On Monday, 4 September, Estonian businesses and institutions were hit by another major wave of denial-of-service (DDoS) attacks, with attempts to clog up websites with mass requests. A few dozen websites were attacked in various sectors, including government agencies, think tanks, logistics companies, and energy companies. Most of the attacks were ineffective, but the websites of an insurance company and a company in the aviation sector experienced a brief disruption.
The Incident Response Department of RIA (CERT-EE) has also been notified of the defacement of at least three websites during this wave, targeting a catering company, a museum, and a logistics company. The defacement of a website means exploiting weaknesses in the website, such as outdated software, breaking into the site, and displaying a message about a successful hack.
The impact of the current wave of attacks has so far been small. As a result of previous attacks and threat assessments, most of the pages important for the country and society now have additional protection measures in place, making them more resilient to attacks.
However, RIA says that this wave is noteworthy, as attacks have become more diverse, with attackers looking for new ways to gain visibility, fame, and publicity. There are also reports of DDoS attacks as well as website defacement in Latvia and Lithuania.
According to RIA, any online service or website can be the victim of an attack. The data of CERT-EE shows that small businesses or websites of marginal importance also get attacked due to their often low security.
There is also a risk of some service providers getting attacked, thereby spreading the impact to their customers. For example, a portal offering online services to local authorities was hit by a DDoS attack this week.
RIA’s recommendations for service and website owners*:
-
Do not use outdated or unpatched software for your website or service.
-
Be prepared that your service or website could also be the target of a cyber attack. Evaluate how a potential attack would affect your business and what the optimal defensive measures would be.
-
Check with your ISP and web host to find out what safeguards they have in place centrally and what additional measures they can take in the event of an attack.
-
Implement a strong password policy in your website management: strong passwords, two-factor authentication.
-
Check who has administrator rights to your website and whether they are justified in any case.
-
Take a look at your website plugins and assess their necessity and relevance. Plugins with security vulnerabilities are one way to hack websites.
-
Know how your website or service works – whether and what you should restrict access to should you come under attack.
-
Perform regular vulnerability scanning of your open service or website. Cybersecurity companies offer a range of automated tools for this purpose, with simpler versions often offered free of charge. If you need advice on finding the right service, please contact [email protected].
-
CERT-EE’s technical guidance on preventing and responding to denial of service attacks (in Estonian)
* These recommendations do not focus on providers of critical services and services critical for the state, who are under increased scrutiny by CERT-EE and have received more specific guidance