OVERVIEW OF 2024 ● Incidents with impact in 2024 The most infamous software update from last year led to one Defacement 24 Ransomware 10 of the most significant IT disBotnet member 5 Malware 50 Data leak 68 ruptions in history. In the early Compromise 69 hours of 19 July, cybersecurity DDoS 105 Account takeover firm CrowdStrike released an 134 Phishing update for its Falcon Sensor security 4,224 software, which large organisations widely use to protect against malware and Malicoius other threats. Unfortunately, the faulty redirect update crippled 8.5 million Windows com565 puters, causing them to crash with the notorious blue screen of death. This resulted in more than 5,000 canFraud 624 celled flights and service disruptions in banks from Brazil to New Zealand, emergency numbers, hospitals, television and Service radio stations, and even fuel payment sysdisruption tems at petrol stations experienced outag637 es. The complete list could go on for pages. Restoring systems took weeks and required significant manual effort. The estimated financial damage quickly reached $10 billion. Estonia was lucky, as CrowdStrike Falcon has relatively few users here. One state institution and one private company experienced only a few hours of disruption, and at Tallinn AirThere were also disruptions to national port, Ryanair check-ins had to be processed authentication services, including TARA, manually, causing minor delays. But overall, Smart-ID, Mobile-ID and the ID card. Most Estonia avoided the worst consequences. outages were short-lived or occurred overnight, After this unfortunate incident, many asked when few people were attempting to log into whether rushing software updates is really online banking or sign digital documents. wise. Our answer remains yes: the risks of delaying updates are far greater. Read more MORE DDoS ATTACKS, LESS DAMAGE about these risks on page 34. While Estonia escaped the CrowdStrike disWebsites and services can also be knocked aster, a Cloudflare outage in September caused offline by DDoS attacks, and last year left little significant disruptions. On the third Monday of room to breathe in this area. DDoS attack volthe month, Cloudflare’s service failures affected umes have increased every year since Russia nearly 200 public-sector websites that rely on launched its full-scale invasion of Ukraine, and RIA’s protection against distributed deni2024 broke records for both attack numbers al-of-service (DDoS) attacks. and scale. One four-hour wave of attacks targetMobile operators also faced network failures, ing public-sector websites generated nearly which affected both data and voice services, three billion malicious requests. Under normal including emergency calls. If your provider’s conditions, reaching this level of traffic would network is down but you need to call emergenhave taken more than 25 years. cy services, removing the SIM card from your However, the number of attacks is less signifphone allows it to connect to another operator’s icant than their impact – and in this regard, network for emergency calls. there is good news. In 2022, one in three DDoS ➜ CYBER SECURITY IN ESTONIA 2025 11 TOTAL 6,515 INCIDENTS

Select target paragraph3