● OVERVIEW OF 2024
DDoS ATTACKS
more noise,
less impact
Last year, CERT-EE registered an unprecedented number of distributed
denial-of-service attacks, but effective defence measures reduced
the proportion of attacks that had a significant impact. A new trend
saw attackers shift their focus to name servers.
I
n 2024, CERT-EE registered 580 distributed denial-of-service (DDoS) attacks. This
was 93 more than in 2023 and 50% more
than in 2021 and 2022 combined.
Just as attackers are constantly seeking new
ways to cause maximum harm, CERT-EE continuously improves its DDoS defences to counteract them. The more attackers target the websites protected by CERT-EE, the more effectively CERT-EE’s DDoS defence measures can
be enhanced.
As a result, despite the alarmingly high number of attacks, the proportion of impactful ones
What is a DDoS attack?
A distributed denial-of-service (DDoS) attack
is a cyberattack in which a large volume of
malicious requests is directed at a target’s
servers to overload them and render the
service inaccessible to users. Since most
DDoS attacks against Estonia are politically
motivated, they typically target services whose
disruption would affect the largest number
of people, such as national e-services,
banks and the transport sector.
26
dropped to just 18%. This represents significant
progress compared to the previous year, when
that figure was 27%.
TARGETING NAME SERVERS
One of the most notable trends of 2024 was
attackers increasingly targeting name servers
rather than web servers.
A name server translates IP addresses into
domain names, allowing users to type google.
com instead of remembering a numeric
sequence like 142.250.189.206. While name
servers do not host web content themselves,
they help users locate it. If attackers succeed in
disabling name servers through a denial-of-service attack, users cannot access websites, even
if the web servers are functioning normally.
As Estonian organisations’ web servers have
faced constant attacks over the years, they are
now better protected. This forced attackers to
change tactics, turning their focus to name
servers, which are somewhat more complicated
to defend.
This wave of attacks began in May 2024,
when the share of denial-of-service attacks targeting Estonian organisations’ name servers
jumped from the usual 3-8% to 69%. At the
CYBER SECURITY IN ESTONIA 2025