RIA: The number of cyber attacks in 2022 was a hundred times higher than during the April Unrest

06.02.2023 | 12:52

In 2022, 2,672 cyber incidents occurred in Estonian cyberspace, which affected Estonian people, businesses, and services. The use of denial-of-service attacks grew most – such attacks are increasingly being used as a foreign policy tool.

According to Kristjan Järvan, Minister of Entrepreneurship and Information Technology, last year was a reminder that freedom, independence, and a sense of security cannot be taken for granted.

‘The war in Ukraine has painfully shown that cybersecurity is one of the cornerstones of national security. Activity in cyberspace takes place not only during physical military activity, but also before and after it. As a result of the daily efforts of thousands of people, Estonia has become one of the most advanced digital states in the world, offering hundreds of high-quality e-services. However, that also makes us a unique target,’ said Järvan.

The minister added that we are facing an ever-changing threat landscape in cyberspace, which means a risk-based response both in the information security of organisations and in national security. ‘There is no service in Estonia that does not depend on digital components in one way or another. Cybersecurity is an integral part of comprehensive national defence, and the war in Ukraine shows that for a state to function even in the most critical situations, we must be able to protect vital information systems that ensure, for example, water supply, mobile phone coverage, or heating,’ Järvan said.

He pointed out that there was a surge in the intensity of cyber attacks against Estonia last year, but Estonia has coped with it well and most of the attacks have remained no more than attempts.

‘Our goal must be a thoroughly cyber-secure Estonia that is able to adapt effectively to technological developments and new potential threats. Therefore, channelling further investments in cybersecurity and improving cooperation is key. A good example of this is the government’s decision to allocate €42 million to the core budget each year. It is important to learn and to spot, adapt, and react in time, because the attackers will do exactly the same,’ the minister stressed.

‘A year ago, we predicted that if Russia were to attack Ukraine, Estonian cyberspace would come under much more fire. Unfortunately, both the theory of invasion and our prediction were correct. Since 24 February, we have practically been in a cyber war, with attacks and attack attempts taking place almost every day or week. We have seen on many occasions that attacks designed to disrupt services followed the speeches and published positions of Estonian leaders and politicians. In August, when the tank monument was moved from Narva, a record 66 denial-of-service attacks were launched against Estonia. Because of good preparation, they had no noticeable impact, although the attackers learned and developed throughout the year. There is a clear contrast between the attacks at the beginning and the end of the year,’ said Margus Noormaa, Director General of the Information System Authority (RIA).

He added that similar increases were also seen when the Riigikogu declared Russia a terrorist state and when the Ukrainian president addressed members of parliament via video. The impact of the attacks on Estonian organisations, institutions, and businesses was marginal, but disruptions did occur.

‘Thanks to the government’s financial boost, we were able to stay one step ahead of the attackers and were able to put up defensive solutions just before the mass attacks. Without additional measures, the outcome would have been very different,’ Noormaa stressed. Similar attacks are continuing this year – the latest major wave started on 23 January, when the financial and insurance sectors were targeted.

Noormaa added that RIA helps to ensure that the digital state works in the public sector, and that it cannot reach everywhere.

‘Our monitoring finds hundreds of vulnerabilities or virus-infected devices every day. We immediately pass this information on to service providers whose customers are at risk. My urgent request is that this information on vulnerabilities is passed on to clients. It is much cheaper to learn from the mistakes of others instead of your own. If our warnings are not acted upon, it is not uncommon for our advice to be sought after a cyber incident has already devastated a business,’ said the Director General of RIA.

Last year, RIA received information on 2,672 cyber incidents with an impact (about a fifth more than in 2021). Phishing pages collecting data (1,206), disruptions of service (344), and account takeovers (236) were the most frequently identified and reported. Fraud was reported 224 times and compromised data 164 times. Last year, 302 denial-of-service attacks were reported to RIA, of which 100 were effective, and 21 ransomware attacks were reported.

The RIA Cybersecurity Yearbook focuses on incidents and statistics in Estonian cyberspace. It includes discussions on denial-of-service attacks, Russian cyber attacks against Ukrainian institutions and businesses, ransomware attacks, security vulnerabilities, protecting elections, and online fraud. There are also stories on how to make Estonia comprehensively cyber-secure and on the biggest cyber attacks in the world last year.

SEIKO KUIK

Press Officer

open graph imagesearch block image