Nearly two thirds of the cases were various phishing and scam websites, with 4,224 discovered – 2.5 times more than the year before last (Another record year we did not need, p. 8).
The Incident Response Department of RIA (CERT-EE) restricts access to malicious sites, informs web hosts about them, and shares information with its international partners. At the same time, cybercriminals are constantly creating new scam websites, so it is a good idea for everyone to keep up to date with the latest scams – by visiting itvaatlik.ee (in Estonian), for example – and to warn their family and friends.
The number of fraud cases involving losses registered by RIA increased by 14 per cent to 624 over the year. According to the Police and Border Guard Board, people in Estonia lost nearly 8 million euros to fraud last year, or an average of 22,000 euros a day. Investment fraud accounted for the majority of it – 4.8 million – and bank fraud for 2.3 million. At the end of the year, Estonian businesses were hit by a wave of invoice fraud, with the biggest losses reaching hundreds of thousands of euros (Fraudsters made off with millions, p. 28).
Cybercrime is increasingly international and organised, making it difficult to fight, but the Cyber Security Yearbook also highlights a number of success stories from the previous year. Among other cases, the Estonian police played an important role in an international police operation called PhishOFF that shut down a phishing platform with nearly a million victims (Phishers caught on the hook, p. 24). The Estonian Internal Security Service and the National Criminal Police also discovered that three Russian military intelligence officers were behind cyber attacks against Estonian government agencies (Russian intelligence ramps up cyber pressure on the West, p. 20).
Last year, 637 service disruptions were recorded. These are often not caused by a malicious attack, but by a bug in a device or software or an update error. However, RIA stresses that updating software is very important, as the number of vulnerabilities detected last year also set a record, exceeding 40,000. Technological advances mean that vulnerabilities are increasingly being exploited for attacks (2024 brought a record number of vulnerabilities, p. 34).
CERT-EE is constantly scanning Estonian cyberspace for vulnerable systems, and while in 2023, an alert was sent to 2,427 owners of vulnerable websites or devices, then last year, it was sent to 7,955. Most of the warnings (2,462 of them) concerned the WordPress web management software and its plug-ins, and 263 pertained to the Magento e-commerce platform.
Name servers were targeted
Distributed denial-of-service attacks (DDoS) continue to dominate among politically motivated cyber attacks in Estonia (DDoS attacks: more noise, less impact, p. 26). They attempt to overwhelm the e-services of our public authorities and businesses with mass requests. The number of such attacks increased exponentially after Russia’s full-scale invasion of Ukraine – from 75 in 2021 to 580 in 2024.
In previous years, the main targets of the attacks were web servers hosting the online services of Estonian government institutions and businesses, but last year, attackers zeroed in on name servers that help users access web content. Fortunately, however, the proportion of attacks with an impact has decreased because Estonia has been more successful in repelling the attacks. Even when an attack does have an impact, it is usually limited to slower service performance or a short-lived disruption.
The doubling of the cases of data leaks stands out as a dangerous trend. A total of 68 cases were recorded last year, the most notable being the theft of the data of nearly 700,000 customers of Apotheka, Apotheka Beauty, and Pet City (Lessons from a massive data leak, p. 18). One of the dangers of data leaks is that stolen data can be used to launch new cyber attacks, phishing attempts, and scams.
The Cyber Security Yearbook also provides a brief description of developments in the rest of cyberspace (2024: Events in international cyberspace, p. 36), including Chinese ambitions in cyberspace (The red dragon spreads its wings, p. 40). Brigadier General Oleksandr Potii, Head of the Ukrainian State Service of Special Communications and Information Protection (SSSCIP), talks in detail about the situation on the cyber front in the war with Russia (SSSCIP chief: Russia operates more covertly in cyberspace, p. 16).
The Yearbook also includes a discussion of cyber security in Estonian schools (Estonian schools should prioritise cybersecurity, p. 44), the efforts of RIA to improve the cyber skills of Estonians (Prevention efforts for all generations, p. 48), the cyber initiatives of the European Union (EU steps in cyber security, p. 50), developments in online voting (p. 54), and much more.
You can read as well as download the full Cyber Security Yearbook on the website of the Information System Authority.