● OVERVIEW OF 2024 PHISHERS caught on the hook The international police operation PhishOFF shut down LabHost, one of the world’s largest platforms used by phishing scammers, with over a million people impacted. The Estonian police played a key role in preparing the raid. Y ears ago, simple scams like “Nigerian letters” offering vast sums of money were the subject of jokes. Today, however, cyber fraud has taken a giant leap forward, often orchestrated by sprawling international networks and organised crime. These operations function like well-oiled machines with distinct roles: some criminals breach systems, others create virtual environments such as phishing websites, while another group devises ways to quickly and effectively drain bank accounts using stolen data. Finally, specialist teams help launder the illicitly obtained funds. Dedicated platforms now allow criminals to purchase phishing services, denial-of-service attacks, ransomware and other malware as a service. OVER A MILLION VICTIMS One of the largest operations of its kind, LabHost, focused specifically on facilitating phishing scams. It was dismantled in April 2024 during the international police operation PhishOFF, with significant contributions from the Estonian police. Coordinated by Europol, the five-day raid resulted in the arrest of 37 organisers of phishing scams worldwide. The operation involved 18 countries, primarily in Europe, but also included the United States, Canada, Australia and New Zealand. Launched in 2021, LabHost was a public platform offering pre-built fake websites, phishing 24 systems and distribution solutions (via SMS or email) while also selling stolen data collected on its platform. Thousands of regular criminal clients purchased access to phishing packages to execute their schemes. These packages included fake websites mimicking major banks and services across dozens of countries, enabling fraudsters to steal authentication details and money from victims’ bank accounts. Higher-tier packages cost between €230 and €350 per month, with quarterly and annual subscriptions also available. Payments were made in cryptocurrency, and LabHost reportedly earned around €1 million from its services, but the financial damage to victims was far greater. The platform handled the most tedious and time-consuming aspects of cybercrime; its administrators offered technical support to criminals through a dedicated Telegram channel. The international investigation uncovered at least 66,000 websites used by nearly 10,000 criminals to steal data or money. Globally, over a million people have fallen victim to scams that have been executed through this platform. LabHost facilitated the theft of 480,000 bank card details, 64,000 PIN codes and over a million passwords. Stolen funds were transferred between various bank accounts to obscure their origins before being withdrawn as cash. In Estonia alone, up to 30 criminals used LabHost for phishing attacks, with around 10 of the most active offenders arrested in different countries. CYBER SECURITY IN ESTONIA 2025

Select target paragraph3