September in Estonian cyberspace: people lost thousands of euros due to phishing

10.10.2024 | 09:36

The monthly overview of the Information System Authority (RIA) states that in September, many lost large amounts of money as a result of phishing emails sent under the name of the bank LHV and several essential online services experienced failures.

In September, the Incident Response Department of the Information System Authority (CERT-EE) recorded 512 cyber incidents with an impact that resulted in people, public authorities, and companies losing their data or money or in disruptions in the work of information systems. During the first nine months of the year, the number of recorded incidents with an impact reached 4,292 – 87% more than during the same period last year.

Over half of the incidents with an impact were phishing attacks. Phishing emails sent posing as LHV continued their massive spread in September, asking clients to update their information. The emails were sent from suspicious email addresses not belonging to the bank.

The emails contained a link that directed readers to enter their bank card details. Unfortunately, many people fell for the scam, and in some cases, the damage exceeded 10,000 euros. RIA would like to remind you that banks do not send such emails or ask for your data through unknown websites. Whenever information must be updated, they send a notification through their internet bank and the data must be updated in the same environment as well.

Lately, RIA has been notified of instances where the Booking.com platform, which mediates accommodation services, is used for attempted scams. An article published in the RIA blog explains in greater detail the steps to take to avoid falling victim to fraudulent activity.

Several high-impact service outages

The monthly summary of the Information System Authority also states that several essential online services faced disruptions in September. On 5 September, voice communication in the Telia network faced failures for nearly one and a half hours, and calls to the emergency number 112 were also disrupted for about an hour. The failure was caused by a software error in the voice communication system.

On 7 September, issuing ID cards was disrupted for four hours because of the inability to validate their certificates. The issue was caused by a configuration error made by the IT and Development Centre of the Ministry of the Interior (SMIT) during maintenance. In the early hours of 17 September, the core network of SMIT experienced data communication failures during maintenance, leading to interruptions in many services, lasting for hours. This included the emergency notification system used by the Emergency Response Centre for processing calls.

In the morning of 16 September, over 200 websites were down for about two hours in Estonia. Among others, several essential pages were unavailable, such as the state authentication service tara.ria.ee. The issue was caused by a malfunction in the data centre of a company that provides protection against denial-of-service attacks. In the afternoon and evening of 26 September, the card payments and internet bank of Swedbank experienced disruptions.

Cyber ​​Security Month helps refresh knowledge

The monthly summary also provides an overview of the efforts of the Information System Authority to improve cybersecurity in Estonia. Among all else, ETV is going to broadcast a TV programme called IT-vaatlik (IT-conscious) every Monday starting from 30 September, discussing cyber threats that people face and how to avoid them. In addition, instructional materials on online safety for children aged 7–11 and their parents were recently published, and 25 free workshops for middle-aged and older people (55+) are going to take place all across Estonia, where the participants can learn to protect themselves better in cyberspace.

Among the news regarding other events in the cyber realm, the monthly summary of RIA describes a cyberattack against the car rental company Avis, an attack of Ukrainian hackers against a Russian national authority called Osnovanie, and an international police operation that managed to shut down an encrypted communication environment called Ghost that was used by criminals.

ARNO PÕDER

Communications Specialist

open graph imagesearch block image