
Phishing Attacks in Estonia: How to Detect and Avoid Them
Phishing is the #1 cyberattack type in Estonia. Practical examples and tips to keep your employees and business data safe.
Author: Meiko Neuman
Founder and web strategist, Kodulehe Haldus
The Reality of Phishing in Estonia
RIA (Information System Authority) 2024 Report: 60% of Estonian cyber incidents start with phishing. Main targets include: - Banks (using the names of Swedbank, SEB, LHV) - Tax and Customs Board (e-MTA) - Smart-ID / Mobile-ID - Parcel terminals (Omniva, DPD) - Eesti.ee services
Typical Types of Phishing
1. General Phishing Mass emails – the same message sent to thousands. Low quality, easy to detect.
2. Spear Phishing Targeted – uses personal data (name, company, colleague). 50% more effective.
3. Whaling Target = executive. Often a "boss" email requesting a money transfer.
4. Smishing SMS-based. "Your package is awaiting customs clearance" link.
5. Vishing Phone calls. "Swedbank customer support" asking for a password.
6. Business Email Compromise (BEC) Hacked business email used to send payment requests.
Warning Signs
Email - Sender domain is slightly off (`swedbank-ee.com` vs `swedbank.ee`) - Sense of urgency ("do this within 24h") - Fear tactics ("account will be blocked") - Slightly unnatural Estonian language - Formatting does not match the usual standard - Links display one URL but lead to another
Web - HTTPS present, but a strange domain - Certificate recently issued - Grammatical errors on the page - Low-resolution logo - Requests different information than a real bank
Phone - "Bank" calls and asks for a password (banks NEVER do this) - Pressures you to act quickly - Asks you to confirm something via Smart-ID that you did not initiate
Real Examples (Estonia 2024-2025)
Example 1: "Swedbank Security Update" An email claimed the account would be blocked if not confirmed via Smart-ID within 24 hours. The link led to a fake Swedbank page where the user was asked to "confirm" with Smart-ID – in reality, this granted authorization to the hacker.
Lesson: Swedbank does not send such emails. See also Smart-ID safety warnings.
Example 2: "Omniva Package Customs Fee" SMS: "Your package is awaiting a €2.50 customs fee. Pay here: [link]". The link led to a fake payment page that stole credit card details.
Lesson: Omniva does not request customs fees via SMS.
Example 3: BEC in Accounting Hackers gained access to an accountant's email. They sent a client an invoice with a new account number. €18,000 vanished.
Lesson: Confirm all changes to payment information over the phone.
Employee Training
Monthly Programme 1. Sending phishing simulations (test emails) 2. Analysis of results 3. Individual training for those who clicked 4. Monthly training on a new topic
Tools - [KnowBe4](https://www.knowbe4.com/) – most well-known platform - [PhishMe / Cofense](https://cofense.com/) - [Hoxhunt](https://hoxhunt.com/) – founded in Finland
Technical Measures
Email - **SPF, DKIM, DMARC** all three configured - Anti-phishing filters (offered by Microsoft 365, Google Workspace) - Sandboxing for suspicious attachments - "External sender" warning label
Browser - [uBlock Origin](https://github.com/gorhill/uBlock) - [Cloudflare 1.1.1.1 for Families](https://1.1.1.1/family/) - Built-in browser Safe Browsing
Endpoint - EDR software (CrowdStrike, SentinelOne) - Auto-updates - Standard user account (not admin) for daily use
What to Do If You Clicked?
First 10 Minutes 1. **DO NOT panic** 2. Disconnect the computer from the network 3. Change passwords from a different device 4. Call the bank if you entered banking details 5. Activate 2FA everywhere
First 24 Hours 1. Scan the computer with antivirus software 2. Change all passwords (see [password managers for businesses](/blogi/parolihaldurid-ettevotetele)) 3. Review bank account transactions 4. Report to the IT department 5. Report to RIA: cert@cert.ee
GDPR Aspect
If client data was leaked due to phishing: - Notify the Data Protection Inspectorate within 72h - Notify affected clients - Document the course of the incident - See GDPR compliance for websites
Summary
Phishing is an exploitation of human weakness, not a technical problem. Technical protection + regular training = stopping 95% of attacks. We offer security audits and employee training programmes – get in touch.
Sources
Need help with your website?
Our team maintains, optimises and protects your website. Pricing is agreed based on scope.
Request a quoteAbout the author
Meiko Neuman — Founder and web strategist, Kodulehe Haldus. Meiko leads the Kodulehehaldus team and has spent over a decade helping companies maintain and optimise their websites for measurable business results. He writes about website management, SEO, AEO/GEO and the commercial side of the web.