OVERVIEW OF 2024 ● deleted. Hansab’s CEO, Kristo Timberg, later described it as the attackers reaching the system’s ‘Holy Grail’. Despite being a crisis for the company, it did not escalate into a national emergency. Cash supplies remained available – ATMs and shops were not emptied, and pension payments were delivered as expected at the beginning of the month. To keep services running, Hansab switched to manual operations, ensuring that ATMs remained functional, cash deposits from retailers were processed, and customer funds were credited. This time, the impact was limited. However, longer-lasting payment disruptions or interruptions to cash circulation could be more severe. To prepare for such scenarios, it is advisable to keep enough cash on hand to cover at least a week’s essential expenses. CRIME AND PUNISHMENT While some may assume that cybercriminals can operate anonymously with impunity, last year provided plenty of evidence to bust this myth, as multiple cases demonstrated that justice can catch up with cyber offenders. In our previous cybersecurity yearbook, we covered a data breach at genetic testing company Asper Biogene, where attackers stole the personal data – including genetic and health information – of nearly 10,000 individuals. A criminal investigation revealed that a four-person group spent two months persistently working to infiltrate the company’s systems. First, they identified a security vulnerability that allowed them to access usernames and encrypted passwords. Next, they decrypted an employee’s password, used it to log into the system and installed malware. This granted them access to sensitive health records, which they downloaded before demanding a €45,000 ransom. The group’s leader was Vladislav Rybakov, a Russian citizen, whose travel options have since become severely restricted. Due to his role in the Asper Biogene attack, he is now an internationally wanted criminal. CYBER SECURITY IN ESTONIA 2025 Following the breach, Estonia’s Data Protection Inspectorate launched a parallel investigation, finding serious shortcomings in Asper Biogene’s information security practices. As a result, a fine of €85,000 was imposed, though, at the time of writing, the decision had not yet entered into force. In 2020, Estonian government bodies suffered a major cyberattack, during which 350 GB of data was stolen from the Ministry of Economic Affairs and Communications; hackers also accessed records on 10,000 COVID-19 patients from agencies under the Ministry of Social Affairs. Investigations by the Estonian Internal Security Service (KAPO) and the National Criminal Police eventually led to three men, all of whom were working for Russia’s military intelligence (GRU) at the time of the attack: Colonel Yuri Denisov, commander of GRU Unit 29155, Nikolay Korchagin and Vitali Shevchenko. These individuals are now also internationally wanted. Read more about this case on page 20. To prepare for such scenarios, it is advisable to keep enough cash on hand to cover at least a week’s essential expenses. Last year, the Harju County Court sentenced a young man from Tallinn to prison for selling phishing toolkits and providing guidance on how to carry out cyberattacks. His tools, which he sold using the Telegram messaging app, were explicitly designed to bypass two-factor authentication. This allowed criminals to steal victims’ login credentials and gain access to Microsoft 365, PayPal, Google, Yahoo, Dropbox, Binance and other online accounts. As for the perpetrators of the Allium UPI and Hansab attacks, that remains an open question. Hopefully, in a future edition of this yearbook, we will be able to report on their identification and prosecution. Until then, stay vigilant in cyberspace! ● 13

Select target paragraph3