The Incident Response Department of the Information System Authority (CERT-EE) recorded 438 cyber incidents with an impact in June, which is slightly above the average for the last six months. During the first six months of this year, there were 2,607 incidents with an impact, or twice as many as during the same period last year (83% increase).
The situation in cyberspace is characterised by the spread of cheap mass attacks and data phishing; one resource that can help combat these threats is the ABCs of cybersecurity of the Information System Authority. In June, most of the incidents with an impact, as usual, were related to phishing sites, with 256 detected and blocked. People are directed to such fake websites through scam messages sent posing as courier companies to coax them into revealing bank card details and other data, for example.
In addition, malware has been spreading much faster lately: the automated monitoring of CERT-EE found 2,710 infected devices in Estonian cyberspace in June and reported them to network owners. This is a 25% increase compared to six months ago and about five times as many as in the same month in 2023.
Significant service interruptions
One of the service disruptions with a big impact, mentioned in the monthly report of the Information System Authority, was the interruption of e-services provided by TEHIK to the social services sector, which took place on 4 June between 8 a.m. and 3 p.m. It was caused by a software malfunction in a network device. The incident also interfered with the activity of ambulance crews, but fortunately, no issues occurred with responding to emergencies and the work of the Emergency Response Centre was able to continue. Due to a malfunction in the firewall of a service provider, the main services of the Health Insurance Fund were not available for about 20 minutes around lunchtime on 28 June.
Late at night on 11 June, there was a few failure in the Mobile-ID services in Estonia and Lithuania. As a result, problems occurred when using Mobile-ID to log into internet banks and other e-services and give digital signatures. In the morning of 20 and 21 June, the Smart-ID service (another authentication service provided by SK ID Solutions) was hit by denial-of-service attacks, disrupting the use of the service for a couple of hours on both days.
Cyberattacks against universities
Estonian universities fell victim to two cyberattacks. On 4 June, 1.5 terabytes of data were encrypted in the server of the Tallinn Health Care College. The server was used for storing the files of university staff and students and the incident impacted approximately 200 people. By the following day, the services were restored from a backup.
On 18 June, the Ministry of Education and Research, which manages the Moodle educational environment, discovered that the Moodle of TalTech had been breached. The attackers mapped its intranet and attempted to access other computers located there. The precise circumstances of the incident are still under investigation. However, no personal data was leaked or data loss occurred according to an analysis of the ministry. The possible motive for the attack was mining cryptocurrencies.
In the light of incidents involving universities, the Information System Authority recommends a critical inspection of the administration of user accounts, avoiding the use of outdated software, and not allowing unrestricted access to service environments from the internet unless absolutely necessary.
Other important topics in Estonia and abroad
In June, the Information System Authority helped ensure that the information systems for the European Parliament elections were ready and secure and provided technical support for these. The organiser of the elections, i.e. State Electoral Office of Estonia, was satisfied with the service the authority provided. Both online voting and the election information system functioned without any major problems and the situation in cyberspace was very calm. At the beginning of the period of online voting, there were issues with downloading the voter app from the website of the Electoral Office (valimised.ee) with the Chrome and Firefox web browsers, and the automatic identification of operating systems of the visitors was not functional.
The monthly summary also provides an overview of the efforts of the Information System Authority to improve cybersecurity in Estonia. Among all else, a new online course was published on the Digiriigi Akadeemia platform in June, introducing the best practices for outsourcing IT services. In addition, a new version of Cyber Test for improving the cyber awareness of organisations and their staff was completed.
Summary of international incidents discusses, among all else, how cyberattacks related to military activities continued in Ukraine, work at London hospitals was disrupted by a ransomware attack, and the data of nearly a thousand European and UK politicians was made available in the dark web.
Read more about these and other topics in the monthly review of the situation in cyberspace by the Information System Authority.
Read more about these and other topics in the monthly review of the situation in cyberspace by the Information System Authority.
June in cyberspace: attacks interfered with an authentication service and the work of universities
12.07.2024 | 10:59