December 12, 2025

Athens News

News in English from Greece

Greek Open University condemns to cyberataka: a leak of 813 GB of personal data


Greek open university announced that in October 2024 he became the victim of the cyber attack, As a result of which personal data with a volume of 813 GB were stolen.

Hacker attack occurred on October 25, using type software Ransomware (Attack of Monitoring Programs), and “The malicious software gained access by intercepting certain rights to the basic infrastructure of information technologies and the reserve copy infrastructure, which led to encryption of the virtual machine management system and failures in the operation of secondary systems and data network.

The encryption did not affect all the backup copies that were restored from the reserve copy infrastructure and used after a thorough security check to restore the university systems and services. According to the statement, the volume of leaked data is 813 GB, However, it is important to clarify that this volume is an extremely small share compared to the total volume of data stored in the institution (the size of several terabytes), which indicates that the leak is limited in scale. ”

Failing files contained, according to the available data, personal data in various file formats (mainly DOC, PDF, Excel). In addition, a leaked file is in Dark network (Dark Web). Open University notified the categories of data that could be stolen:

  • Full name/maternal name
  • Job title
  • Data on relatives
  • Citizenship
  • Floor
  • Date of birth
  • Taxpayer identification number (Αφμ)
  • Social insurance identification number (αμκα)
  • Personality certificate number (αδτ)
  • Signature (physical)
  • Photos
  • User name
  • Contact details (postal address, phone number (stationary and mobile), email address, personal and university, electronic correspondence)
  • Academic and educational data & diplomas (assessments and achievements, diplomas, training certificates)
  • Health data
  • Financial data (IBAN, data for issuing bills, data for payment of expenses)
  • Data of professional and research activities (resume, research/professional/teaching/writing)
  • Data of decisions of collective bodies, decisions of committees
  • Data of contracts, contractors and proposals

Cyberataka were notified Cybercrime Control Officeand also National Cybersecurity Service.



Source link

Verified by MonsterInsights