Growing awareness of China’s role in cyber security In the final months of 2024, several news stories in Estonia highlighted China’s influence, including its implications for cyber security. One widely discussed topic was whether the city of Tallinn should use TikTok, a platform controlled by the Chinese government – this later evolved into a broader debate on whether Estonia should ban TikTok, which helps train China’s artificial intelligence systems. Another major issue was the arrival of Chinese BYD electric vehicles into the Estonian market, with concerns that their data is transmitted to servers in China, where authorities have access. Discussions also arose over whether Chinese-made routers are secure and should be used. These debates paralleled questions raised in September about members of the Estonian Parliament’s China Friendship Group, some of whom travelled to China on visits partially funded by the Chinese state. All of this unfolds against the broader backdrop of China’s close ties with Estonia’s eastern AI continues to grow neighbour, its stance on Russia’s aggression against Ukraine and its military manoeuvres around Taiwan. China’s role in cybersecurity will not fade in 2025 – or beyond. We expect growing awareness of these red flags to influence consumer and policy decisions. When products from a particular country systematically transmit user data to that country’s authorities – and when that country stands on the opposite side of major global value divides from Estonia and its allies – it is worth thinking twice before buying the latest Chinese gadget or letting children install TikTok on their phones. Artificial intelligence is advancing at an extraordinary pace. In addition to more sophisticated phishing emails, cybercriminals now use AI applications to generate attack codes. In hindsight, it has also become clear that AI-generated code was used in attacks against Estonian heating plants and water stations during the wave of cyber incidents following the outbreak of the Israel-Hamas conflict at the end of 2023. One of the world’s best-known artificial intelligence developers, OpenAI, reported in October 2024 that its AI-powered chatbot, ChatGPT, had been used to prepare cyberattacks, including for developing malware, spreading disinformation and producing phishing messages. The report specifically mentioned China, Iran and Russia. Of course, AI is also being harnessed for defence. Another major data breach on the horizon? Data protection was also featured in last year’s cybersecurity forecast, following several significant data leaks in 2023. At the time, we expressed hope that public exposure of these cases would encourage institutions and companies to improve their ability to protect the personal data entrusted to them. However, just CYBER SECURITY IN ESTONIA 2025 days after the publication of our 2024 yearbook, RIA learned of yet another – and by far the largest – personal data breach in Estonia, details of which are covered in this edition. Fortunately, Estonia has seen no further large-scale violations since then, but there is no reason to assume that the most recent one will be the last. 57

Select target paragraph3