Archive notice: This article was originally published on January 29, 2008. Links and embedded videos are preserved as part of the historical record.
the 20-year-old was involved in the attacks on the Baltic country’s IT infrastructure, which had temporarily cut off the whole of Estonia from the global internet in spring 2007. The suspicion that the Russian government had been behind the attacks could not be proven. However, parts of the botnet used for the attack had previously been observed in similar attacks on servers belonging to the Russian opposition, such as former world chess champion Garry Kasparov.
“I very much doubt that a single person is actually responsible for the cyberattack in Estonia,” says Toralv Dirro, a security expert at McAfee Germany. From a technical perspective, this would certainly be feasible, but the assumption that there were several perpetrators was nevertheless an obvious one. “It is extremely unlikely, however, that one individual has control over several large botnets,” Dirro explains. There were also serious doubts about this court ruling in terms of the way the cyberattack was conducted in this case. “Botnets are generally used primarily to make money,” the McAfee expert explains. Using such a method to attack an entire country had so far been a rare exception.
“A whole series of such cyberattack cases have already become known in the USA,” says Dirro. But there too, botnets had been used exclusively for commercial purposes. “There are now quite good technical solutions for protecting individual websites,” the security expert adds. However, when an entire country is attacked, as in the current example, complete protection is effectively impossible. “In such cases, it would certainly make sense to introduce controls at the level of the major providers,” says Dirro.
After a Russian war memorial was moved from the capital Tallinn, servers belonging to the Estonian government and to banks, newspapers and other companies became targets of cyberattacks. The Estonian government had claimed that the attacks originated from Kremlin computers and subsequently involved the EU and NATO. Russian involvement in the cyberattacks was never proven, however.