End of the year in Estonian cyberspace: fraudsters were exceptionally active over the Christmas period

10.01.2025 | 15:55

According to the monthly summary of the Information System Authority (RIA), 735 phishing and scam websites were detected in December 2024, which is almost twice as many as in previous months.

Among the notable cyber incidents, RIA highlights a ransomware attack that hit an education company on 2 December. In the course of the attack, the attacker encrypted the data of the company in the Amazon cloud environment and demanded a ransom for the restoration of the data. The data in question was not personal data or business-critical data and as a result, the company accepted the loss. The attack was possible due to the misuse of an account with excessive rights.

In the morning of 9 December, it was not possible to buy tickets in the city buses in Tartu. The electronic displays of the buses indicating the number of the line and the information screens at the bus stops were also not working. The interruption was caused by the systems of the company providing the service to the public transport system of Tartu running out of disc space.

In the morning of 10 December, a commercial bank experienced short-term disruptions in its services due to a denial-of-service attack. In the afternoon of 16 December, Smart-ID authentication and signing was unavailable for about an hour. This was due to a technical problem that occurred for the service provider after executing scheduled changes.

RIA also received reports in December that several dozen former employees of a state authority still had email accounts of the authority and that some of the accounts with administrative rights of former employees were still active. The impact and specific circumstances of the incident are still being investigated.

Hundreds of phishing and scam websites found

In December 2024, the Incident Response Department of the Information System Authority (CERT-EE) recorded a total of 920 cyber incidents with an impact that resulted in people, public authorities, and companies losing their data or money or in disruptions in the work of information systems. The majority of cases were phishing and scam websites, with a record 735 detected. CERT-EE restricts access to malicious sites, informs web hosts about them, and shares information with its international partners.

Among other things, in December, large amounts of emails sent posing as the bank LHV were sent, asking customers to log in to their internet bank and update their data. Unfortunately, many people fell victim to fraud: they entered their details on a seemingly trustworthy-looking fake bank page and lost hundreds or even thousands of euros to cybercriminals.

There has also been a recent proliferation of fraudulent website inviting people to invest in cryptocurrencies and the stock market, to take out loans on very favourable terms, or benefit from legal loopholes. 

RIA’s monthly summary ‘Situation in cyberspace’ also gives an overview of recent efforts to improve cyber security in Estonia. Among other events, the RIA hosted a major exercise of the country’s IT houses, the Baltic cyber security centres organised the innovation forum CyberBazaar, and the updated prevention portal itvaatlik.ee was launched.

Elsewhere in the cyber world, the monthly summary highlights the annulment of the results of the Romanian presidential election, which was linked to a Russian influence campaign. There is also a report on malware created by an Iranian cyber group, a cyber attack on the databases of the Ukrainian Ministry of Justice, and the plan of the US to ban routers from the Chinese manufacturer TP-Link.

ARNO PÕDER

Communications Specialist

open graph imagesearch block image