In September, Innovaatik, a company providing information system services to dental care providers, announced that there had been repeated unauthorised access to the computer system it manages and that patients’ personal data, including health data, had been downloaded from it. The police arrested a 45-year-old Estonian national, who had previously been associated with the company, on suspicion of the criminal offence.
‘Health data is highly sensitive, and security must be maintained at a consistently high level when processing it. This incident demonstrates once again why it is important to restrict access to data in line with actual needs, to keep systems up to date, and to detect unusual activity quickly,’ said Dorel Kiik, an analyst at the Analysis and Prevention Department of RIA.
On 11 September, the University of Tartu discovered that attackers had gained access to the online bookshop of the university. It is highly likely that customer data was downloaded from there. According to initial reports, the attacker gained access to the site via an unpatched security vulnerability. After the attack was discovered, the university closed its e-bookshop in order to clean up the system and rectify the vulnerabilities.
At the beginning of last month, there were denial-of-service attacks against Estonian websites. The targets of the attacks included the banking, healthcare, energy, transport and water sectors, as well as the websites of government agencies and political parties. There were some brief delays or interruptions in the operation of a few websites, but the attacks had no significant impact. On 11 September, a distributed denial-of-service attack also hit the national authentication service. During this attack, over 86 million queries were made to the service – more than a hundred times the usual volume.
‘The aim of denial-of-service attacks is to overload services with a large volume of requests and render them inaccessible to users. The incidents in September showed that the scale of attacks can be very large, but properly implemented defences are capable of blocking the majority of malicious traffic,’ said Kiik.
In September, a configuration error that occurred during scheduled maintenance work caused disruptions to the services provided by the IT and Development Centre of the Ministry of the Interior. Among other things, the disruption affected the operation of the administrative sector’s websites and calls to the emergency number 112, resulting in longer than usual waiting times.
The operation of the national authentication service was also disrupted on several occasions during the month, causing users to experience problems logging in to a number of government e-services. The causes of the faults are currently being investigated.