime Ministerautomated
Polski przemysł obronny przyspiesza dzięki SAFE

At the International Defence Industry Exhibition in Kielce, Poland signed an executive contract for Piorun portable air-defence missile systems worth over PLN 8 billion under the SAFE programme. Norway, Latvia and Lithuania are purchasing the systems. A letter of intent for a Polish military satellite communications system was also signed, with nine satellites planned by year-end.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Podczas Międzynarodowego Salonu Przemysłu Obronnego w Kielcach Agencja Uzbrojenia i Mesko podpisały pierwszą umowę wykonawczą do wartej ponad 8 mld zł umowy na dostawy przenośnych przeciwlotniczych zestawów rakietowych Piorun.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinPolish Special Servicesautomated
Tomasz Siemoniak w USA: Sojusz polsko-amerykański jest silny i niezachwiany

Polish Minister Tomasz Siemoniak visited the United States and met with the CIA Director and the Deputy Director of National Intelligence, affirming that close intelligence cooperation is a cornerstone of the Polish-American alliance.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Lata współdziałania w różnych częściach świata zbudowały między służbami wielkie zaufanie - podkreślił minister Tomasz Siemoniak podczas wizyty w Stanach Zjednoczonych.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinNKSC / Lithuaniaautomated
NKSC koordinuojamas Regioninis kibernetinės gynybos centras tampa Tarptautine kibernetinių grėsmių analizės platforma

Lithuania's NKSC announced that its Regional Cyber Defence Centre is expanding international cooperation and becoming an International Cyber Threat Analysis Platform.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Nacionalinio kibernetinio saugumo centro prie Krašto apsaugos ministerijos (NKSC) koordinuojamas Regioninis kibernetinės gynybos centras (RKGC) pradeda naują veiklos etapą – plečia tarptautinį bendradarbiavimą ir tampa Tarptautine kibernetinių grėsmių analizės platforma …

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Strategic assessmentRIA / Estoniaautomated
August in cyberspace: service disruptions, ransomware attacks, and phishing messages

Estonia's Information System Authority registered 899 cyber incidents in August, including disruptions to key services, a ransomware attack on a school in Harju County, and a phishing campaign impersonating the Transport Administration. No attribution stated.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Over the course of the month, there were disruptions to several key services, a school in Harju County was hit by a ransomware attack, and a phishing campaign with the perpetrator purporting to be from the Transport Administration was circulating.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Investigation / allegationPolish Special Servicesautomated
Broń, amunicja i trzech obywateli Rosji. Operacja ABW i KSP

Poland's ABW and Warsaw Police conducted an operation against three Russian citizens of Chechen nationality suspected of operating within an organised criminal group and possessing firearms, with the aim of neutralising a potential threat.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Na podstawie wiedzy ABW o trzech obywatelach Federacji Rosyjskiej narodowości czeczeńskiej, którzy mogli działać w ramach zorganizowanej grupy przestępczej i posiadać broń palną, wspólnie z funkcjonariuszami Wydziału do walki z Terrorem Kryminalnym i Zabójstw Komendy Stołecznej Policji przeprowadzono operację mającą na celu neutralizację potencjalnego zagrożenia.

Attribution: Source attribution claim — see excerpt; not a court finding

Na podstawie wiedzy ABW o trzech obywatelach Federacji Rosyjskiej narodowości czeczeńskiej, którzy mogli działać w ramach zorganizowanej grupy przestępczej i posiadać broń palną, wspólnie z funkcjonariuszami Wydziału do walki z Terrorem Kryminalnym i Zabójstw Komendy Stołecznej Policji przeprowadzono operację mającą na celu neutralizację potencjalnego zagrożenia.

Automated reading of one official document; not independent verification.

Advisory / preparednessNKSC / Lithuaniaautomated
Nuo privatumo iki nacionalinio saugumo: kodėl būtina apsaugoti vaizdo stebėjimo kameras?

Lithuania's NKSC warns that video surveillance cameras used in homes, businesses and public institutions may be easy targets for cyber criminals, who could gain access to unsecured devices, posing risks to privacy and national security.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Vaizdo stebėjimo kameros, užtikrinančios saugumą namuose, įmonėse ir viešosiose įstaigose, taip pat padedančios kontroliuoti gamybos, logistikos ar kitų veiklų efektyvumą, gali tapti lengvu taikiniu kibernetiniams nusikaltėliams.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Investigation / allegationVDD / Latviaautomated
VDD detains three Latvian citizens on suspicion of arson in Estonia

Latvia's VDD initiated a criminal case on 16 August 2026 on suspicion that three Latvian citizens carried out an arson attack on defence technology company Milrem Robotics in Estonia on the night of 15 August.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

On 16 August 2026, Latvian State Security Service (VDD) initiated a criminal case on the suspicion that on the night of 15 August three Latvian citizens had carried out an arson attack of the defence technology company "Milrem Robotics" in Estonia.

Attribution: Source attribution claim — see excerpt; not a court finding

On 16 August 2026, Latvian State Security Service (VDD) initiated a criminal case on the suspicion that on the night of 15 August three Latvian citizens had carried out an arson attack of the defence technology company "Milrem Robotics" in Estonia.

Automated reading of one official document; not independent verification.

Official bulletinPolish Special Servicesautomated
Minister Tomasz Siemoniak w Polsat News: Rosja rozumie język siły

Polish Special Services coordinator Minister Tomasz Siemoniak stated in a Polsat News interview that NATO and its allies must seriously prepare for various scenarios, that Russia understands the language of force, and that visible NATO exercises in Poland send a strong deterrent signal.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

- My, NATO, nasi sojusznicy musimy poważnie zakładać różne scenariusze i do nich się przygotowywać.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinPolish Special Servicesautomated
Minister Tomasz Siemoniak o wycieku danych. „Przechodzimy przyspieszoną lekcję cyberbezpieczeństwa”

Polish Special Services coordinator Minister Tomasz Siemoniak discussed a medical data leak affecting millions of Polish citizens, actions by security services regarding Marcin Romanowski, and a CBA audit of flood relief, describing it as an accelerated lesson in cybersecurity.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Wyciek danych medycznych dotyczący milionów Polaków, działania służb w sprawie Marcina Romanowskiego oraz kontrola CBA dotycząca pomocy dla powodzian - to najważniejsze tematy rozmowy z ministrem Tomaszem Siemoniakiem w audycji Sygnały Dnia.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Strategic assessmentPolish Special Servicesautomated
Minister Tomasz Siemoniak w TVN24

Polish Special Services coordinator Minister Tomasz Siemoniak assessed that Russia is exploiting tensions between Poland and Ukraine to deepen social divisions.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Ocenił również, że Rosja wykorzystuje napięcia między Polską a Ukrainą do pogłębiania podziałów społecznych.

Attribution: Source attribution claim — see excerpt; not a court finding

Ocenił również, że Rosja wykorzystuje napięcia między Polską a Ukrainą do pogłębiania podziałów społecznych.

Automated reading of one official document; not independent verification.

Investigation / allegationVDD / Latviaautomated
VDD detains person for funding Russian armed forces

On 5 August 2026, Latvia's VDD detained a person on suspicion of providing funding to the Russian armed forces to continue military action against Ukraine.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

On 5 August 2026, Latvian State Security Service (VDD) detained a person on suspicion of providing funding to the Russian armed forces to continue military action against Ukraine.

Attribution: Source attribution claim — see excerpt; not a court finding

On 5 August 2026, Latvian State Security Service (VDD) detained a person on suspicion of providing funding to the Russian armed forces to continue military action against Ukraine.

Automated reading of one official document; not independent verification.

Strategic assessmentRIA / Estoniaautomated
July in cyberspace: hacked websites, service disruptions, and phishing emails

Estonia's RIA registered 1,044 cyber incidents in July, including website disruptions, increased defacements of Estonian websites, and ongoing phishing emails impersonating banks. No attribution stated.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Over the course of the month, several websites experienced disruptions, defacements of Estonian websites became more frequent, and phishing emails sent posing as banks continued.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinRIA / Estoniaautomated
Mai Kraft appointed Director of RIA's National Cyber Security Centre

Mai Kraft assumed the role of Director of Estonia's National Cyber Security Centre (NCSC-EE) and Deputy Director General for Cyber Security at RIA as of 1 August, succeeding Gert Auväärt who was appointed Ambassador to Canada.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

As of 1 August, Mai Kraft has assumed the position of Director of the National Cyber Security Centre of Estonia (NCSC-EE) at the Estonian Information System Authority (RIA), as well as Deputy Director General for Cyber Security.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinVSD / Lithuaniaautomated
VSD strateginės komunikacijos vadovu tapo A. Pučėta

Communications specialist Artūras Pučėta has been appointed head of the Strategic Communications Division of Lithuania's State Security Department (VSD), having previously worked at a communications agency and news outlets.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Valstybės saugumo departamento (VSD) Strateginės komunikacijos skyriui pradeda vadovauti komunikacijos specialistas Artūras Pučėta.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Exercise / testRIA / Estoniaautomated
The next generation of cyber talent to assemble in Estonia

An international cyber camp for girls is taking place in Kehtna, Estonia, bringing nearly a hundred young cyber talents from nine countries.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

An international cyber camp for girls is taking place in Estonia this week, bringing nearly a hundred young cyber talents from nine countries to the small town of Kehtna.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Investigation / allegationVSD / Lithuaniaautomated
Atliekamas ikiteisminis tyrimas dėl šnipinėjimo – informacija rinkta apie karinius objektus

Vilnius district prosecutor's office is conducting a pre-trial investigation in which one Lithuanian citizen is suspected of espionage. The suspect allegedly used Telegram to self-initiate contact and carry out tasks from Russian intelligence services via intermediaries, collecting information on Lithuanian military facilities, radar and electronic warfare equipment, and military vehicle movements, including at Vilnius airport, and reportedly offered to provide information while visiting Belgium.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Vilniaus apygardos prokuratūra atlieka ikiteisminį tyrimą, kuriame įtarimai dėl šnipinėjimo pareikšti vienam Lietuvos Respublikos piliečiui.

Attribution: Source attribution claim — see excerpt; not a court finding

Ikiteisminis tyrimas pradėtas po to, kai Lietuvos Respublikos valstybės saugumo departamentui (VSD) atliekant žvalgybos tyrimą buvo gauta informacija apie asmenį, kuris galimai renka informaciją veikdamas pagal Rusijos Federacijos žvalgybos ir saugumo tarnybų (RF ŽST) taikomus metodus.

Automated reading of one official document; not independent verification.

Strategic assessmentRIA / Estoniaautomated
June in cyberspace: service disruptions and data breaches attracted attention

Estonia's RIA registered 1,232 cyber incidents with impact in June, slightly above the six-month average. Disruptions affected several key public services, denial-of-service attacks occurred, and a customer data breach was recorded in the booking system of a company in southern Estonia. No perpetrator attributed.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

The Information System Authority (RIA) registered 1,232 incidents with an impact in the Estonian cyberspace in June, which is slightly higher than the average for the last six months.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinNKSC / Lithuaniaautomated
Kaip neatsidurti sukčių akivaruose? Visuomenei atveriamas kursas „Atsparumas finansiniam sukčiavimui“

Lithuania's central bank, NKSC, and AML centre jointly launched a free public training course aimed at strengthening societal resilience to financial fraud.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Lietuvos bankas, Nacionalinis kibernetinio saugumo centras (NKSC) ir Pinigų plovimo prevencijos kompetencijų centras (AML centras) suvienijo jėgas siekdami stiprinti visuomenės atsparumą finansiniam sukčiavimui.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Investigation / allegationVDD / Latviaautomated
VDD seeks criminal prosecution against four persons for espionage on behalf of Russia

Latvia's VDD requested the Prosecution Office on 19 June 2026 to initiate criminal prosecution against four Latvian nationals allegedly suspected of collecting intelligence in Latvia and transferring it to Russian intelligence and security services through the pro-Kremlin criminal organisation 'Baltic anti-fascists'.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

On 19 June 2026, Latvian State Security Service (VDD) asked the Prosecution Office to initiate criminal prosecution against four Latvian nationals for collecting intelligence in Latvia and transferring it to Russian intelligence and security services through the pro-Kremlin criminal organisation "Baltic anti-fascists".

Attribution: Source attribution claim — see excerpt; not a court finding

On 19 June 2026, Latvian State Security Service (VDD) asked the Prosecution Office to initiate criminal prosecution against four Latvian nationals for collecting intelligence in Latvia and transferring it to Russian intelligence and security services through the pro-Kremlin criminal organisation "Baltic anti-fascists".

Automated reading of one official document; not independent verification.

Official bulletinNKSC / Lithuaniaautomated
NKSC: bendradarbiavimas leidžia užkirsti kelią kibernetinėms atakoms

Lithuania's NKSC conducted a cybersecurity assessment of the geothermal heat pump 'IGLU MAX 90' as part of efforts to ensure the cyber resilience of critical infrastructure.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Nacionalinis kibernetinio saugumo centras prie Krašto apsaugos ministerijos (NKSC), siekdamas užtikrinti kritinės infrastruktūros kibernetinį atsparumą, atliko geoterminio šilumos siurblio „IGLU MAX 90“ kibernetinio saugumo vertinimą.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Strategic assessmentNKSC / Lithuaniaautomated
Tarptautinė kibernetinių grėsmių ataskaita: dirbtinis intelektas ir pažeidžiamos interneto sistemos keičia kibernetinių atakų pobūdį

Lithuania's NKSC published an international cyber threat report noting that malicious actors are increasingly using artificial intelligence, exploiting publicly accessible organisational systems, and targeting cloud services.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Piktavaliai kibernetiniams nusikaltimams organizuoti ir vykdyti vis aktyviau pasitelkia dirbtinį intelektą, išnaudoja viešai prieinamas organizacijų sistemas ir taikosi į debesijos paslaugas.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official warningVSD / Lithuaniaautomated
VSD ĮSPĖJA DĖL TARP NEPILNAMEČIŲ ASMENŲ PLINTAČIOS NIHILISTINIO EKSTREMIZMO IDEOLOGIJOS

Lithuania's VSD warns of the rapid spread of nihilistic extremism ideology among minors, observed in Lithuania and globally. Networks such as '764' and 'Maniac Murder Cult' operate via social media and gaming platforms, coercing vulnerable youth into self-harm, violence and other criminal acts. VSD urges parents, guardians and educators to monitor children's online activity and report suspicious contacts.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Valstybės saugumo departamentas nihilistinio ekstremizmo plitimo apraiškas stebi ir Lietuvoje, todėl ragina tėvus, globėjus, pedagogus ir kitus nepilnamečių artimoje aplinkoje esančius asmenis atkreipti dėmesį į šią grėsmę ir domėtis vaikų veikla virtualioje erdvėje.

Attribution: Not established by this reading

Automatically identified prospective warning, not independent verification or evidence that an attack occurred. Check the original wording and geography.

Automated reading of one official document; not independent verification.

Official bulletinVDD / Latviaautomated
VDD holds the meeting of Counterterrorism Centre Expert Advisory Council

Latvia's VDD held a biannual meeting of the Counterterrorism Centre Expert Advisory Council on 19 June, discussing current counterterrorism developments, reviewing the draft Latvian counterterrorism strategy for 2027–2031, and setting priorities for the next half-year.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

On 19 June, Latvian State Security Service (VDD) held a meeting of Counterterrorism Centre Expert Advisory Council discussing the current developments in the counterterrorism field, reviewing the draft Latvian counterterrorism strategy for 2027-2031 and outlining the priorities for the next half of the year.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinNKSC / Lithuaniaautomated
Krašto apsaugos ministras: NKSC dar 2022 m. nustatė trūkumus VRM sistemose, imamės veiksmų

Lithuania's Defence Minister visited NKSC; discussions included a cyber incident at the Ministry of Internal Affairs that NKSC had identified vulnerabilities relating to as early as 2022.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Krašto apsaugos ministras Robertas Kaunas lankėsi Nacionaliniame kibernetinio saugumo centre prie Krašto apsaugos ministerijos (NKSC).

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinNKSC / Lithuaniaautomated
Premjerė: kibernetinis saugumas negali būti atidėliojamas

Lithuania's Prime Minister instructed more than 70 public-sector organisations to implement Cybersecurity Law requirements by 31 August.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Ministrė Pirmininkė Inga Ruginienė pavedė daugiau kaip 70 viešojo sektoriaus organizacijų iki rugpjūčio 31 d.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Strategic assessmentRIA / Estoniaautomated
RIA: May saw the highest number of cyber incidents with an impact recorded in the last six months

Estonia's RIA recorded 1,561 cyber incidents with impact in May, the highest figure over the previous six months. Of these, 1,047 were scam and phishing websites. Disruptions affected several key public services and a fraud case against the Estonian Artists Association caused losses of nearly €700,000. No state perpetrator attributed.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

In May, the Estonian Information System Authority (RIA) recorded 1,561 incidents with impact in Estonian cyberspace, which is highest of the last six months.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Exercise / testVDD / Latviaautomated
Large-scale counterterrorism exercise organised by VDD takes place in Ventspils port

Latvia's VDD conducted the national-level counterterrorism exercise 'Windau 2026' with full force deployment in Ventspils on 4 June 2026. Emergency services and other institutions tested readiness for a scenario involving armed terrorists attacking a port and passenger ferry and taking hostages.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

On 4 June 2026, Latvian State Security Service (VDD) conducted the national level counterterrorism exercise with full force deployment "Windau 2026" in Ventspils.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Exercise / testVDD / Latviaautomated
VDD conducts its largest counterterrorism exercise to date at Ventspils port

On 4 June 2026, Latvia's VDD conducted its largest counterterrorism exercise to date, 'Windau 2026', with full force deployment at Ventspils port.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Today, 4 June 2026, Latvian State Security Service (VDD) is conducting its largest counterterrorism exercise to date with full force deployment in Ventspils – "Windau 2026".

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Official bulletinVSD / Lithuaniaautomated
Konkursas „Geriausias baigiamasis mokslo darbas nacionaliniam saugumui reikšmingomis temomis“

Lithuania's VSD is organising a competition for bachelor's and master's students who defended theses on national security and intelligence topics in the 2025–2026 academic year, with monetary prizes of €800 and €1,000 respectively. Submissions accepted 1 July–1 September.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Valstybės saugumo departamentas (VSD) organizuoja konkursą Lietuvos aukštųjų universitetinių mokyklų bakalauro ir magistro studijų studentams, 2025-2026 mokslo metais apgynusiems baigiamuosius darbus, nagrinėjančius nacionaliniam saugumui ir žvalgybai reikšmingas temas.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Strategic assessmentNKSC / Lithuaniaautomated
R. Kaunas: pagrindinė incidentų priežastis – laiku nešalinami pažeidžiamumai, neatlikta IT higiena

On 26 May 2026, Lithuania's Defence Minister presented the 2025 National Cybersecurity Status Report, stating that the main cause of incidents remains unpatched vulnerabilities and inadequate IT hygiene.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

Nacionalinės kibernetinio saugumo būklės ataskaitą krašto apsaugos ministras Robertas Kaunas sako, kad kibernetinio saugumo klausimas išlieka itin aktualus visos valstybės mastu, o operatyvus reagavimas …

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Investigation / allegationVDD / Latviaautomated
VDD seeks criminal prosecution against a group of persons for arson in the interests of a foreign state

On 21 May 2026, Latvia's VDD requested the Prosecution Office to initiate criminal prosecution against four individuals allegedly responsible for arson of Latvian railway objects, purportedly carried out in the interests of a foreign state.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

On 21 May 2026, Latvian State Security Service (VDD) asked the Prosecution Office to initiate criminal prosecution against four individuals for the arson of Latvian railway objects in the interests of a foreign state.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Source-reported incidentRIA / Estoniaautomated
April in cyberspace: disruptions to digital services and a surge in phishing emails

In April, Estonia's RIA recorded 1,138 cyber incidents with impact, including disruptions to everyday digital services and a surge in phishing attacks that caused individuals to lose thousands of euros.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

In April, the Information System Authority (RIA) recorded 1,138 cyber incidents with impact, some of which were related to the functioning of everyday digital services.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification. Occurrence, cause and attribution are separate questions.

Official bulletinRIA / Estoniaautomated
The Cyber Accelerator invites applications from cyber security startups with a focus on combating cybercrime and on research-based solutions

Estonia's RIA and Tehnopol Startup Incubator's Cyber Accelerator is inviting applications from cybersecurity startups, offering up to €60,000 in financial support to develop products or services combating cybercrime and research-based solutions.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

The Cyber Accelerator, organised in collaboration between the Information System Authority (RIA) and the Tehnopol Startup Incubator, is inviting applications from startups operating in the field of cyber security.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Investigation / allegationVDD / Latviaautomated
VDD seeks criminal prosecution against a person for providing publications to a Russian propaganda website

On 7 April 2026, Latvia's VDD requested criminal prosecution against a long-standing Russian compatriot policy activist alleged to have violated EU sanctions by providing publications to a Russian propaganda website.

Read original publication ↗
Evidence, attribution & limits

Event date not separately established; the timeline uses publication dates.

On 7 April 2026, Latvian State Security Service (VDD) asked the Prosecution Office to initiate criminal prosecution against a long-standing Russian compatriot policy activist for violating the European Union (EU) sanctions by providing publications to a Russian propaganda resource.

Attribution: Not established by this reading

Automated reading of one official document; not independent verification.

Documents are not incident counts; a publication date is not an event date. Original-language evidence stays one click away.

Assessments

Strategic baseline

5 lenses

Thematic lenses on one Lithuanian intelligence assessment, not independent confirmations. Newer developments belong in the document timeline.

Sabotage & coercionreviewed baseline

VSD/AOTD assess that the GRU is seeking more dangerous operations, including in Lithuania, and more experienced recruits. The report also records prevented operations.

This is a strategic assessment, not a live attack notice. Public reporting does not reveal all attempted or disrupted operations.

What could change the reading: New official warnings, completed incidents and prevention reports belong in the timeline; none alone establishes a trend in successful attacks.

Publisher
VSD / AOTD · National Threat Assessment 2026
Information cutoff
2026-02-06
Analytical review
2026-09-20 · next due 2026-10-20
Source check
2026-10-07 11:38 UTC · unchanged
Read the assessment ↗
Intelligence & recruitmentreviewed baseline

The assessment describes FSB recruitment pressure on people travelling from Lithuania to Russia, including collection concerning military activity and support for Ukraine.

Exposure is not uniform across residents. This does not show that a particular individual has been targeted.

What could change the reading: Direct VSD notices and investigation updates; distinguish suspected recruitment, prosecution and conviction.

Publisher
VSD / AOTD · National Threat Assessment 2026
Information cutoff
2026-02-06
Analytical review
2026-09-20 · next due 2026-10-20
Source check
2026-10-07 11:38 UTC · unchanged
Read the assessment ↗
Cyber & service continuityreviewed baseline

VSD/AOTD assess increasing cyber risks from hostile-state groups, including destructive operations and shared-supplier vulnerabilities.

An internet outage is not evidence of a cyberattack; attribution requires separate evidence. IODA measures availability only.

What could change the reading: NKSC/RIA notices on affected services, impact and attribution; compare with connectivity observations without treating coincidence as causation.

Publisher
VSD / AOTD · National Threat Assessment 2026
Information cutoff
2026-02-06
Analytical review
2026-09-20 · next due 2026-10-20
Source check
2026-10-07 11:38 UTC · unchanged
Read the assessment ↗
Information manipulationreviewed baseline

The report describes disguised Russian narratives, impersonation and social-platform campaigns aimed at weakening trust in institutions, NATO and support for Ukraine.

Criticism or disagreement alone is not evidence of a coordinated influence operation. Repetition is not independent corroboration.

What could change the reading: Official attribution and documented coordinated behaviour, not counts of alarming posts.

Publisher
VSD / AOTD · National Threat Assessment 2026
Information cutoff
2026-02-06
Analytical review
2026-09-20 · next due 2026-10-20
Source check
2026-10-07 11:38 UTC · unchanged
Read the assessment ↗
Conventional military scenariosreviewed baseline

The assessment links Russian force regeneration to the war in Ukraine: continuing high-intensity fighting constrains capacity; a freeze or ceasefire accelerates rebuilding; peace plus lifted sanctions accelerates it further.

These are conditional capability scenarios, not a countdown to invasion or proof of a decision to attack.

What could change the reading: Changes in the Ukraine-war scenario, verified regional deployments and alliance posture. Hybrid activity does not automatically imply conventional escalation.

Publisher
VSD / AOTD · National Threat Assessment 2026
Information cutoff
2026-02-06
Analytical review
2026-09-20 · next due 2026-10-20
Source check
2026-10-07 11:38 UTC · unchanged
Read the assessment ↗

Checking a page does not renew its analytical review. Overdue or changed assessments stay flagged; they never silently become “safe”.

Civil defence

Slėptuvės · Public shelters

2522 sites

Kolektyvinės apsaugos statiniai. Centred on Vilnius; zoom out for the national network. Markers open address, capacity and a Google Maps link. Source: PAGD via data.gov.lt, weekly.

Satellite / Coordinates

Reference Points

7 sites
Key Coordinates
Kaliningrad Garrison
54.7104N · 20.5128E
Map
Pskov Airbase (Russia)
57.7839N · 28.3956E
Map
Luga Garrison
58.7N · 29.8E
Map
Vitebsk Staging Area (BY)
55.2N · 30.2E
Map
Siauliai Air Base (LT)
55.8938N · 23.3932E
Map
Amari Air Base (EE)
59.2586N · 24.2083E
Map
Suwalki Gap
54.1N · 22.9E
Map
History

Signal Log

200 entries
2026-10-07 21:14:36
[AUTO] BY BORDER CLEARED
2026-10-07 19:56:22
[AUTO] BY BORDER ACTIVATED — NBS: Migrant group pushed aggressively across Latvian border this week (LSM)
2026-10-07 18:33:44
[AUTO] BY BORDER CLEARED
2026-10-07 16:42:16
[AUTO] BY BORDER ACTIVATED — NBS: Migrant group pushed aggressively across Latvian border this week (LSM)
2026-10-07 16:01:31
[AUTO] BY BORDER CLEARED
2026-10-07 15:10:20
[AUTO] EMBASSY DEPART ACTIVATED — JAV ambasada dėl galimo maro ragina visus piliečius nedelsiant palikti Rusiją (LRT LT)
2026-10-07 15:10:20
[AUTO] BY BORDER ACTIVATED — NBS: Migrant group pushed aggressively across Latvian border this week (LSM)
2026-10-07 14:34:36
[AUTO] EMBASSY DEPART CLEARED
2026-10-07 13:43:09
[AUTO] DIPLO EXPUL ACTIVATED — Latvia’s Foreign Ministry reportedly moves to declare Russian journalist Leonid Ragozin persona non grata (Meduza)
2026-10-07 12:55:42
[AUTO] DIPLO EXPUL CLEARED
2026-10-07 10:42:25
[AUTO] PROVOCATION WARNING ACTIVATED — Katelynas: neramu, kad incidentas Latvijos pasienyje gali pasikartoti ir Lietuvoje (LRT LT)
2026-10-07 09:55:50
[AUTO] DIPLO EXPUL ACTIVATED — Latvia’s Foreign Ministry reportedly moves to declare Russian journalist Leonid Ragozin persona non grata (Meduza)
2026-10-07 09:40:09
[AUTO] EMBASSY DEPART ACTIVATED — JAV ambasada dėl galimo maro ragina visus piliečius nedelsiant palikti Rusiją (LRT LT)
2026-10-07 05:41:43
[AUTO] PROVOCATION WARNING CLEARED
2026-10-07 04:54:58
[AUTO] PROVOCATION WARNING ACTIVATED — Latvian officials say armed masked men threatened troops while trying to push 20 migrants across from Belarus, then crossed into Latvia themselves and stole sur (Meduza)
2026-10-06 20:26:33
[AUTO] PROVOCATION WARNING CLEARED
2026-10-06 18:36:59
[AUTO] PROVOCATION WARNING ACTIVATED — Russia testing Europe's defenses below threshold of open war, experts say (KyivInd)
2026-10-06 18:06:25
[AUTO] PROVOCATION WARNING CLEARED
2026-10-06 16:32:58
[AUTO] PROVOCATION WARNING ACTIVATED — Russia testing Europe's defenses below threshold of open war, experts say (KyivInd)
2026-10-06 16:17:05
[AUTO] PROVOCATION WARNING CLEARED