● OVERVIEW OF 2024
Number of incidents with an impact by month
1000
920
800
675
600
400
200
521
439
383
188
206
430
226
243
230
499
438
394
329
658
269
305
647
511
299
337
378
309
0
Jan.
Feb.
Mar.
Apr.
May
June
July
Aug.
Sept.
Oct.
Nov.
Dec.
● 2023 ● 2024
widespread. These messages direct recipients
to fraudulent websites, tricking them into
entering their bank card details under the guise
of paying a delivery fee. Some victims fall for
this even when they haven’t ordered a package
recently, only realising their mistake later when
checking their bank statements and seeing not
tite) grows while their scepticism fades. In the
next round, they invest more.
As their displayed balance balloons, some,
having spent their savings, even take out loans
to maximise returns. But when they finally try
to withdraw their funds, endless excuses begin:
delays, additional fees and new requirements.
In some cases, scammers demand further deposits to ‘unlock’ the money –
deposits that, of course, are never
returned. Eventually, the fraudulent
But when they finally try to
website disappears altogether, leaving
withdraw their funds, endless
victims with nothing.
excuses begin: delays, additional
When CERT-EE identifies such scam
sites,
it requests their hosting providers
fees and new requirements.
to take them down, limiting the number
of potential victims. However, our reach
is not infinite. Ultimately, public awarejust a few euros withdrawn but hundreds or
ness and critical thinking are the most effective
even thousands.
defences against these schemes. Read more
Investment scams also spread last year,
about various types of scams on page 28.
promising fantastic returns. After a temporary
lull, alongside stocks, various cryptocurrencies
SERVICE DISRUPTIONS,
DAY AFTER DAY
– some more exotic than others – became a hot
commodity for scammers once again. These
After phishing and scams, the third-largest catfrauds usually start small: victims ‘invest’ a
egory of incidents in 2024 was service disrupmodest sum, often just a few dozen or a couple
tions, with an average of two per day. Malicious
of hundred euros. Their balance appears to
attacks did not always cause these; many resultgrow over the next few weeks, and when they
ed from hardware or software failures or even
successfully withdraw their initial amount plus
well-intentioned but flawed system updates by
a supposed profit, their confidence (and appedevelopers and administrators.
10
CYBER SECURITY IN ESTONIA 2025