● OVERVIEW OF 2024
Number of incidents with an impact doubled
6,515
6000
4000
3,314
2000
0
2,237
2021
2,672
2022
attacks succeeded in causing significant disruptions. By 2024, this figure had dropped to 18%.
Some websites experienced short-term outages
or slowdowns, but none of the attacks caused
severe damage. Read more about DDoS attacks
and their consequences on page 26.
DATA BREACH AFFECTS
MORE THAN 700,000 PEOPLE
Last year, 68 data breach incidents were recorded in Estonia – nearly twice as many as in 2023.
Some were relatively small in scale: for example, the exam information system’s GitHub
page accidentally contained real personal data
In 2022, one in three DDoS
attacks succeeded in causing
significant disruptions. By 2024,
this figure had dropped to 18%.
instead of test data, making hundreds of people’s details publicly accessible. Elsewhere, a
waste management self-service portal accidentally displayed all customer transactions and
personal identification numbers instead of just
the user’s own information.
However, all these breaches pale in comparison to the cyberattack on Allium UPI, a company
that manages loyalty card systems for Apotheka,
12
2023
2024
Apotheka Beauty, and Pet City. Attackers gained
access to this system and successfully stole nearly 700,000 personal identification numbers,
more than 400,000 email addresses, and tens of
thousands of phone numbers and home addresses. The stolen data originated from a backup of
the customer database covering the years 2014–
2020. Anyone affected by this breach should
exercise even greater caution against phishing
attempts and scams. Read more about this incident on page 18.
ATTACK ON CASH CIRCULATION
Unlike the pharmacy chain Apotheka, whose
customer data was leaked, Hansab is
not a household name, but its services
are critical to nearly everyone. Hansab
is responsible for filling Swedbank,
Luminor and LHV ATMs, delivering
pensions, issuing ID cards and passports in cooperation with the Police and
Border Guard Board, and many other
essential functions. In short, if its operations were to suddenly stop, almost
everyone would feel the impact.
At midday on 1 March, Hansab’s servers
began unexpectedly rebooting. Within minutes,
it became clear that something was terribly
wrong. As an emergency measure, the company
disconnected from the internet and isolated its
network to prevent further damage. But the
attack had already inflicted severe losses: the
entire virtualisation environment had been
CYBER SECURITY IN ESTONIA 2025