● OVERVIEW OF 2024 LESSONS from a massive data leak At the beginning of 2024, criminals breached a server of Allium UPI, stealing data on the customers of Apotheka, Apotheka Beauty and Pet City. The leak included nearly 700,000 personal identification codes, over 400,000 email addresses, and tens of thousands of phone numbers and home addresses. Why and how did this happen? T he Estonia-based company Allium UPI, which operates in the pharmacy and healthcare product sectors in Estonia, Latvia and Lithuania, reported in February 2024 to both the Estonian Police and Border Guard Board and the Information System Authority’s incident handling unit (CERT-EE) that their loyalty card system had been illegally accessed. The intruders 18 downloaded data on the customers of Apotheka, Apotheka Beauty OÜ and PetCity OÜ, including personal identification codes, purchase data and contact information. The Police and Border Guard Board’s criminal investigation revealed that nearly 700,000 personal identification codes, over 400,000 email addresses, around 60,000 home addresses and approximately 30,000 phone numbers CYBER SECURITY IN ESTONIA 2025

Select target paragraph3