In 2024, CERT-EE registered 580 distributed denial-of-service (DDoS) attacks. This was 93 more than in 2023 and 50% more than in 2021 and 2022 combined.
Just as attackers are constantly seeking new ways to cause maximum harm, CERT-EE continuously improves its DDoS defences to counteract them. The more attackers target the websites protected by CERT-EE, the more effectively CERT-EE’s DDoS defence measures can be enhanced.
As a result, despite the alarmingly high number of attacks, the proportion of impactful ones dropped to just 18%. This represents significant progress compared to the previous year, when that figure was 27%.
Targeting name servers
One of the most notable trends of 2024 was attackers increasingly targeting name servers rather than web servers.
A name server translates IP addresses into domain names, allowing users to type google.com instead of remembering a numeric sequence like 142.250.189.206. While name servers do not host web content themselves, they help users locate it. If attackers succeed in disabling name servers through a denial-of-service attack, users cannot access websites, even if the web servers are functioning normally.
As Estonian organisations’ web servers have faced constant attacks over the years, they are now better protected. This forced attackers to change tactics, turning their focus to name servers, which are somewhat more complicated to defend.
This wave of attacks began in May 2024, when the share of denial-of-service attacks targeting Estonian organisations’ name servers jumped from the usual 3-8% to 69%. At the same time, attacks against web servers decreased. By the end of the year, attacks on name servers accounted for an average of 90% of all denial-of-service attacks registered by CERT-EE.
This trend clearly shows that attackers adapt to security measures and constantly seek new vulnerabilities to exploit. When systems critical to the functioning of the internet are targeted, the consequences of attacks can extend far beyond disabling individual websites.
This shift underlines the need for institutions and companies to invest more heavily in protecting name servers, which form the backbone of the internet.
The volume and scale of DDoS attacks continue to grow
Due to ongoing geopolitical tensions, distributed denial-of-service attacks are expected to increase further in 2025. These attacks will remain a popular tool for both state-sponsored groups and independent hacktivists. The rising popularity of this type of attack has led to the emergence of platforms and service providers that offer DDoS attacks for hire, making them more powerful and accessible even to less experienced cyber criminals. This, in turn, raises the overall threat level in cyberspace.
It is also likely that attackers will increasingly target components critical to internet functionality, such as name servers, cloud services and authentication services that many other services rely on. With the help of artificial intelligence and machine learning, distributed denial-of-service attacks are becoming more dynamic, allowing them to be adjusted in real-time to bypass defence mechanisms and complicate countermeasures.
26 years’ worth of traffic in four hours
In March, Estonia’s public sector faced an unprecedented wave of distributed denial-of-service attacks. Over a span of just four hours, attackers directed nearly 2.8 billion malicious requests at the websites of three institutions. Under normal circumstances, generating such a volume of traffic would have taken approximately 26 years.
The wave of attacks was carried out by two Russian hacktivist groups, targeting 16 Estonian government institutions.
Despite the unprecedented scale of the attacks, the impact on the targeted websites was minimal.
Although the attackers managed to produce a massive volume of malicious requests, the attacks themselves were not particularly sophisticated. Thanks to DDoS protection measures and CERT-EE’s active response, most of the requests never reached their intended targets. Out of the other 13 targeted websites, only three experienced brief disruptions, while the remaining 10 were unaffected by the attacks.
What is a DDoS attack?
A distributed denial-of-service (DDoS) attack is a cyberattack in which a large volume of malicious requests is directed at a target’s servers to overload them and render the service inaccessible to users.
Since most DDoS attacks against Estonia are politically motivated, they typically target services whose disruption would affect the largest number of people, such as national e-services, banks and the transport sector.
Last updated: 14.04.2025