● OVERVIEW OF 2024 SSSCIP CHIEF: Russia operates more covertly in cyberspace We learn about the cyberattacks thwarted in 2024 through an interview with Brigadier General Oleksandr Potii, head of Ukraine’s State Service of Special Communications and Information Protection (SSSCIP) and a close partner of CERT-EE. How have Russian cyberattack capabilities evolved in 2024? What changes have you observed compared with the previous year? In 2023, we saw destructive cyberattacks by Russian hacker groups targeting IT and telecommunications companies. At least 11 internet service providers suffered from such attacks, culminating in the cyberattack on Kyivstar in December 2023. These attacks were accompanied by data leaks and publications on Russian social media networks. In 2024, Russia gradually shifted away from publicising its cyberattacks, as it focused instead on cyber intelligence operations targeting systems linked to war and politics, aiming to remain undetected for as long as possible. The main targets were Ukraine’s security and defence sectors, as well as companies directly supporting them. There was also a significant increase in the activity of Russian financially motivated groups in 2024, including targeted cyberattacks on large organisations and various fraud schemes. We believe these criminal hacker groups operate under the direction or approval of the Rus16 sian government, as some engage in both financial theft and cyber espionage. Have you observed AI-enabled cyberattacks from Russia? Has the broader use of AI led to any significant changes? AI is already being used in cyberattacks, for example, to generate phishing emails in Ukrainian or to facilitate interactions between hackers and victims through messaging apps or email. The use of AI components will undoubtedly increase further. In 2024, there was only one widely publicised attack on Ukraine’s critical infrastructure – the December attack on state registries. This seems to suggest your defences have been largely effective. Which critical sectors faced the greatest threats last year? Indeed, 2024 ended with a high-profile attack on the Ministry of Justice’s registries. However, attempts to target critical infrastructure were detected throughout the year. For example, in March, preparations by UAC-0002 (also known as Sandworm) for CYBER SECURITY IN ESTONIA 2025

Select target paragraph3