Tõnu Tammer, Head of Incident Response (CERT-EE) department, Estonian Information System Authority (RIA)
Usually CERT-EE - department of Estonian Information System Authority - registers around ten DDoS attacks in a month. In August we have already seen more than 20 DDoS attacks. We also witnessed a similar increase on 9 and 10 April when the Locked Shields international cyber defence exercise was held in Estonia.
On 17 August, the websites of politsei.ee, cybernet.eu, cr14.ee, valitsus.ee and omniva.ee were targeted, among others, but the attacks did not have an effect or had minimal effect on the functioning of the websites, to the knowledge of the Estonian Information System Authority (RIA). The attack against the website of emta.ee (home page of Estonian Tax and Customs Board) on 17th of August had the most visible effect, with the website being unavailable from 12.30 p.m. to 1.40 p.m. After changing the settings and implementing additional defence mechanisms, it was possible to use the website again. Still, all the services were functional and only the web page was affected.
Based on what is known at this point, the attacks over the last few days were primarily targeted against the clients of the State Network of the Information System Authority. We have to keep in mind that such attacks may last several days and it is quite likely that some websites may not be immediately available at one point or another.
It is relatively simple to organise distributed denial-of-service attacks and such attacks are a daily occurrence in the Estonian cyber space. RIA emphasizes that data confidentiality is not at risk due to the DDoS attacks because attackers cannot access or change the data.
The attacks come from the cyber criminals known to us since spring, but naming the group would give them attention which they do not deserve.
We are also carefully monitoring whether any attempts are made to launch other attacks in the shadow of the DDoS attacks. We remain alert. We actively exchange information with domestic, as well as foreign partners.
Bulk of the web pages that were under attack were not affected because they are using different kind of solutions and defence mechanisms. This is possible because the government has provided us with the means to buy and impliment different tools.
Overview of 18 August
Over the past twenty-four hours, twelve attacks against public authorities or their websites were registered by the department of the Information System Authority in charge of handing cyber incidents (CERT-EE). There were also four attacks against businesses, but these attacks also appear to have been motivated by an intention to attack certain public services.
Eight of the DDoS attacks targeted a specific website and the same number of attacks attempted to clog up data exchange channels.
No impact was observed in the case of nine of the attacks, while seven attacks may have caused a service interruption.