The Incident Response Department of RIA (CERT-EE) recorded 522 cyber incidents with an impact in March, which is the highest indicator for the last years. The majority of cases were typically the result of phishing scams, mainly designed to steal bank card details and usernames and passwords.
March saw a significant increase in frauds. There has also been an increase in malicious redirects, with hackers taking over the websites of companies or institutions and redirecting the visitors to, for example, phishing websites. Criminals use hijacked websites in various scams because it makes their activities more difficult to detect and prevent. The takeover of websites is facilitated by unfixed security vulnerabilities.
At the beginning of the month, the cash handling and payment terminal provision company Hansab fell under a cyberattack. Among other services, the company fills the ATMs of Swedbank, Luminor, and LHV. As a result of the attack, Hansab had to temporarily switch to manual operation to ensure its services.
On 9 March, the largest denial-of-service attacks so far were carried out against Estonian public sector websites. More than ten sites were attacked, but the main targets were the Police and Border Guard Board, the Tax and Customs Board, and the Ministry of Justice. In just over four hours, nearly three billion malicious queries were made, resulting in brief interruptions to websites.
During March, there were three interruptions in the operation of the eesti.ee portal, lasting from 15 minutes to a couple of hours. In one case, it was due to a configuration error made during the modification process and in the other case, it was due to an error when changing certificates. On 18 March, from midnight to half past nine in the morning, ID-card authentication was not available in the state authentication service TARA and in the single-sign-on (SSO) service of the state due to expired certificates.
On 4 April, a data leak concerning 700,000 loyalty card owners of Apotheka, Apotheka Beauty, and Pet City was disclosed. In January, a backup copy of a database where information from the years 2014–2020 was stored fell into the hands of a criminal/criminals. Among other things, the personal identification codes of customers, more than 400,000 email addresses, nearly 60,000 home addresses, and around 30,000 telephone numbers were leaked. Data on 43 million purchases were also leaked, but fortunately, this did not include information on prescription medicines.
The RIA monthly summary also provides an overview of RIA’s work to improve cyber security in Estonia and of other developments in the cyberworld.