The Estonia-based company Allium UPI, which operates in the pharmacy and healthcare product sectors in Estonia, Latvia and Lithuania, reported in February 2024 to both the Estonian Police and Border Guard Board and the Information System Authority’s incident handling unit (CERT-EE) that their loyalty card system had been illegally accessed. The intruders downloaded data on the customers of Apotheka, Apotheka Beauty OÜ and PetCity OÜ, including personal identification codes, purchase data and contact information.
The Police and Border Guard Board’s criminal investigation revealed that nearly 700,000 personal identification codes, over 400,000 email addresses, around 60,000 home addresses and approximately 30,000 phone numbers were unlawfully downloaded from UPI’s database. In some cases, it was possible to identify over-the-counter medications and other pharmacy products purchased, though prescription medication data was not accessible. Since the loyalty programme did not store passwords, bank card information or other financial details, these were not compromised. The data came from a backup of the customer database containing records from 2014-2020.
Why did this happen?
Cyberattacks with serious consequences often begin with the takeover of an employee’s user account. Criminals can obtain usernames and passwords through methods such as malware, which might be downloaded to an employee’s computer using a malicious email attachment or pirated software from an untrusted source.
Two-factor authentication should be implemented to prevent criminals from immediately accessing systems with a leaked password. Furthermore, only information systems and services that absolutely must be online should have internet access, and all such systems should be secured behind a VPN or similar protective solution.
Given the highly international nature of cybercrime, leaked data can circulate for years among different countries and groups, who will be able to use it to carry out various cyberattacks.
Data is personal property
This incident once again brought the issue of protecting sensitive personal data into the public spotlight in Estonia. People increasingly trust their data to a growing number of service providers, expecting these providers to take their data protection responsibilities seriously. Unfortunately, this is not always the case, but similar incidents in recent years have raised awareness among both service providers and individuals, encouraging better preparedness and action.
As customers, we should critically assess the sharing of our personal data, including for loyalty accounts. A small discount or slightly more convenient service may not be worth the risk.
Lessons from the eye of the storm
‘An experience like this is a cold shower,’ recalls Marika Pensa, a member of the management board at Allium UPI.
Last winter, criminals stole a backup of the Apotheka customer database. Following this unfortunate incident, we, as a service provider, have placed even greater emphasis on system security.
Criminals never rest, and they exploit any weakness that may have escaped the heightened attention of system administrators.
The first lesson is simple: ensuring security is an ongoing process that never ends. It’s like riding a bicycle; you must keep moving to stay upright.
For a company that has become a victim or target of a cyberattack, such an experience is a cold shower, but also a reminder and an opportunity to reassess its systems. Cybersecurity is no longer just something described as “nice to have”.
Another lesson from this incident is that criminals don’t see the world as divided into business, government, customers, or other neatly defined boxes. Effective action against crime can only be achieved through unified collective defence involving individuals, companies, governments and others. That’s why we are very happy about the effective cooperation we’ve had with Estonian government agencies, from the Police and Border Guard Board to the Information System Authority and the Data Protection Inspectorate.
We all understand that we are on the same side of the front line, with international criminals on the other side. We hope the perpetrators of this crime will be apprehended and held accountable.
The fight against cybercrime requires continuous and growing attention from all of us. The question is not whether a cyberattack will happen but when, on what scale and in which area. There are no bulletproof individuals or systems, but robust defences against external attacks can save lives and protect data.
Last updated: 17.02.2025