OVERVIEW OF 2024 ●
What to do if you
have fallen victim to
a ransomware attack
- Disconnect the infected device from the
network (don’t forget to disable wireless
connections).
- Notify CERT-EE (cert@cert.ee) for guidance
on resolving the incident and advice on
preventing similar attacks in the future.
- If infected, restore the operating system
from a backup or reinstall it to avoid
reinfection. Before restoring from a
backup, ensure that it is free of malware.
Carefully consider the risks before
contacting the attackers.
- Paying the ransom offers no guarantee
that your files will be decrypted or that
stolen data will not be published. Instead,
paying will signal to the attackers that their
actions were successful, which may make
you a target for future attacks.
and lacked additional security measures such as
VPNs, two-factor authentication, IP-based
restrictions, logging and monitoring. In light of
these incidents, we recommend RDP users review
the threat assessment available on RIA’s website
(ria.ee/media/929/download), which outlines
the risks associated with the Remote Desktop
Protocol and how to mitigate them.
Several organisations also became victims of
ransomware attacks in 2024 due to outdated
network devices, unpatched software or insecurely configured management interfaces. In
one case, a network device’s management interface was publicly accessible on the internet, and
the default administrator password was still
used, while the server’s software was not up to
date. In another instance, a router with a longknown vulnerability was in use, despite the
device manufacturer having stopped releasing
security updates back in 2022. In such cases,
purchasing a new device is essential. Delays in
replacing outdated equipment can lead to
extremely costly consequences.
CYBER SECURITY IN ESTONIA 2025
UNIDENTIFIED INFECTION METHODS
In several instances, the exact method by which
ransomware entered the system remained
unknown. This uncertainty often stems from a
lack of logging. While attackers sometimes
delete logs to cover their tracks, in many cases,
In nearly one-third of cases,
attackers gained access to
systems through Remote
Desktop applications that
were protected by weak
passwords and lacked
additional security measures.
they do not need to, as the systems simply do
not have logs. Without knowledge of how
attackers accessed the system, organisations
face a significant risk of intruders exploiting the
same entry point again. ●
33