● OVERVIEW OF 2024 access to sensitive data belonging to Snowflake’s high-profile clients. The Snowflake data breach affected at least nine major corporations and millions of their customers. Among the victims was Ticketmaster, whose leaked data caused significant disruption, including chaos around already scarce tickets for a Taylor Swift concert tour. CROWDSTRIKE SOFTWARE GLITCH DISRUPTED MILLIONS OF COMPUTERS While high-impact cyber incidents are usually associated with malicious attacks and prevented by cybersecurity companies through their protective solutions, one of the most significant IT incidents in history was caused by a colossal blunder by the renowned cybersecurity provider CrowdStrike. Last summer, the company released a faulty update for one of its flagship products, the CrowdStrike Falcon platform, which on 19 July caused millions of Windows systems to stop functioning. The fallout included flight cancel- CrowdStrike’s global IT disruption In the early hours of 19 July, at 4:24 am, CrowdStrike released a routine security update for the sensor in its cloud-based CrowdStrike Falcon antivirus system. But the update turned out to be flawed. The automatically updated sensor affected the underlying settings of many Windows systems, causing them to stop functioning. It is estimated that the operation of at least 8.5 million devices was disrupted globally. This led to disruptions and closures across aviation, finance, healthcare, commerce and media sectors worldwide, with global damages estimated in the billions of dollars. CrowdStrike quickly identified the error and issued a corrected update at 5:27 am the same morning. However, already affected devices had to be restored manually, which meant that the interruptions lasted anywhere from hours to days or even weeks, depending on the sector and organisation. 38 lations across the US and Europe, disruptions to rail services in the UK, interruptions at a Finnish news agency, and the closure of shopping centres in Australia, to name just a few examples of the widespread global disruptions. Estonia was also affected: some computers at grid operator Elektrilevi were down for a few hours, and check-in for Ryanair flights at Tallinn Airport had to be carried out manually. ATTACKS ON THE HEALTHCARE SECTOR Cyberattackers often target critical services, and as in previous years, several serious incidents were linked to the healthcare sector. In many cases, attackers bypassed the healthcare institutions themselves and targeted these institutions’ critical service providers instead. In February, the ransomware group BlackCat attacked the US company Change Healthcare, which connects patients, doctors and insurance providers. As a result, healthcare billing and patient reimbursements across the country were disrupted, with healthcare institutions reportedly suffering losses amounting to tens of millions of dollars. The attack also led to the theft of sensitive data on 100 million Americans – about one in three people – followed by additional ransom demands months later. In Romania, a February ransomware attack on the medical sector’s information system forced around 100 hospitals to go offline and temporarily resort to handwritten prescriptions and patient records. In early June, a ransomware attack hit Synnovis, a pathology and diagnostic service provider collaborating with several major hospitals in London. This led to several days during which rapid blood tests and transfusions could not be performed, resulting in postponed surgeries and cancelled appointments. DATA LEAK FROM HELSINKI CITY GOVERNMENT Data breaches have become increasingly common in today’s digitalised society, but 2024 saw some particularly notable cases. Early May brought bad news for Finland, as it was revealed that the education department of the Helsinki City Government had suffered a cyberattack resulting in the theft of data belonging to up to CYBER SECURITY IN ESTONIA 2025

Select target paragraph3