● OVERVIEW OF 2024
access to sensitive data belonging to Snowflake’s high-profile clients. The Snowflake data
breach affected at least nine major corporations
and millions of their customers. Among the victims was Ticketmaster, whose leaked data
caused significant disruption, including chaos
around already scarce tickets for a Taylor Swift
concert tour.
CROWDSTRIKE SOFTWARE GLITCH
DISRUPTED MILLIONS OF COMPUTERS
While high-impact cyber incidents are usually
associated with malicious attacks and prevented by cybersecurity companies through their
protective solutions, one of the most significant
IT incidents in history was caused by a colossal
blunder by the renowned cybersecurity provider CrowdStrike.
Last summer, the company released a faulty
update for one of its flagship products, the
CrowdStrike Falcon platform, which on 19 July
caused millions of Windows systems to stop
functioning. The fallout included flight cancel-
CrowdStrike’s
global IT disruption
In the early hours of 19 July, at 4:24 am,
CrowdStrike released a routine security
update for the sensor in its cloud-based
CrowdStrike Falcon antivirus system.
But the update turned out to be flawed.
The automatically updated sensor affected
the underlying settings of many Windows
systems, causing them to stop functioning.
It is estimated that the operation of at least
8.5 million devices was disrupted globally.
This led to disruptions and closures across
aviation, finance, healthcare, commerce and
media sectors worldwide, with global
damages estimated in the billions of dollars.
CrowdStrike quickly identified the error
and issued a corrected update at 5:27 am the
same morning. However, already affected
devices had to be restored manually, which
meant that the interruptions lasted anywhere
from hours to days or even weeks, depending
on the sector and organisation.
38
lations across the US and Europe, disruptions
to rail services in the UK, interruptions at a
Finnish news agency, and the closure of shopping centres in Australia, to name just a few
examples of the widespread global disruptions.
Estonia was also affected: some computers at
grid operator Elektrilevi were down for a few
hours, and check-in for Ryanair flights at Tallinn Airport had to be carried out manually.
ATTACKS ON THE HEALTHCARE SECTOR
Cyberattackers often target critical services,
and as in previous years, several serious incidents were linked to the healthcare sector. In
many cases, attackers bypassed the healthcare
institutions themselves and targeted these
institutions’ critical service providers instead.
In February, the ransomware group BlackCat
attacked the US company Change Healthcare,
which connects patients, doctors and insurance
providers. As a result, healthcare billing and
patient reimbursements across the country
were disrupted, with healthcare institutions
reportedly suffering losses amounting to tens of
millions of dollars. The attack also led to the
theft of sensitive data on 100 million Americans
– about one in three people – followed by additional ransom demands months later.
In Romania, a February ransomware attack
on the medical sector’s information system
forced around 100 hospitals to go offline and
temporarily resort to handwritten prescriptions
and patient records. In early June, a ransomware attack hit Synnovis, a pathology and diagnostic service provider collaborating with several major hospitals in London. This led to several
days during which rapid blood tests and transfusions could not be performed, resulting in postponed surgeries and cancelled appointments.
DATA LEAK FROM HELSINKI
CITY GOVERNMENT
Data breaches have become increasingly common in today’s digitalised society, but 2024 saw
some particularly notable cases. Early May
brought bad news for Finland, as it was revealed
that the education department of the Helsinki
City Government had suffered a cyberattack
resulting in the theft of data belonging to up to
CYBER SECURITY IN ESTONIA 2025