The Incident Response Department of RIA (CERT-EE) registered 309 cyber incidents with an impact during the month. The majority of the incidents, as usual, were phishing sites, with 185 detected and blocked. Most common were schemes to steal bank card details, with fraudsters using scam messages sent on behalf of postal and courier companies.
During the automated monitoring, CERT-EE also found 1,204 malware-infected devices and reported them to telecommunication companies. This was the highest number recorded this year.
In December, Estonia’s largest ever data theft was made public. The personal and health information of about 10,000 people was downloaded from the database of the genetic testing company Asper Biogene and a financial claim was made against the company. The case was investigated by the Data Protection Inspectorate, the police, and the prosecutor’s office.
On 12 December, the remote control equipment of a boiler house in Rapla county was attacked. As a result of the attack, the main boiler was shut down for a whole day and a lower-capacity backup boiler was put into operation. The local school, community centre, and care home depend on this boiler house.
Equipment manufactured by the Israeli company Unitronics was also hit at the end of November, when the controls of eight boiler plants and ten pumping stations in Estonia were knocked out, but there was no threat to heating and water supplies. Similar politically motivated cyber attacks took place in other countries around the world.
The fact that the devices were often publicly available on the internet and their factory default settings were unchanged made them vulnerable to attack. In the Rapla County case, the device was removed from the web after warnings following the first wave of attacks, but was put back online a few weeks later. In its threat assessment (in Estonian) RIA stressed that if remote management is necessary, at least a firewall and VPN connection should be used.
On 7 December, a printing company fell victim to a ransomware attack: the Babuk ransomware encrypted a large part of the files and the operation of the company was partially shut down. The server of a state authority was attacked last month via an unpatched vulnerability in Atlassian Confluence. In light of this case, RIA reminded that unpatched software is one of the most common attack vectors.
There were also three major disruptions to online services in Estonia in December. In the early hours of 14 December, the border control information system PIKO, the police tactical management database KILP, and the e-police information system Apollo did not function for 45 minutes. The interruption was caused by a failure in the firewall of the Centre for Information Technology and Development of the Ministry of the Interior (SMIT).
On 15 December, during 20 minutes, there were disruptions in the operation of Elisa’s Mobile-ID, which may have caused problems with entering internet banks and other e-services and giving digital signatures. On 22 December, the following services of the Health Insurance Fund were interrupted for nearly two hours: the health insurance check, incapacity for work benefits, medical billing, etc.
In addition, the monthly summary provides an overview of RIA’s work to improve cyber security in Estonia and of other developments in the cyberworld. For example, in cooperation with Clarified Security, RIA organised the cyber security exercise DigiTorm for the employees of three major telecommunication companies to share knowledge on how to strengthen their infrastructure and to practise working together to deal with potential attacks. Meanwhile, in Ukraine, the country’s largest telecommunication company Kyivstar was hit by a cyberattack claimed by a cyber group linked to the Russian military intelligence agency GRU.