OVERVIEW OF 2024 ●
deleted. Hansab’s CEO, Kristo Timberg, later
described it as the attackers reaching the system’s ‘Holy Grail’.
Despite being a crisis for the company, it did
not escalate into a national emergency. Cash
supplies remained available – ATMs and shops
were not emptied, and pension payments were
delivered as expected at the beginning of the
month. To keep services running, Hansab
switched to manual operations, ensuring that
ATMs remained functional, cash deposits from
retailers were processed, and customer funds
were credited.
This time, the impact was limited. However,
longer-lasting payment disruptions or interruptions to cash circulation could be more
severe. To prepare for such scenarios, it is
advisable to keep enough cash on hand to cover
at least a week’s essential expenses.
CRIME AND PUNISHMENT
While some may assume that cybercriminals
can operate anonymously with impunity, last
year provided plenty of evidence to bust
this myth, as multiple cases demonstrated
that justice can catch up with cyber offenders.
In our previous cybersecurity yearbook,
we covered a data breach at genetic testing
company Asper Biogene, where attackers
stole the personal data – including genetic
and health information – of nearly 10,000
individuals.
A criminal investigation revealed that a
four-person group spent two months persistently working to infiltrate the company’s systems. First, they identified a security vulnerability that allowed them to access usernames
and encrypted passwords. Next, they decrypted
an employee’s password, used it to log into the
system and installed malware. This granted
them access to sensitive health records, which
they downloaded before demanding a €45,000
ransom.
The group’s leader was Vladislav Rybakov, a
Russian citizen, whose travel options have since
become severely restricted. Due to his role in
the Asper Biogene attack, he is now an internationally wanted criminal.
CYBER SECURITY IN ESTONIA 2025
Following the breach, Estonia’s Data Protection Inspectorate launched a parallel investigation, finding serious shortcomings in Asper
Biogene’s information security practices. As a
result, a fine of €85,000 was imposed, though,
at the time of writing, the decision had not yet
entered into force.
In 2020, Estonian government bodies suffered a major cyberattack, during which 350 GB
of data was stolen from the Ministry of Economic Affairs and Communications; hackers
also accessed records on 10,000 COVID-19
patients from agencies under the Ministry of
Social Affairs. Investigations by the Estonian
Internal Security Service (KAPO) and the
National Criminal Police eventually led to three
men, all of whom were working for Russia’s
military intelligence (GRU) at the time of the
attack: Colonel Yuri Denisov, commander of
GRU Unit 29155, Nikolay Korchagin and Vitali
Shevchenko. These individuals are now also
internationally wanted. Read more about this
case on page 20.
To prepare for such scenarios,
it is advisable to keep enough
cash on hand to cover at least a
week’s essential expenses.
Last year, the Harju County Court sentenced
a young man from Tallinn to prison for selling
phishing toolkits and providing guidance on
how to carry out cyberattacks. His tools, which
he sold using the Telegram messaging app,
were explicitly designed to bypass two-factor
authentication. This allowed criminals to steal
victims’ login credentials and gain access to
Microsoft 365, PayPal, Google, Yahoo, Dropbox, Binance and other online accounts.
As for the perpetrators of the Allium UPI and
Hansab attacks, that remains an open question.
Hopefully, in a future edition of this yearbook,
we will be able to report on their identification
and prosecution. Until then, stay vigilant in
cyberspace! ●
13