439 scam sites were detected in April, most of which were used for investment scams. According to the police, several people lost tens of thousands of euros to such scams in the past month, with the biggest loss recently being 220,000 euros (in Estonian). For more information on how to avoid investment fraud, visit the website itvaatlik.ee (in Estonian).
Last month, 201 phishing sites designed to steal bank and other account details were discovered.
The Incident Response Department of the Information System Authority (CERT-EE) restricts access to scam and phishing sites, informs web hosts about them, and shares information with its international partners. Information about malicious websites can be sent to [email protected].
Common scams
In April, a lot of fraud calls (in Estonian) were made in Estonia, in which the fraudsters introduced themselves as Health Insurance Fund employees. The fraudsters claimed that it was possible to apply for a discount on the increased medical specialist visit fee from 1 April, and asked for personal information, including PINs, to claim the discount. The aim was to gain access to the bank account of the victim. RIA recommends that you immediately hang up such fraud calls and never share your personal data or PINs.
In April, many people in Estonia also once again fell victim to Facebook Marketplace scams (in Estonian). The scheme works as follows: the fraudster contacts the seller and expresses their wish to buy the goods. The ‘buyer’ then informs the seller that they wish to receive the goods by courier and sends the seller a link to a phishing site resembling the website of the courier company.
Once the victim has entered their details, as much money as possible will be taken from their bank card. The largest amount lost in this way was over 14,000 euros in April, according to police. Many more people lost thousands of euros.
RIA stresses that it is strongly discouraged to click on any of the links sent to you by ‘potential buyers’. The seller should always arrange for the parcel to be shipped via the official website of a courier company. Then, give the buyer your bank account number to receive the money.
Major incidents
On 3–6 April, there was a major wave of denial-of-service attacks in Estonia. The targets included the websites of major local governments, the Tax and Customs Board, Omniva, and Elron. This time, the attacks were technically more complex than usual, resulting in some websites experiencing short interruptions.
On 7 April, the admission information system sais.ee, managed by the Ministry of Education and Research, was unavailable for eight hours. The failure was caused by a wrong file loaded into the system due to human error, which caused the memory to fill up.
On 16 April, several services of the Information Technology and Development Centre of the Ministry of the Interior (SMIT) were disrupted for an hour, disrupting police work and document checks at the border. The incident was caused by a malfunction of the network equipment.
RIA is improving cyber security in Estonia
In the last few months, Estonian companies have been hit by four ransomware attacks, most likely via an insecure Remote Desktop Protocol (RDP). Therefore, RIA issued updated recommendations for the protection of RDP connections and the prevention of ransomware attacks (in Estonian).
The updated cyber test, which companies and institutions can use to raise the awareness of their employees of cyber threats, was also completed in April. The test includes a course covering all the main cyber hygiene topics and a practical test. The online test is free to use and can be taken on the RIA website. Cyber test is also available in English.
Schools have the opportunity to order free educational materials from the RIA website (in Estonian) to help children recognise and avoid the dangers of using the internet. The materials for primary school children were produced last year and proved extremely popular, with nearly 35,000 copies printed for 145 schools. RIA has therefore decided to issue a reprint and is waiting for orders from schools until 19 May.
On the RIA website, young girls can register for the international cyber security camp CyberWizards, which will take place in Kehtna on 11–16 August. Registration is open until 16 June or until places fill up.