At the end of August, Estonian media portals were under assault. Attacks were made against the web portals of Ekspress Grupp, the Postimees, and the Õhtuleht. According to the head of Ekspress Grupp, the attacks in August were more intense than ever before and the company has been under constant attack over the last few years. This was confirmed by the report of the Analysis and Prevention Department of the Information System Authority after comparing the reports of cyber attacks against media portals of the last three years.
Incident Response Department CERT-EE registered 13 incidents in 2020, six of which had an impact, and 11 incidents in 2021, seven of which had an impact. However, by the end of August 2022, CERT-EE had registered 27 incidents, 18 of which had had an impact. During the first eight months of this year, the number of incidents involving media companies has doubled compared to the entire year of 2020 or 2021.
‘One of the reasons for this increase is definitely higher awareness – people and companies are more prone to report cyber attacks with every passing year. Another factor behind this increase is undoubtedly the fact that Estonian media companies, being against Russia’s war, are targeted by pro-Kremlin cyber attackers in the current geopolitical situation. Attacks have become a foreign policy tool for gaining leverage and used when the perpetrators do not like a decision that has been made,’ stated Tõnu Tammer, the Head of Incident Response Department CERT-EE of the Information System Authority.
When analysing this growth trend, we can see that it is supported by the increase in the number of DDoS (distributed denial-of-service) attacks. In addition, more bogus web pages imitating media portals are being created. Such bogus web pages are generally used for financial scams – adding the design elements of news portals is an attempt to create greater trust in a potential victim.
However, the purpose of DDoS attacks is rendering a specific server, service, or system unusable by overwhelming the target with a flood of Internet traffic. ‘Server overload can be compared to a situation where 10,000 people want to enter the same department store at the same time. The store is not ready for so many visitors so it will be shut down, making it impossible for people to access its services,’ explained Tammer.
Attacks against portals are mainly attempts to disrupt their operation. These types of attacks are relatively easy to carry out. ‘If an attack succeeds, all users see it immediately because the web page is no longer available. Therefore, the potential impact of DDoS attacks is relatively huge,’ added the Head of CERT-EE.
In addition to DDoS attacks and bogus web pages, targets are bombarded with phishing e-mails and ransomware attacks. CERT-EE has also recorded incidents over the last three years, related to compromised accounts and data leaks.
‘I would like to recommend to every media company to find ways to defend themselves better in this situation where cyber attacks take place with increasing frequency. We can help them with advice.’ recommended Tammer.
The homepage and the blog of the Information System Authority contain helpful guidelines, recommendations, and posts. The Authority recommends subscribing to the CERT-EE newsletter, which brings the most recent and relevant cyber news from Estonia and the world to the reader every morning. A CERT-EE solution helps defend smart devices from bogus web pages.