● OVERVIEW OF 2024 Number of incidents with an impact doubled 6,515 6000 4000 3,314 2000 0 2,237 2021 2,672 2022 attacks succeeded in causing significant disruptions. By 2024, this figure had dropped to 18%. Some websites experienced short-term outages or slowdowns, but none of the attacks caused severe damage. Read more about DDoS attacks and their consequences on page 26. DATA BREACH AFFECTS MORE THAN 700,000 PEOPLE Last year, 68 data breach incidents were recorded in Estonia – nearly twice as many as in 2023. Some were relatively small in scale: for example, the exam information system’s GitHub page accidentally contained real personal data In 2022, one in three DDoS attacks succeeded in causing significant disruptions. By 2024, this figure had dropped to 18%. instead of test data, making hundreds of people’s details publicly accessible. Elsewhere, a waste management self-service portal accidentally displayed all customer transactions and personal identification numbers instead of just the user’s own information. However, all these breaches pale in comparison to the cyberattack on Allium UPI, a company that manages loyalty card systems for Apotheka, 12 2023 2024 Apotheka Beauty, and Pet City. Attackers gained access to this system and successfully stole nearly 700,000 personal identification numbers, more than 400,000 email addresses, and tens of thousands of phone numbers and home addresses. The stolen data originated from a backup of the customer database covering the years 2014– 2020. Anyone affected by this breach should exercise even greater caution against phishing attempts and scams. Read more about this incident on page 18. ATTACK ON CASH CIRCULATION Unlike the pharmacy chain Apotheka, whose customer data was leaked, Hansab is not a household name, but its services are critical to nearly everyone. Hansab is responsible for filling Swedbank, Luminor and LHV ATMs, delivering pensions, issuing ID cards and passports in cooperation with the Police and Border Guard Board, and many other essential functions. In short, if its operations were to suddenly stop, almost everyone would feel the impact. At midday on 1 March, Hansab’s servers began unexpectedly rebooting. Within minutes, it became clear that something was terribly wrong. As an emergency measure, the company disconnected from the internet and isolated its network to prevent further damage. But the attack had already inflicted severe losses: the entire virtualisation environment had been CYBER SECURITY IN ESTONIA 2025

Select target paragraph3