● OVERVIEW OF 2024 RANSOMWARE VICTIMS: schools and businesses Although Estonia once again avoided society-wide ransomware attacks last year, some businesses, schools and a dental clinic found their systems infiltrated and their data locked. A ransomware attack is one of the most distressing forms of cyberattack as it can halt an organisation’s operations and jeopardise personal data. While the global number of ransomware attacks and the associated damages increased in 2024, the data available to us suggests a different trend in Estonia. CERT-EE registered around 10 ransomware incidents, fewer than in previous years. However, it is important to note that many victims do not report such incidents. TWO SCHOOLS, TWO DIFFERENT OUTCOMES In 2024, two Estonian schools fell victim to ransomware attacks. At the beginning of June, during the busy exam period, Tallinn Health Care College had to manage the aftermath of an attack. The attacker encrypted approximately 1.5 terabytes of data on the school’s server, including files belonging to more than 200 staff members and students. Fortunately, the school had a recent backup, enabling them to restore the files and services by the next day. Two weeks before the start of the new school year, on 16 August, staff at Järvamaa Vocational Training Centre discovered that all data on 32 the school’s servers had been encrypted. This attack caused more significant damage, as there was no backup of the data. ATTACKS THAT HALTED BUSINESS OPERATIONS At the end of July, a ransomware attack hit a small company in Tartu, and the attackers encrypted files on four computers. The attack disrupted the company’s regular operations. About a week later, ransomware halted operations at a retail company in southern Estonia. Attackers gained access to the backup server, preventing the company from restoring its data. On 1 November, a dental clinic fell victim to a ransomware attack that resulted in its data being encrypted. Since there was no functional backup, the clinic was unable to recover its files. WHY DO SUCH ATTACKS HAPPEN? An analysis of ransomware attacks that occurred in 2024 highlights vulnerabilities related to Remote Desktop Protocol (RDP) applications and network devices. In nearly one-third of cases, attackers gained access to systems through Remote Desktop applications that were protected by weak passwords CYBER SECURITY IN ESTONIA 2025

Select target paragraph3