According to the monthly overview of the Estonian Information System Authority (RIA), 1,121 cyber incidents with an impact were recorded in Estonia in January. The majority of cases were phishing and scam websites, with a record number detected and blocked.
In January, 338 phishing scams, mainly designed to steal bank and other user data, and 592 different types of fraudulent websites were discovered. The latter are used, for example, in investment scams, as a result of which Estonians lost nearly five million euros last year, according to the police. RIA has also recently published recommendations on how to recognise and avoid investment fraud (in Estonian) on its itvaatlik.ee website.
Soon, it is time to file income tax returns in Estonia, and as early as in January, scam messages and emails sent posing as the Tax and Customs Board began to circulate, claiming that the recipients could expect an annual tax refund. This incident was special because the recipients were directed to open a link via a QR code. For more detailed advice on how to spot fraud, please visit the website of the Tax and Customs Board (in Estonian).
In January, people in Estonia also continued to receive phishing emails sent purporting to be LHV Pank, inviting them to update their details. Unfortunately, some of the recipients entered their details on the phishing site and lost the money they had on their bank accounts – in some cases, the losses amounted to several thousand euros.
Major cyber incidents in January
Among notable cyber incidents, RIA highlights two cases of using VPN device vulnerabilities for penetrating government systems. A critical vulnerability in the Ivanti Connect Secure software was used for the attack, which was made public on 8 January. In Estonia, the incidents are known to have started in late December and they were discovered in early January. However, they did not cause any serious damage.
One of the signs of abusing this particular vulnerability is an interruption in the transmission of system logs. Vulnerabilities in the Ivanti software have also been used against Estonian state institutions in the past, which is why RIA has stressed the importance of the continuous monitoring of systems and patching vulnerabilities as quickly as possible.
On 2 January, the automatic border control system, the ABC gates, at Narva and Saatse border crossing points and at Tallinn Airport were down for two hours due to the expiry of a certificate. On 8 January, messages could not be modified or recorded in the SIRENE information system of the Police and Border Guard Board due to a configuration error.
On the evening of 3 January and the morning of 4 January, a commercial bank operating in Estonia was hit by a distributed denial-of-service attack (DDoS), resulting in short interruptions in the operation of their internet bank. In January, DDoS attacks against the name servers of CERT-EE, RIA, EEnet.ee, and the Ministry of Foreign Affairs continued, but thanks to protective measures in place, they failed to cause any harm.
On the morning of 31 January, the prescription list service of the Health Insurance Fund experienced disruptions for a period of two hours. The cause of the incident is not yet known, but it was resolved by the withdrawal of an upgrade.
User support for a number of important software products will end
In January, RIA published in its blog an overview of the most important software programs (in Estonian) ending their official user support in 2025 – the most common among them is definitely Windows 10. At this point, the users of these programs still have time to take steps to ensure that they are protected from security threats after the end of the technical support.
The monthly overview of RIA also includes a description of what is happening elsewhere in cyberspace: Ukrainian hacker group penetrated the network of a Russian telecom called Nodex, stole its data, and destroyed its systems; a UK domain registry called Nominet fell victim to an Ivanti vulnerability; and a border control system used by German airports suffered a major IT outage. In many countries, questions have been raised about the security of the Chinese-made DeepSeek artificial intelligence and RIA’s blog (in Estonian) also contains a short article on it.