OVERVIEW OF 2024 ● 150,000 individuals, including children and young people’s personal details and health information. The attack exploited a server running outdated software, which had been slated for replacement but was delayed due to a busy maintenance schedule. Given that serious data breaches have shaken Finnish society before, the government decided to involve the Safety Investigation Authority, which is responsible for investigating and preventing major incidents. During the first week of May, it was also revealed that over 225,000 personal records of active-duty personnel, veterans and reservists in the United Kingdom armed forces were leaked through payroll system used by the UK Ministry of Defence. The leaked data included names and bank account information – sensitive details likely to be of interest to hostile intelligence services. The breach was reportedly made possible due to the service provider’s inadequate cybersecurity standards. This underlined an issue that many countries, including Estonia, continue to grapple with: how to mitigate cyber risks in critical sectors that rely on external service providers. $25 MILLION LOST DUE TO DEEPFAKE TECHNOLOGY Last year, we predicted that rapidly advancing artificial intelligence would transform the cyber landscape. In 2024, phishing emails and messages, enhanced by large language models, became more realistic and accurate, even in less widely spoken languages. However, the most alarming developments were tied to deepfake technology in both voice and video. In February, Hong Kong police investigated a case where a finance officer at a multinational corporation participated in a video call with colleagues and later transferred $25 million from the company account, acting on what appeared to be instructions from the CFO during the call. The entire video call turned out to be fake – the ‘colleagues’ on-screen were deepfake creations, made to look and sound exactly like their real counterparts. While creating fake videos requires some effort and time, synthesising a specific individuCYBER SECURITY IN ESTONIA 2025 al’s voice can take just 10 minutes using widely available software. In one case in the US, for example, a mother received a call from a stranger claiming her daughter had caused a car accident and demanded compensation. To lend credibility to the story, the phone was passed to the ‘daughter’, who sounded distressed, admitted fault and urged her mother to comply. In reality, the daughter’s voice had been faked. While creating fake videos requires some effort and time, synthesising a specific individual’s voice can take just 10 minutes using widely available software. Scammers often use public speech samples, such as TikTok videos or conference recordings, to create a fake voice. In this case, however, the daughter had received several strange phone calls in the days leading up to the scam, which she did not think to hang up immediately. The family believes these calls were used to train the AI tool to replicate her voice and mannerisms. GROWING COLLABORATION AMONG HACKTIVISTS In recent years, hacktivists have made their presence felt in cyberspace, in Estonia, and globally, attempting to disrupt the daily lives of nations they view as adversaries through cyberattacks. In 2024, they continued their efforts, targeting high-profile events such as the Paris Olympics and the UEFA European Championship. These attacks primarily involved basic denial-of-service (DoS) attacks on government websites, which were largely ineffective. However, there are signs that cooperation among various hacktivist groups is gradually growing, enabling them to occasionally expand their activities geographically. For example, pro-Kremlin hacktivists added South Korea to their list of targets after the country condemned North Korean soldiers’ involvement in Russia’s war in Ukraine. ● 39

Select target paragraph3