OVERVIEW OF 2024 ●
were unlawfully downloaded from UPI’s database. In some cases, it was possible to identify
over-the-counter medications and other pharmacy products purchased, though prescription
medication data was not accessible. Since the
loyalty programme did not store passwords,
bank card information or other financial details,
these were not compromised. The data came
from a backup of the customer database containing records from 2014-2020.
WHY DID THIS HAPPEN?
Cyberattacks with serious consequences often
begin with the takeover of an employee’s user
account. Criminals can obtain usernames and
passwords through methods such as malware,
which might be downloaded to an employee’s
computer using a malicious email attachment
or pirated software from an untrusted source.
Two-factor authentication should be implemented to prevent criminals from immediately
accessing systems with a leaked password. Furthermore, only information systems and services that absolutely must be online should have
internet access, and all such systems should be
secured behind a VPN or similar protective
solution.
Given the highly international nature of
cybercrime, leaked data can circulate for years
among different countries and groups, who will
be able to use it to carry out various cyberattacks.
DATA IS PERSONAL PROPERTY
This incident once again brought the issue of
protecting sensitive personal data into the public spotlight in Estonia. People increasingly
trust their data to a growing number of service
providers, expecting these providers to take
their data protection responsibilities seriously.
Unfortunately, this is not always the case, but
similar incidents in recent years have raised
awareness among both service providers and
individuals, encouraging better preparedness
and action.
As customers, we should critically assess the
sharing of our personal data, including for loyalty accounts. A small discount or slightly more
convenient service may not be worth the risk. ●
CYBER SECURITY IN ESTONIA 2025
Lessons from the
eye of the storm
‘An experience like this is a cold shower,’
recalls Marika Pensa, a member of the
management board at Allium UPI.
Last winter, criminals stole a backup of the
Apotheka customer database. Following this
unfortunate incident, we, as a service provider,
have placed even greater emphasis on
system security. Criminals never rest, and
they exploit any weakness that may have
escaped the heightened attention of system
administrators.
The first lesson is simple: ensuring security
is an ongoing process that never ends. It’s like
riding a bicycle; you must keep moving to stay
upright.
For a company that has become a victim
or target of a cyberattack, such an experience
is a cold shower, but also a reminder and an
opportunity to reassess its systems. Cybersecurity is no longer just something described
as “nice to have”.
Another lesson from this incident is that
criminals don’t see the world as divided into
business, government, customers, or other
neatly defined boxes. Effective action against
crime can only be achieved through unified
collective defence involving individuals,
companies, governments and others. That’s
why we are very happy about the effective
cooperation we’ve had with Estonian government agencies, from the Police and Border
Guard Board to the Information System
Authority and the Data Protection Inspectorate. We all understand that we are on the
same side of the front line, with international
criminals on the other side. We hope the
perpetrators of this crime will be apprehended
and held accountable.
The fight against cybercrime requires
continuous and growing attention from all of
us. The question is not whether a cyberattack
will happen but when, on what scale and in
which area. There are no bulletproof individuals or systems, but robust defences against
external attacks can save lives and protect
data.
19