The Incident Response Department of RIA (CERT-EE) recorded 383 cyber incidents with an impact in January, which is the highest indicator for the last 12 months. Most of the incidents, as usual, were phishing sites, with 223 detected and blocked. Most common were schemes to steal bank card details, with fraudsters using scam messages sent on behalf of postal and courier companies, for example.
According to CERT-EE, there were 17 denial-of-service attacks (DDoS) with an impact in Estonia during the month, which affected the websites of, for example, the Tax and Customs Board, the National Library, Nordica, and the ERR news portal, as well as the servers of the state IT centres (the Information System Authority, the Information Technology Centre of the Ministry of Finance, and the Development Centre of the Ministry of the Interior). All of their websites and services experienced short-term operational disruptions.
Facebook Marketplace scams, which have been used by scammers for money-making for quite some time, also continued in the first month of the year. The scheme usually works as follows: the fraudster contacts the seller and expresses their wish to buy the goods. The seller is then asked to pay for the delivery of the goods or insure the parcel to verify the transaction and the victim is lead to a phishing page to enter their bank account details. In most cases, a person loses a couple of hundred euros, but at the end of last year, RIA was also informed of a case where the loss exceeded €10,000.
A Tallinn-based company fell victim to a ransomware attack on 18 January. During the attack, the data on the company server was encrypted, including documents, as well as a financial software database. Fortunately, the company had a back-up copy of the most important data. Based on preliminary information, a weakly protected Remote Desktop Protocol (RDP) was used for the attack. In light of this case, RIA recommends reading the 2022 risk assessment (in Estonian), which addressed these risks.
Last month, RIA also led several initiatives to improve the cyber security of Estonia: training was organised for IT teachers of vocational schools and an information day for providers of critical and important services; in addition, the 2023 version of the Estonian Information Security Standard (E-ITS) was completed with a new portal, etc.
The Monthly summary of RIA also provides an overview of activities across the cyber world. Among other things, war-related cyberattacks on a Ukrainian data centre and security cameras are discussed. It also reports a ransomware attack on the Swedish data centre of Tietoevry, one of the largest Nordic IT companies, and on the discovery by software giant Microsoft of traces of a cyberattack on its systems that point to a cyber group linked to Russian foreign intelligence.