There were two major waves of malware and phishing emails in Estonia in February

11.03.2024 | 18:45

The monthly summary of the Information System Authority (RIA) reveals that in February, there were two large waves of phishing emails and emails with malware sent on behalf of businesses and several state agencies had to deal with technical problems and cyber attacks, which sometimes disrupted e-services.

The Incident Response Department of RIA (CERT-EE) recorded 439 cyber incidents with an impact in February, which is the highest indicator for the last 12 months. The majority of cases were typically the result of phishing scams, mainly designed to steal bank card details and usernames and passwords.

On the morning of 23 February, letters in error-riddled Estonian started arriving in many people’s mailboxes, calling for the renewal of domain names. The emails were ostensibly sent from Zone Media OÜ, included a fake Zone web link, and attempted to obtain usernames and passwords. The emails were sent from random addresses, which made it possible to tell that they were not legitimate.

At the same time, emails sent on behalf of Tallink were also circulating, with a malware-infected file attached. Once again, the letter was sent from a random address and claimed to have an order attached. Such emails should be forwarded to the CERT-EE team for investigation ([email protected]) and then deleted. The most important thing is not to open the attachment and to take note of the address from which the email was sent.

Several state agencies experienced technical glitches and were hit by cyber attacks in February, which also hampered the operation of some e-services. At the beginning of the month, an agency reported that their network had been hacked via a VPN solution used for remote working. The attack exploited vulnerabilities in the Ivanti software, which you can read more about here. The attack, which started in January, mapped the network of the agency and some data may have also leaked.

Another agency was upgrading its file hosting software, but an error occurred and the system had to be restored from a backup copy. During the restoration process, it was discovered that the backup function had been unavailable for some time and therefore, not all data could be restored.

On 10 February, a firewall error prevented access to many of the services of the IT and Development Centre at the Estonian Ministry of the Interior (SMIT), including e-Police, the call recording system, and the remote working solution.

A week later, on 16 February, the income tax return page of the Tax and Customs Board was unavailable for about half an hour. The outage coincided with the period for filing income tax returns and happened because of the disk space of the web server of the Information Technology Centre of the Ministry of Finance (RMIT) reaching full capacity.

On the night of 22 February, SK ID Solutions carried out routine maintenance. During this process, an error occurred and for almost ten hours, the validation service responded with ‘INVALID’ when checking the validity of an institution’s certificates (digital stamps, authentication and encryption certificates). This issue occurred if the SK open-access validation service was used.

In addition, the RIA monthly summary provides an overview of RIA’s work to improve cyber security in Estonia and of other developments in the cyberworld. Among other things, cyber attacks linked to military activities continued in Ukraine, the US and other countries of the Five Eyes intelligence alliance warned of activities by Chinese state-sponsored hackers against critical infrastructure, and cyber attacks also hit the healthcare sector, including Romanian hospitals and US pharmacies.

ARNO PÕDER

Press Officer

open graph imagesearch block image