‘May showed that in Estonian cyberspace, we must continue to address both the reliability of services and fraud. With over a thousand registered scam and phishing websites, and the case involving the Estonian Artists Association, it is clear that cybercriminals are increasingly focusing on manipulating people and abusing their trust,’ said Dorel Kiik, an analyst at the RIA Analysis and Prevention Department.
During May, there were disruptions to the operation of several public services. Short-lived disruptions were recorded on open data portals, the European Union’s Entry/Exit System (EES), the Health Insurance Fund’s partner management information system, the Commercial Register, and the Police and Border Guard Board’s identity verification and case management system, UUSIS. The causes of the disruptions ranged from technical faults and human error to partner system glitches.
In May, particular attention was drawn to a fraud committed against the Estonian Artists Association, as a result of which the organisation lost nearly 700,000 euros. According to Kiige, to prevent such incidents, organisations should regularly review their payment approval processes, set reasonable transfer limits, and use a multi-level approval process for larger payments. ‘It is also important to train staff to recognise telephone scams, phishing attempts, and other forms of social engineering,’ she added.
To raise cyber awareness, RIA recommends that organisations familiarise themselves with the materials on the IT-vaatlik prevention portal and sign up for the RIA Cyber Test, which helps to assess and improve the cyber security awareness of employees.
In May, several high-profile incidents came to light in the international cyberspace – hackers gained access to Lithuanian government databases; a report by the Polish Internal Security Agency highlighted attacks on the networks of water treatment plants in five cities; and data on customers of Zara and Škoda, as well as patients at several German university hospitals, was leaked.