The Incident Response Department of RIA (CERT-EE) registered 337 incidents with an impact in October. The majority of incidents, as usual, were phishing sites with 178 detected. The automated monitoring also found 1,282 malware-infected devices, which were reported to the owners of the communication networks. Both indicators were at their highest levels in half a year.
Among the more significant service disruptions, RIA pointed out that on 3 October, due to systems overload, the basic services of the Health Insurance Fund were disrupted for nearly an hour and a half: digital prescription, insurance verification, etc. The ehr.ee website of the national building register was down for almost a day on 6 October for an unknown reason.
On 11 October within two and a half hours, the call centre service of Telia was disrupted – several services were down, including the national information line 1247 and the general practitioner information line 1220. The emergency line could be called, but there were problems when the emergency call centre tried to call the caller back. The incident was caused by a network failure.
October also saw several major waves of denial-of-service attacks, with attempts to overload websites and services with mass queries. Many Estonian state and educational institutions, as well as private companies, were targeted. The attacks on 23 October had a greater impact, with some websites also unavailable for some time.
Last month, a large company in Tallinn fell victim to a ransomware attack, which encrypted data on two servers with malware. The attackers used an accounting firm and hacked into its system via Remote Desktop Protocol (RDP) to reach the final target. The industrial company had fresh backups of locked data from which the systems could be restored. According to preliminary information, no data was stolen in the attack.
On 16 October, a critical security flaw in the Cisco IOS XE networking software was discovered, allowing an attacker to gain full control of an infected device. At least 130 devices in Estonian cyberspace were also affected by the vulnerability according to CERT-EE. RIA therefore published threat assessment (in Estonian) and worked with a number of partner agencies to mitigate the impact of the vulnerability.
October is also Cybersecurity Month and this year, RIA carried out an information campaign called ‘Lead IT Carefully’, targeting small and medium-sized enterprises. Surveys carried out by RIA and Statistics Estonia show that smaller companies train their employees on cyber threats much less frequently than large companies. They are also not in the habit of planning large investments in cyber security. This is why small businesses are also at a higher risk of becoming victims of a cyber-attack.
In addition, you can read about other RIA’s efforts to improve cyber security in Estonia in the monthly summary. It also includes an overview of what is happening elsewhere in the cyber world: a €100 million ransomware attack in the US, the growing role of governmental groups in cyber-attacks, the activities of Russian hackers against Ukrainian telecom companies, and the wave of hacktivism accompanying the Hamas attack on Israel.