In November, the Incident Response Department of the Information System Authority (CERT-EE) recorded 647 cyber incidents with an impact that resulted in people, public authorities, and companies losing their data or money or in disruptions in the work of information systems. During the first 11 months of the year, the number of recorded incidents with an impact reached 5,597 – 86% more than during the same period last year.
The majority of incidents with an impact were related to phishing sites with 434 detected. Many people again fell victim to phishing messages sent on behalf of banks and courier companies, losing hundreds or even thousands of euros to cyber criminals. CERT-EE restricts access to these sites, informs web hosts about them, and shares information with its international partners.
Among the notable cyber incidents, the monthly review highlights the malware attack that was carried out against a dental clinic on 1 November, encrypting the data on its server – mainly X-ray images. The clinic did not have a working backup, meaning the data could not be restored. The attack originated via an open remote desktop (RDP) connection with an easy password. In light of the incident, RIA recommends reviewing both the services available online and password policies.
On 17 November, the website of the Consumer and Technical Regulatory Authority ttja.ee was hit by a denial-of-service attack. As a side effect, there were outages for seven minutes on a total of eighteen state agency websites managed by the Information Technology Centre of the Ministry of Finance. CERT-EE and RIA name servers were actively attacked in both October and November, but these attacks generally had no impact.
In November, we recorded four successful cases of invoices fraud, which resulted in losses of up to 300,000 euros for Estonian companies. Invoice fraud means that an invoice (where usually only the bank account number has been changed) is sent to an institution company on behalf of its partner. Fraudsters who have infiltrated the email system usually monitor the communication between the two parties for some time and then intervene at the appropriate moment.
How to do your Christmas shopping safely?
With the Christmas shopping approaching, RIA has published advice on safe shopping in online shops. It is definitely worth looking into the background of the online shop and the experiences of other users and, if possible, avoid paying for purchases by bank card and instead use a bank link or other secure payment methods.
You can also find an overview of other activities carried out by RIA to promote cyber security in Estonia. Among other things, a series of workshops started on 21 November, where local governments and educational institutions will be introduced to the practical use of the Estonian Information Security Standard (E-ITS) to improve their cyber security.
Internationally, the November overview highlights the cyber attacks on hospitals in the UK and France, and the actions of pro-Kremlin hacktivists against South Korean websites. In addition, the overview covers the fact that Chinese hackers managed to infiltrate the systems of US telecoms companies and steal information on the activities of law enforcement agencies, as well as gain access to the devices of some government officials and top politicians, from which data was stolen.
Read the full ‘Situation in Cyberspace’ overview on our website.