Ransomware attacks have become more brutal

14.07.2020 | 13:39

The review of the cyberspace of the Information System Authority (RIA) in the second quarter shows that the tactics of ransomware attacks have become increasingly brutal, because in addition to encrypting data, it is also stolen and threatened to be disclosed.

According to Märt Hiietamm, Head of the Analysis and Prevention Department of the Information System Authority, all agencies should realise that in the event of a ransomware attack, the data on their devices is not only encrypted, but often also stolen and disclosed. Therefore, backing up data is not enough to combat ransomware attacks. ‘Important and sensitive data must always be backed up and encrypted, and it must be ensured that the backups are not on the same data medium as the original data. It is also important to use the latest version of any software and train your staff so that they are aware of the dangers and can protect themselves from cyber attacks,’ Hiietamm emphasised.

Due to the emergency situation in the spring, people were left to work and study at home, which meant that they urgently needed to create new accounts on several platforms. However, little attention is often paid to creating passwords for new accounts, and existing passwords are used instead. Therefore, a password leaked from one environment may also compromise a person’s accounts created in other environments.

‘We are constantly seeing extensive data leaks, from airlines to children’s virtual playrooms. It is probable that as a result of the data leak of the British airline Easyjet in May, the personal and banking information of several Estonian residents was also endangered. Therefore, we consider it necessary to once again emphasise the importance of unique and strong passwords,’ said Märt Hiietamm.

In the context of the following overviews, it is important to point out that from July, the Information System Authority will stop reporting infections with the robotic networks Avalanche and Necurs in the list of CERT-EE incidents and in the reports to be sent out. The Avalanche botnet was shut down as a result of an international police operation already in December 2016 (but infections continued later), and Microsoft gained control of the Necurs network in March 2020. Thus, it can be estimated that these two networks are no longer actively threatening cyberspace.

However, this does not mean that CERT will no longer deal with these infections. On the contrary – CERT is sending out more and more notifications about infections with botnets (and other malware). The change in the coverage of Avalanche and Necurs infections will initially be reflected in a sharp decline in incidents (estimated at 50–60%), but as a result of the change, our incident statistics will reflect the real risk picture more clearly.

Kertu Kärk
Head of the Communication Department
Information System Authority

Riigi Infosüsteemi Amet

open graph image