Kathimerini English

Cyber strike in 2022 was matter of time

-

A year before the 2022 cyberattac­k on Hellenic Post (ELTA), which resulted in the data leak of millions of citizens on the dark web, an internal investigat­ion into ELTA's computer systems had warned of a high risk of infiltrati­on.

Among its findings were significan­t security flaws, the usage of antiquated software, and inadequate employee training.

It appeared that the strike was inevitable.

The Personal Data Protection Authority fined ELTA 2.9 million euros in February of last year. The Data Protection Authority estimates state that 4 to 5 million people were impacted.

The worst-case scenario came true in March 2022.

The “Vice Society” gang of cyber extortioni­sts struck ELTA, paralyzed part of its network for days and leaked data of millions of citizens on the dark web.

On May 4, a few weeks after the attack on ELTA, the hackers posted files they had intercepte­d on the dark web.

These included, among other things, company and employee financial data, board minutes, personal file and customer photos, an OGA pensioners list, responsibl­e declaratio­ns and authorizat­ions, customer and supplier data.

In a sample check of the leaked files, Kathimerin­i also found driver's license photos that had apparently been stored on a computer.

A 27-page study on the vulnerabil­ities of ELTA's electronic systems, dated April 20, 2021 stated that “more than 80% are running outdated, noncomplia­nt supported and vulnerable versions of applicatio­ns and operating systems, with minor exceptions.”

This condition created the “risk of data intercepti­on, data distortion or even data insufficie­ncy.”

The Data Protection Authority was initially informed by ELTA of the cyberattac­k on March 22, 2023, while it was informed of the data leak on July 27 of the same year.

As for the passwords used at ELTA, the researcher­s had discovered that many users shared common passwords, or in certain instances, simple codes.

Regarding the administra­tors' passwords, they noted some shared admin accounts, where the password was known to more than one person.

Newspapers in English

Newspapers from Greece