OVERVIEW OF 2024 ● What to do if you have fallen victim to a ransomware attack - Disconnect the infected device from the network (don’t forget to disable wireless connections). - Notify CERT-EE (cert@cert.ee) for guidance on resolving the incident and advice on preventing similar attacks in the future. - If infected, restore the operating system from a backup or reinstall it to avoid reinfection. Before restoring from a backup, ensure that it is free of malware. Carefully consider the risks before contacting the attackers. - Paying the ransom offers no guarantee that your files will be decrypted or that stolen data will not be published. Instead, paying will signal to the attackers that their actions were successful, which may make you a target for future attacks. and lacked additional security measures such as VPNs, two-factor authentication, IP-based restrictions, logging and monitoring. In light of these incidents, we recommend RDP users review the threat assessment available on RIA’s website (ria.ee/media/929/download), which outlines the risks associated with the Remote Desktop Protocol and how to mitigate them. Several organisations also became victims of ransomware attacks in 2024 due to outdated network devices, unpatched software or insecurely configured management interfaces. In one case, a network device’s management interface was publicly accessible on the internet, and the default administrator password was still used, while the server’s software was not up to date. In another instance, a router with a longknown vulnerability was in use, despite the device manufacturer having stopped releasing security updates back in 2022. In such cases, purchasing a new device is essential. Delays in replacing outdated equipment can lead to extremely costly consequences. CYBER SECURITY IN ESTONIA 2025 UNIDENTIFIED INFECTION METHODS In several instances, the exact method by which ransomware entered the system remained unknown. This uncertainty often stems from a lack of logging. While attackers sometimes delete logs to cover their tracks, in many cases, In nearly one-third of cases, attackers gained access to systems through Remote Desktop applications that were protected by weak passwords and lacked additional security measures. they do not need to, as the systems simply do not have logs. Without knowledge of how attackers accessed the system, organisations face a significant risk of intruders exploiting the same entry point again. ● 33

Select target paragraph3