Growing awareness
of China’s role in cyber security
In the final months of 2024,
several news stories in Estonia
highlighted China’s influence,
including its implications for
cyber security. One widely
discussed topic was whether the
city of Tallinn should use TikTok,
a platform controlled by the
Chinese government – this later
evolved into a broader debate on
whether Estonia should ban
TikTok, which helps train China’s
artificial intelligence systems.
Another major issue was the
arrival of Chinese BYD electric
vehicles into the Estonian
market, with concerns that their
data is transmitted to servers in
China, where authorities have
access. Discussions also arose
over whether Chinese-made
routers are secure and should be
used. These debates paralleled
questions raised in September
about members of the Estonian
Parliament’s China Friendship
Group, some of whom travelled
to China on visits partially
funded by the Chinese state. All
of this unfolds against the
broader backdrop of China’s
close ties with Estonia’s eastern
AI continues
to grow
neighbour, its stance on Russia’s
aggression against Ukraine and
its military manoeuvres around
Taiwan.
China’s role in cybersecurity
will not fade in 2025 – or
beyond. We expect growing
awareness of these red flags to
influence consumer and policy
decisions. When products from
a particular country systematically transmit user data to that
country’s authorities – and when
that country stands on the
opposite side of major global
value divides from Estonia and
its allies – it is worth thinking
twice before buying the latest
Chinese gadget or letting
children install TikTok on their
phones.
Artificial intelligence is advancing
at an extraordinary pace. In
addition to more sophisticated
phishing emails, cybercriminals
now use AI applications to
generate attack codes. In
hindsight, it has also become
clear that AI-generated code was
used in attacks against Estonian
heating plants and water stations
during the wave of cyber incidents
following the outbreak of the
Israel-Hamas conflict at the end
of 2023. One of the world’s
best-known artificial intelligence
developers, OpenAI, reported in
October 2024 that its AI-powered
chatbot, ChatGPT, had been used
to prepare cyberattacks, including
for developing malware, spreading disinformation and producing
phishing messages. The report
specifically mentioned China, Iran
and Russia. Of course, AI is also
being harnessed for defence.
Another major data breach on the horizon?
Data protection was also featured
in last year’s cybersecurity
forecast, following several
significant data leaks in 2023. At
the time, we expressed hope that
public exposure of these cases
would encourage institutions and
companies to improve their ability
to protect the personal data
entrusted to them. However, just
CYBER SECURITY IN ESTONIA 2025
days after the publication of our
2024 yearbook, RIA learned of yet
another – and by far the largest –
personal data breach in Estonia,
details of which are covered in this
edition. Fortunately, Estonia has
seen no further large-scale
violations since then, but there is
no reason to assume that the
most recent one will be the last.
57