Fraudsters made off with millions

Despite awareness campaigns by the Estonian Police and Border Guard Board, the Information System Authority and other organisations, the final figures for last year sadly confirm that it was a successful year for fraudsters.

In 2024, CERT-EE recorded 837 significant fraud incidents – nearly double the 546 incidents reported in 2023.

During the first 11 months of the year, Estonian citizens lost €7 million to fraud, according to data from the Police and Border Guard Board. Since many cases go unreported, the actual losses are likely much higher. 

But why do so many fraud attempts succeed?

There are several factors. First, scammers have become increasingly sophisticated, and their messages appear more convincing. Second, in today’s fast-paced world, people often multitask and let their guard down. Third, with more individuals shopping online frequently, they are often waiting for deliveries, which increases the likelihood of them mistaking a scammer’s message for a genuine notification about a package.

Illustratsioon: hobusel kappav kauboi, keerutamas @-märgi kujuga lassot. Taustal täidetav arve põhi.

Businesses plagued by invoice fraud

Invoice fraud has become a relatively common type of scam in which fraudsters send a fake invoice to an organisation under the guise of a legitimate business partner. The phoney invoice usually differs only in the payment account details, making the fraud easy to overlook. The recipient unknowingly transfers money to the fraudsters, while the actual partner continues to wait for payment.

This type of fraud can be difficult to detect, as criminals often hijack ongoing correspondence, leading the victim to believe they are still communicating with their business partner. However, changes to account details, which are not a common practice, should serve as a warning sign.

In November, we received reports about four cases of invoice fraud with damages totalling nearly €300,000.

  • In one case, an Estonian company transferred over €170,000 to an account controlled by fraudsters. The criminals had compromised the company’s email account and monitored correspondence with a supplier. At the right moment, they sent an invoice in the supplier’s name with altered account details, and the recipient made the payment.
  • In another case, a state-owned company fell victim to fraud when an invoice sent to its general email address appeared legitimate. The amount matched expectations, but the bank account details had been changed. The company transferred nearly €30,000 to the fraudsters, only discovering the fraud when the real business partner, who had not received the payment, asked for a payment confirmation.
  • A third case involved an Estonian company purchasing a new car. Over the course of a month, the company corresponded with a German car dealer, finalised the contract and transferred the payment according to the provided bank details. When it came time to deliver the car, it was revealed that the bank account belonged to fraudsters, and nearly €60,000 had gone to the wrong account. The criminals had hijacked the correspondence and altered the payment details.
  • In another instance, an industrial company fell victim to invoice fraud. The fraudster intercepted correspondence at the right moment and issued a fake invoice. Since the company was due to pay its next instalment, everything seemed legitimate, and the nearly identical invoice was paid. The accountant did not suspect that the payment details had been altered.

How to avoid invoice fraud

  • Raise awareness about invoice fraud. Everyone in your organisation who approves invoices should understand the nature and signs of such fraud. As a starting point, share the post published on RIA’s blog (in Estonian) and explain the issue to your employees.
  • Agree on an invoice approval procedure. For example, establish a rule that if invoice details, such as bank account information, have changed, the sender must be contacted through an alternative channel, such as by phone. Be sure to use a known contact number rather than the one listed on the invoice, as fraudsters may replace genuine contact information with their own.
  • If you or your accountant suspect that a payment has been made to the wrong account, contact your bank immediately. In the age of instant payments, reaction time is limited, but prompt action may allow the bank to reverse the transfer.
  • If you identify or suspect a fake invoice sent in the name of a business partner, contact the partner immediately. Use a different channel from the one through which the invoice was received. Acting quickly in this way can help uncover the problem before it reaches the next victim.

The crypto boom brought new scams

Fraud involving cryptocurrency is becoming increasingly common. Since the field is often associated with promises of quick and easy profits, scammers have started exploiting the trust of unsuspecting individuals.

The schemes vary, but the pattern is often the same: a person is offered an opportunity to earn money and is guided through making an initial deposit on a cryptocurrency trading platform.

The process typically starts with smaller amounts, such as €250, transferred to the platform. After the initial payment, the person is shown how much profit they are supposedly making. They withdraw the earnings, which builds trust and encourages reinvestment, this time with a larger sum.

The second time, the person transfers a significantly higher amount to the scammers’ account. Later, they are informed that additional fees are required to access their funds.

They pay even more, but ultimately, they are unable to retrieve either the initial amount or the extra money. 

In some cases, these scams appear as job offers. The victim is promised payment for completing cryptocurrency-related tasks.

Once compensation is agreed upon, they are informed that an additional fee or taxes must be paid upfront to receive the money. For example, if the agreed compensation is €10,000, the “employee” is required to pay 20% in taxes first. Enticed by the prospect of substantial earnings, the victim transfers the requested sum, only to find that they neither receive the promised payment nor recover the upfront fee.

The amounts lost in such scams typically range from €2,000 to €3,000, but reports have also been received of much larger losses.

Scams impersonating banks and postal service providers continued

Once again, numerous reports were received about phishing emails and SMS messages sent in the name of postal service providers or banks. This type of fraud has been popular for years and shows no signs of abating. Broadly speaking, these phishing scams fall into two categories.

Ekraanikuvad õngitsustest: postipaki saabumise SMS ja panga nimel saadetud e-kiri
  • The first involves emails or SMS messages sent in the name of service providers such as Omniva, DPD or DHL, claiming that a parcel cannot be delivered due to an incorrect address, unpaid delivery fees or customs charges. Often, these messages ask for a small payment, typically a few euros, for customs or postal services. However, once users enter their payment card details, significantly larger sums are withdrawn from their accounts. Losses from such scams typically range from a few hundred to tens of thousands of euros.
  • The second type involves emails purportedly sent by a popular bank, asking recipients to update their information. The sender’s address is arbitrary, and the email contains a suspicious link that does not belong to the claimed bank. These emails often stress urgency and set a deadline for completing the task. Unfortunately, many people overlook these warning signs and proceed to update their details. The user is directed to a fake website, where they are prompted to log in using the Smart-ID authentication service and enter their PIN codes. 

In both cases, users can be almost certain they will not recover their money.

The most important step is to carefully check the link included in the email or message to make sure the domain is legitimate.

Suspicious addresses usually reveal that the message is not authentic. Banks never send emails with links for updating information; they only request updates via their official apps or websites. Similarly, Omniva and other postal service providers never ask users to enter their details on external websites.

Four examples of successful scams

  • In August, Kalle (all names have been changed) received a message from Omniva claiming that his parcel had been returned due to an incorrect address and asking him to update the delivery address. On the phishing site, he was asked to select the correct parcel locker and pay €4. Kalle entered his card details and noticed that the page kept loading, but he didn’t give it much thought. The next morning, however, he discovered that over €1,300 had been withdrawn from his account. Although he cancelled his bank card, the lost money could not be recovered.
  • In September, Malle was selling a refrigerator on Facebook Marketplace. The buyer claimed they could not pick up the item themselves and suggested using Cargobus courier services instead. Malle was sent a link and redirected to a fake Cargobus page to make a payment confirming the refrigerator’s transport. Trusting the process, she entered her card details, only to find that €3,900 had disappeared from her account moments later. The payment could not be reversed, and the scammer succeeded.
  • In October, Helle received an email that appeared to be from LHV Bank, asking her to update her details. She entered her banking information on the page opened via the link and later discovered that €950 had been withdrawn from her account. She tried calling and emailing the bank, but as it was outside working hours, she could only reach them the following morning. Unfortunately, it was too late to recover the money.
  • Ülle booked accommodation on Booking.com. She carefully reviewed other visitors’ ratings, photos of the property and the price: the offer seemed both attractive and credible. The site featured dozens of photos of the property and several positive reviews from users. Although payments should typically be made through Booking.com, the host sent Ülle separate bank account details for payment. After receiving her transfer, the host disappeared without a trace, and the property was removed from the portal.

Police caught the creator of phishing kits

On 5 June, Estonian National Criminal Police charged a 22-year-old man suspected of developing phishing kits and selling them on the Telegram app. These kits enabled users to create phishing websites and collect people’s login credentials. With these tools, it was possible to bypass two-factor authentication systems used by platforms such as Microsoft 365, PayPal, Google, Dropbox and Binance. 

This case highlights the growing trend of cybercrime becoming more service-based, where the person conducting the attacks and the one providing the tools are often different individuals.

Fraudsters who create such services are also of interest to the police, as cybercriminals are increasingly becoming a key link in the world of international organised crime.

It is crucial to disrupt this chain at an early stage.

Last updated: 17.02.2025

open graph imagesearch block image