According to Märt Hiietamm, Head of the Analysis and Prevention Department of the Information System Authority, the negligence or indifference of Internet users make the life of cybercriminals much easier, and greater awareness of the dangers lurking in cyberspace helps to protect both people and entire systems.
‘After the Russian attack on Ukraine, the already risky cyberspace became noticeably more dangerous. Since March, an average of 100 million malicious requests and attack attempts per month have been made towards Estonian national e-services and systems alone,’ Hiietamm pointed out.
He added that these massive attacks are carried out by thousands of devices that are at the disposal of attackers due to the negligence of ordinary people. ‘Few criminals have the millions of euros necessary to attack technology instead of people. It is much easier and cheaper to take advantage of an unsuspecting person and manipulate them into clicking on a link or entering their data.’
Hiietamm said that finding weaknesses is as easy as looking for lunch in a food delivery app: set your taste preferences and see what is offered to you.
‘There are many pages that display poorly configured servers of companies or home cameras connected to the Internet with just a few clicks. It is all incredibly simple and almost anyone can try and see if they can access the server and the camera. More skilled people can cause a lot of damage this way. The campaign aims to show our people how easy it is to carry out attacks. Fortunately, it is also quite easy to protect yourself,’
said Hiietamm.
In the first nine months of this year, RIA registered half a thousand phishing pages spread via email. In addition, RIA detected the hijacking of nearly 80 social media accounts and 300 instances of financial fraud, in the course of which criminals tried to defraud companies of money with false invoices. 17 companies have reported falling victim to a ransomware attack this year.
Examples of cyber attacks in Estonia this year
- An Estonian company recently fell victim to a ransomware attack four times with different weaknesses being targeted to organise each attack.
- At the beginning of September, a South Estonian company was hit by a ransomware attack, as a result of which the operations of the company were severely disrupted.
- In August, criminals gained access to the email server of an Estonian transport company, but thanks to their quick response, the hackers were unable to encrypt the data.
- In August, data related to the accounts of dozens of Estonian websites was for sale on the dark web.
- In July, the server of a real estate company was hit with a ransomware attack and the data there was encrypted.
- In July, it was discovered that the data of a trading company operating in Estonia is for sale on a website of a criminal cyber group. The data was likely stolen in a ransomware attack.
- In June, a denial-of-service attack was carried out against a bank operating in Estonia, and as a result, the payment service and the internet bank service were disrupted.
- In May, an HR manager of a company received an email in which the criminal pretended to be an employee of the company and asked their salary for the next month to be transferred to another bank account. The HR manager complied with the request and the money was transferred to the fraudster.
- In April, the VoIP app of a hospital was hijacked and used to make a large number of calls to Malawi.
- At the beginning of April, a company in Tallinn fell victim to an invoice fraud and paid the criminals an invoice in the amount of 17,000 euros.
- In March, two Estonian companies were hit by a ransomware attack. The attack was carried out through a solution that allows remote access to the server.
- In February, criminals gained access to the administrator account of an IT company and thus to the systems and email server of the company.
- In January, a company fell victim to a CEO fraud. The company paid the invoice to the criminals and lost 15,000 euros.
The campaign helps to avoid threats
The information campaign Kontrolli üle! focuses on the most common fraud and criminal schemes in Estonia, as a result of which hundreds of companies and people lose money, data, and accounts.
The cyber awareness of Estonian people has improved over the past few years, according to the survey ‘Information technology in households 2021’ of Statistics Estonia, but people who use computers and smart devices on a daily basis still fall into the traps of scammers. ‘Criminals take advantage of every wrong move – clicking on the wrong link, being careless with passwords, or responding to a fraudulent email,’ said the Head of the Analysis and Prevention Department.
‘We call for people to pay more attention on the Internet – for example, which link they click on, whether they use a strong password and where do they enter it, whether they are convinced that the email they received from a friend was really sent by a friend, and whether what they download from the Internet and install on their computer is safe and necessary. These are well-known and small steps, but they are very important from the point of view of security,’ listed Hiietamm.
This campaign is built on the Ole IT-vaatlik campaign from 2019 and emphasises the basics of cyber hygiene, which help keep malware away from computers and phones and protect users from criminals.
The campaign lasts until 20 November and recommendations can be found both on the streets and in the media. The campaign is financed from the state budget and costs approximately 200,000 euros. The partners of the campaign are communication and marketing agencies Nobel, Arena Media, and Agenda PR.
The campaign materials and recommendations are available on the website www.itvaatlik.ee.