OVERVIEW OF 2024 ● DDoS attacks increased, but impact dropped 600 ● Incidents without impact ● Incidents with impact 484 345 400 580 475 302 202 200 0 75 31 44 100 2021 2022 same time, attacks against web servers decreased. By the end of the year, attacks on name servers accounted for an average of 90% of all denial-of-service attacks registered by CERT-EE. This trend clearly shows that attackers adapt to security measures and constantly seek new vulnerabilities to exploit. When systems critical to the functioning of the internet are targeted, the consequences of attacks can extend far beyond disabling individual websites. This shift underlines the need for institutions and companies to invest more heavily in protecting name servers, which form the backbone of the internet. THE VOLUME AND SCALE OF DDoS ATTACKS CONTINUE TO GROW Due to ongoing geopolitical tensions, distributed denial-of-service attacks are expected to increase further in 2025. These attacks will remain a popular tool for both state-sponsored groups and independent hacktivists. The rising popularity of this type of attack has led to the emergence of platforms and service providers that offer DDoS attacks for hire, making them more powerful and accessible even to less experienced cyber criminals. This, in turn, raises the overall threat level in cyberspace. It is also likely that attackers will increasingly target components critical to internet functionality, such as name servers, cloud services and authentication services that many other services rely on. With the help of artificial intelligence CYBER SECURITY IN ESTONIA 2025 139 2023 105 2024 26 years’ worth of traffic in four hours In March, Estonia’s public sector faced an unprecedented wave of distributed denial-of-service attacks. Over a span of just four hours, attackers directed nearly 2.8 billion malicious requests at the websites of three institutions. Under normal circumstances, generating such a volume of traffic would have taken approximately 26 years. The wave of attacks was carried out by two Russian hacktivist groups, targeting 16 Estonian government institutions. Despite the unprecedented scale of the attacks, the impact on the three targeted websites was minimal. Although the attackers managed to produce a massive volume of malicious requests, the attacks themselves were not particularly sophisticated. Thanks to DDoS protection measures and CERT-EE’s active response, most of the requests never reached their intended targets. Out of the other 13 targeted websites, only three experienced brief disruptions, while the remaining 10 were unaffected by the attacks. and machine learning, distributed denial-of-service attacks are becoming more dynamic, allowing them to be adjusted in realtime to bypass defence mechanisms and complicate countermeasures. ● 27

Select target paragraph3