The RIA monthly summary provides information on several cases with an impact. For example, on 1 December, a family medicine centre announced that it had fallen victim to a ransomware attack. During the incident, data on two servers and backups were encrypted. The most recent backup that the attackers were unable to access was from 2021. The encrypted server contained patient data, medical records, and appointment times, meaning that the attack completely halted the work of the family medicine centre. CERT-EE was able to recover some of the encrypted data.
On 5 December, Cloudflare’s systems suffered a failure, resulting in numerous Estonian and global websites and services becoming inaccessible. The cause of the outage was a change they made to their virtual firewall in response to a recently discovered security vulnerability, which resulted in a technical glitch.
On 9 December, the security and access control system server of a rural municipality government was attacked. The server was accessed via a service provider’s account, which was taken over through phishing. The compromised account was closed within a few minutes and, based on the information available to RIA, the attackers did not have time to cause any significant damage.
On 10 December, there were disruptions in the operation of the identity verification and procedural information system UUSIS of the Police and Border Guard Board, which also disrupted the work at the offices of the institution. The disruptions were caused by server overload.
On 12 December, train ticket sales and timetable searches were unavailable on the websites elron.ee and pilet.ee. The interruption was caused by a failure in the systems of Ridango, the company that manages the ticket sales environment.
On 17 December, failures occurred in the operation of RIA’s services, including the state portal eesti.ee, the national authentication service TARA, and X-tee services. The failures began after a change was made at the data centre and were caused by a configuration error.
International situation
There was no Christmas peace to be found in cyberspace elsewhere in the world, either. For example, University of Sydney announced that the personal data of approximately 27,500 former and current employees, students, and alumni had been leaked from their information system.
On the weekend before Christmas, a ransomware attack hit Romanian Waters, the company that manages Romania’s national water supply, taking more than 1,000 servers and workstations offline.
The German government announced that it has found conclusive evidence linking APT28, a threat actor with Russian state backing, to cyber attacks against the German air traffic control centre in August 2024. The Danish intelligence service disclosed that the cyber attack against a local water company at the end of 2024 was carried out by the Russian hacktivist group Z-Pentest. The United Kingdom imposed sanctions on two Chinese technology companies that have carried out cyber attacks against government agencies and private companies in the United Kingdom and many other countries.