August saw two ransomware attacks and a massive spread of phishing attempts

13.09.2024 | 15:33

The monthly summary prepared by the Information System Authority (RIA) reports that August in Estonia saw two ransomware attacks, a system of the Transport Administration was breached by taking advantage of security vulnerabilities, and a massive amount of phishing emails and messages were sent posing as Omniva.

In August, the Incident Response Department of the Information System Authority (CERT-EE) recorded 499 cyber incidents with an impact that resulted in people and companies losing their data or money or disruptions in the work of information systems. During the first eight months of this year, the number of recorded incidents with an impact had reached 3,781 – 90% more than during the same period last year.

In August, the incidents with the highest impact were once again phishing pages, of which CERT-EE managed to block 313. Over the last few months, phishing has been on the rise, and in August, a huge number of phishing messages were sent posing as Omniva. The content of the messages differed, but most of them stated that a parcel could not be delivered due to an incorrect address and asked the recipient to update their information. Some of the messages requested a payment of shipping costs or customs fees.

All of the messages contained a suspicious link leading to a phishing page and many who entered their data lost hundreds or even thousands of euros. RIA would like to remind you that courier companies do not send such messages or ask their customers to add their data at unknown links.

Noteworthy cyber attacks and service disruptions

In August, RIA received notifications of two ransomware attacks. On 16 August, the servers of the Järva County Vocational Training Centre were encrypted with ransomware. All of the data on the servers was destroyed and the school did not have any backup copies. A day later, information on the servers of a retail company in South Estonia was encrypted. As the attackers managed to gain access to the backup server as well, the backup copy was deleted. Due to the attack, the operation of the company came to a standstill. In the opinion of RIA, these incidents once again demonstrate the importance of creating data backups, which must be stored separately from other systems.

On 15 August, RIA was notified that attackers managed to gain access to the central management system of end user devices of the Transport Administration. The Transport Administration, its partners, and CERT-EE conducted an analysis which indicated that a vulnerability in the Fortinet software, disclosed in March, was used for the attack. As far as is currently known, the attackers did not succeed in obtaining data from the system.

RIA would like to note that new security vulnerabilities are constantly discovered in different types of software due to technological advances, and over the last few years, they have been abused at an increasing pace. Therefore, it is essential to patch vulnerabilities as quickly as possible and automate security updates where feasible.

When it comes to service disruptions with a bigger impact, the monthly update of RIA discusses an incident that took place on 6 August, where the Apollo online information system of the police and the PIKO information system of the border control were not functioning properly for about an hour. The border guards were unable to use the system because X-tee queries were not forwarded. The incident was caused by a technical error. On the same day, a glitch in email software caused issues with sending emails in the online commercial register.

During the second half of the month, on 22 August, the services of TeliaTV stopped operating in Android set-top boxes for about three hours. On 24 August, 67 websites managed by the Information Technology Centre of the Ministry of Finance (RMIT) were disrupted for several hours. The malfunction was caused by a configuration error in a name server of the RMIT.

RIA’s monthly summary also discusses steps taken to improve cybersecurity in Estonia and the situation elsewhere in cyberspace. Among all else, Ukrainian experts discovered a malware campaign targeted at Ukrainian government agencies; moreover, cyber attacks were carried out against Halliburton, which is one of the largest oil processing companies in the world, and Microchip Technology, which is a manufacturer of semiconductors in the US.

ARNO PÕDER

Communications Specialist

open graph image