● OVERVIEW OF 2024 DDoS ATTACKS more noise, less impact Last year, CERT-EE registered an unprecedented number of distributed denial-of-service attacks, but effective defence measures reduced the proportion of attacks that had a significant impact. A new trend saw attackers shift their focus to name servers. I n 2024, CERT-EE registered 580 distributed denial-of-service (DDoS) attacks. This was 93 more than in 2023 and 50% more than in 2021 and 2022 combined. Just as attackers are constantly seeking new ways to cause maximum harm, CERT-EE continuously improves its DDoS defences to counteract them. The more attackers target the websites protected by CERT-EE, the more effectively CERT-EE’s DDoS defence measures can be enhanced. As a result, despite the alarmingly high number of attacks, the proportion of impactful ones What is a DDoS attack? A distributed denial-of-service (DDoS) attack is a cyberattack in which a large volume of malicious requests is directed at a target’s servers to overload them and render the service inaccessible to users. Since most DDoS attacks against Estonia are politically motivated, they typically target services whose disruption would affect the largest number of people, such as national e-services, banks and the transport sector. 26 dropped to just 18%. This represents significant progress compared to the previous year, when that figure was 27%. TARGETING NAME SERVERS One of the most notable trends of 2024 was attackers increasingly targeting name servers rather than web servers. A name server translates IP addresses into domain names, allowing users to type google. com instead of remembering a numeric sequence like 142.250.189.206. While name servers do not host web content themselves, they help users locate it. If attackers succeed in disabling name servers through a denial-of-service attack, users cannot access websites, even if the web servers are functioning normally. As Estonian organisations’ web servers have faced constant attacks over the years, they are now better protected. This forced attackers to change tactics, turning their focus to name servers, which are somewhat more complicated to defend. This wave of attacks began in May 2024, when the share of denial-of-service attacks targeting Estonian organisations’ name servers jumped from the usual 3-8% to 69%. At the CYBER SECURITY IN ESTONIA 2025

Select target paragraph3