The Incident Response Department of RIA (CERT-EE) recorded 305 incidents with an impact in August, which is slightly above the average for the last six months. The majority of incidents, as usual, were phishing sites with 158 detected.
In August, we saw an increase in denial-of-service (DDoS) attacks, but most of these did not have a significant impact. Among others, the websites of Tallinn Airport and the Tax and Customs Board, as well as estonia.ee, a website introducing Estonia, were attacked.
A major wave of DDoS attacks started around 20 August, targeting both public and private websites. Estonian media companies – Delfi, Äripäev, and Lääne Elu – were also targeted, causing their websites to experience short-term interruptions. RIA published a threat assessment concerning the wave of attacks this week.
While the number of service disruptions was smaller than usual last month, there were still several high-impact incidents. For example, Mobile-ID was not available for almost half an hour on the Elisa network. Likewise, the basic services of the Health Insurance Fund, such as the digital prescription and the insurance verification, could not be used within 30 minutes due to malfunctions in the X-tee data exchange layer.
A couple of times, there were also interruptions in the operation of the state portal eesti.ee. After the update, the business services no longer worked properly and due to a technical error, it was possible to see the personal data of another person during a five-minute period: their name, email address, phone number, and information about related companies.
During the night of 21 August, several services provided by the IT and Development Centre of the Ministry of the Interior were disrupted for nearly four hours due to network outages. Due to the incident, the waiting time of 112 emergency calls may have been longer than usual – up to 30 seconds instead of the usual 5–6 seconds.
Activities of RIA to promote cyber security
From 7 to 12 August, RIA organised the international youth camp CyberWizards to popularise cyber security among girls aged 13 to 16 and spark their interest in studying the subject. English was the language of communication at the camp and the participants, more than 70 of them, included girls from foreign countries: Italy, the Czech Republic, and Latvia. Among other things, the girls learned how to use different operating systems, protect themselves in cyberspace, detect security vulnerabilities, and crack passwords.
On 29 and 30 August, RIA participated in the international cyber exercise ‘Northern Bastion’ in Helsinki, which aimed to increase the resilience of the Nordic banking sector to attacks. The exercise brought together the central banks, finance ministries, financial supervisory authorities, and cyber defence centres of Estonia, Finland, Sweden, Denmark, and Norway.
RIA has also put together an e-course to introduce the Estonian Information Security Standard (E-ITS). The training ‘Implementing e-ITS: from defence to an implementation plan’ is primarily intended for public sector employees who are responsible for implementing the information security strategy of their institution or company. This is a continuation of the introductory course ‘The ABCs of the Estonian Information Security Standard (E-ITS)’.
You can read more about all of these and many other topics in the monthly summary of RIA, ‘Situation in Cyberspace – August 2023’, which also gives an overview of cyber events around the world.