Seimo kanceliarija fiksuavo kibernetinį incidentą
Friday 3rd July 2026 on 11:30 in
Lithuania
The Lithuanian parliament (Seimas) has reported a cyber incident in which an attempt was made to compromise the passwords of some of its staff, according to a statement from the Seimas Chancellery cited by national broadcaster LRT.
The incident was detected and contained, and the National Cyber Security Centre was informed. The Seimas Chancellery stated that the situation is fully under control, with no negative consequences or system disruptions identified.
The Chancellery also noted that the parliament has recently restored its Information Technology Department and is strengthening its operations. Significant investments have been allocated to modernise systems and enhance long-term cyber resilience, with the latest incident underscoring the need for such measures.
In response to growing cyber threats—including a large-scale data breach at the Centre of Registers—the Seimas has updated its rules for the secure use and management of networks and information systems. These rules, approved by an order from Seimas Chancellor Algirdas Stončaitis, aim to ensure the security of the parliament’s IT systems and data.
The updated regulations introduce strict restrictions on external storage devices (USB). USB drives and external hard drives will be centrally blocked on Chancellery computers and equipment in meeting rooms. For information exchange or presentations in the parliament’s meeting halls, only secure Seimas cloud storage (OneDrive/SharePoint) is recommended.
Exceptions will allow the use of work computers in meeting rooms if they are connected solely via HDMI or USB-C for screen transmission. Access to the Seimas Chancellery’s systems from work email will only be permitted from devices provided and centrally managed by the Chancellery.
If a member of parliament wishes to connect via a personal phone or computer, an exception process will apply—requiring prior coordination and written consent for the device to be controlled by the Chancellery’s IT specialists and integrated into the centralised management system (MDM), ensuring all basic security parameters are met.
The Chancellery has also tightened requirements for passwords and multi-factor authentication (MFA). MFA will now be mandatory for accessing Seimas Chancellery systems, both on-site and remotely, wherever technically feasible. Passwords must be at least 12 characters long and changed every 90 days. After five incorrect password attempts, the account will be automatically blocked for 15 minutes.
For official information and document sharing, only approved and secure platforms (such as Microsoft Teams and Signal) may be used. Sending non-public information via popular messaging apps (Viber, WhatsApp, etc.) is prohibited. Additionally, uploading or processing non-public Seimas data, internal documents, or personal data in public generative AI tools (e.g., the free version of ChatGPT) is banned.