In October, the Incident Response Department of the Information System Authority (CERT-EE) recorded 658 cyber incidents with an impact that resulted in people, public authorities, and companies losing their data or money or in disruptions in the work of information systems. During the first ten months of the year, the number of recorded incidents with an impact reached 4,950 – 88% more than during the same period last year.
The majority of incidents in October were related to phishing sites with 377 detected. CERT-EE restricts access to malicious sites, informs web hosts about them, and shares information with its international partners. As usual, emails and text messages sent on behalf of courier companies were the most common method, directing people to a phishing page to renew their address or pay a postage fee, thereby giving cybercriminals access to their bank account details and PIN codes.
Many people fell victim to phishing schemes on Facebook Marketplace. The scheme works as follows: the fraudster contacts the seller and expresses their wish to buy the goods. The buyer offers to use a courier service to collect the goods. The seller is then asked to pay a delivery fee or insurance to verify the transaction and is lead to a phishing site to enter their bank account details. Among others, a person who was trying to sell a fridge recently lost €3,900 and a person selling shoes lost €1,400.
Top cyber incidents of the month in Estonia
Among the more significant cyber incidents, the monthly summary highlights problems with the automated border control system, or ABC gates. On 2 October, the gates used for the verification of documents did not work for five hours, disrupting the work of Tallinn Airport and the border crossing points of Saatse and Narva. The exact cause of the incident is not yet known, but there is no reason to suspect an attack.
On 4 October, the email addresses of 350 people who had wished to test the state mobile app Eesti.ee were leaked, as the email sent by RIA’s development partner displayed all the addresses due to a human error. On 7 October, the Russian language proficiency test had to be cancelled in schools due to technical problems with the Examination Information System.
On 19 October, an unknown person logged into the Estonian Public Broadcasting’s FTP server, which is used to exchange files with partners, deleting the files and replacing them with malware. A weak password was used to protect the compromised account. Fortunately, it was possible to recover the deleted files. In light of this incident, RIA recommended everyone to review their password policy and use two-factor authentication wherever possible.
In addition, the monthly summary provides an overview of RIA’s work to improve cyber security in Estonia and of other developments in the cyberworld. For example, it covers denial-of-service attacks by Russian hacktivists targeting Japanese government agencies and logistics companies and a recent Microsoft report, according to which Russia, China, and Iran are increasingly collaborating with criminal groups in cyber operations.