{"id":4991,"date":"2026-08-13T11:24:16","date_gmt":"2026-08-13T08:24:16","guid":{"rendered":"https:\/\/webembed.gr\/?p=4991"},"modified":"2026-08-13T11:55:41","modified_gmt":"2026-08-13T08:55:41","slug":"ransomware-at-eoppep-the-real-problem-is-bigger-than-the-attack","status":"publish","type":"post","link":"https:\/\/webembed.gr\/el\/ransomware-at-eoppep-the-real-problem-is-bigger-than-the-attack\/","title":{"rendered":"Ransomware at EOPPEP: The Real Problem Is Bigger Than the Attack"},"content":{"rendered":"<h3><strong>The recent ransomware cyberattack against EOPPEP is another reminder of something we often overlook:<\/strong><\/h3>\n<p class=\"isSelectedEnd\"><strong>Cybersecurity is not only about technology. It is about people, processes, infrastructure, and organizational culture.<\/strong><\/p>\n<p class=\"isSelectedEnd\">On August 5, 2026, EOPPEP was targeted by a ransomware-type cyberattack, affecting the operation of its network and information systems. The organization has stated that recovery activities are underway and that, according to its own assessment, the integrity of its files, registries, and data has been preserved.<\/p>\n<p class=\"isSelectedEnd\">However, this incident deserves much more attention than simply being another example of a public-sector organization being attacked.<\/p>\n<p class=\"isSelectedEnd\">Because ransomware is no longer just malware.<\/p>\n<p><strong>It is a business and operational risk.<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-5005\" src=\"https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-hacker-2851143_1920-1024x665.jpg\" alt=\"Hacked\" width=\"1024\" height=\"665\" srcset=\"https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-hacker-2851143_1920-1024x665.jpg 1024w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-hacker-2851143_1920-300x195.jpg 300w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-hacker-2851143_1920-768x499.jpg 768w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-hacker-2851143_1920-1536x998.jpg 1536w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-hacker-2851143_1920-18x12.jpg 18w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-hacker-2851143_1920-1320x857.jpg 1320w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-hacker-2851143_1920.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<h3>Ransomware Is Not Just &#8220;A Virus&#8221;<\/h3>\n<p class=\"isSelectedEnd\">A modern ransomware attack usually does not begin when the victim sees:<\/p>\n<blockquote>\n<p class=\"isSelectedEnd\"><em>&#8220;Your files have been encrypted.&#8221;<\/em><\/p>\n<\/blockquote>\n<p class=\"isSelectedEnd\">That is often the final stage.<\/p>\n<p class=\"isSelectedEnd\">Before that, attackers may spend days or weeks conducting reconnaissance, stealing credentials, gaining initial access, escalating privileges, moving laterally across the network and, in many cases, exfiltrating sensitive information.<\/p>\n<p class=\"isSelectedEnd\">A typical attack chain can look like:<\/p>\n<p class=\"isSelectedEnd\"><strong>Initial Access \u2192 Persistence \u2192 Privilege Escalation \u2192 Lateral Movement \u2192 Data Discovery \u2192 Exfiltration \u2192 Backup Destruction \u2192 Ransomware Deployment<\/strong><\/p>\n<p class=\"isSelectedEnd\">This is why ransomware response cannot simply be:<\/p>\n<p class=\"isSelectedEnd\"><strong>&#8220;Restore the backup and move on.&#8221;<\/strong><\/p>\n<p class=\"isSelectedEnd\">Before recovery, much more important questions need to be answered:<\/p>\n<ul data-spread=\"false\">\n<li>How did the attacker gain access?<\/li>\n<li>Which system was compromised first?<\/li>\n<li>Which credentials were used?<\/li>\n<li>How long did the attacker remain inside the environment?<\/li>\n<li>Which systems did they access?<\/li>\n<li>Did they access personal data?<\/li>\n<li>Was data exfiltrated?<\/li>\n<li>Were privileged accounts compromised?<\/li>\n<li>Were backups affected?<\/li>\n<li>Did the organization have sufficient logging to reconstruct the attack timeline?<\/li>\n<\/ul>\n<p>These are questions for the SOC and IT teams, but also for management and the DPO.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-5007\" src=\"https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5042249_1920-1024x683.jpg\" alt=\"Security\" width=\"1024\" height=\"683\" srcset=\"https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5042249_1920-1024x683.jpg 1024w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5042249_1920-300x200.jpg 300w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5042249_1920-768x512.jpg 768w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5042249_1920-1536x1024.jpg 1536w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5042249_1920-18x12.jpg 18w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5042249_1920-1500x1000.jpg 1500w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5042249_1920-1320x880.jpg 1320w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5042249_1920.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<h3>Ransomware and GDPR<\/h3>\n<p class=\"isSelectedEnd\">There is an important misconception about ransomware:<\/p>\n<p class=\"isSelectedEnd\"><strong>A ransomware attack does not automatically mean that personal data was leaked.<\/strong><\/p>\n<p class=\"isSelectedEnd\">However, a data breach does not require confirmed public disclosure of data either.<\/p>\n<p class=\"isSelectedEnd\">Under GDPR, a personal data breach can involve the destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to personal data.<\/p>\n<p class=\"isSelectedEnd\">Therefore, if ransomware encrypts personal data and makes it unavailable, there is already a potential GDPR issue that must be assessed.<\/p>\n<p class=\"isSelectedEnd\">If the attacker also copied the data before encrypting it, the situation becomes considerably more serious.<\/p>\n<p class=\"isSelectedEnd\">We may then have an incident affecting:<\/p>\n<p class=\"isSelectedEnd\"><strong>Confidentiality + Integrity + Availability.<\/strong><\/p>\n<p class=\"isSelectedEnd\">This is where the well-known <strong>72-hour GDPR requirement<\/strong> becomes relevant.<\/p>\n<p class=\"isSelectedEnd\">When a personal data breach is likely to result in a risk to the rights and freedoms of individuals, the data controller must generally notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach.<\/p>\n<p class=\"isSelectedEnd\">Importantly, the organization does not necessarily need to have completed the entire forensic investigation within those 72 hours.<\/p>\n<p class=\"isSelectedEnd\">Initial notification and subsequent supplementary information can form part of the process.<\/p>\n<p class=\"isSelectedEnd\">This is why <strong>incident response and GDPR compliance cannot be treated as two completely separate processes.<\/strong><\/p>\n<p>They must operate in parallel.<\/p>\n<div class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-5016\" src=\"https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/cliff1126-hacker-8003399_1920-1024x574.jpg\" alt=\"hacker-2\" width=\"1024\" height=\"574\" srcset=\"https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/cliff1126-hacker-8003399_1920-1024x574.jpg 1024w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/cliff1126-hacker-8003399_1920-300x168.jpg 300w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/cliff1126-hacker-8003399_1920-768x430.jpg 768w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/cliff1126-hacker-8003399_1920-1536x861.jpg 1536w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/cliff1126-hacker-8003399_1920-18x10.jpg 18w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/cliff1126-hacker-8003399_1920-1320x740.jpg 1320w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/cliff1126-hacker-8003399_1920.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div>\n<h3>And Then We Reach a Bigger Problem: Legacy Systems<\/h3>\n<div>\n<p class=\"isSelectedEnd\">The EOPPEP incident should not be used as an excuse to blame the people responsible for maintaining its infrastructure.<\/p>\n<p class=\"isSelectedEnd\">There is, however, a broader issue affecting a significant part of the public sector:<\/p>\n<p class=\"isSelectedEnd\"><strong>Legacy infrastructure.<\/strong><\/p>\n<p class=\"isSelectedEnd\">Information systems designed and implemented many years ago continue to support critical public services.<\/p>\n<p class=\"isSelectedEnd\">Being old does not automatically mean that a system is insecure.<\/p>\n<p class=\"isSelectedEnd\">The problem arises when a legacy system:<\/p>\n<ul data-spread=\"false\">\n<li>is no longer supported by its vendor,<\/li>\n<li>cannot be easily upgraded,<\/li>\n<li>relies on outdated libraries or protocols,<\/li>\n<li>depends on obsolete operating systems,<\/li>\n<li>cannot integrate properly with modern security controls,<\/li>\n<li>provides limited logging,<\/li>\n<li>does not support modern authentication mechanisms,<\/li>\n<li>cannot effectively run modern EDR\/XDR solutions,<\/li>\n<li>or represents a critical dependency within a much larger information ecosystem.<\/li>\n<\/ul>\n<p class=\"isSelectedEnd\">This creates a vicious cycle.<\/p>\n<p class=\"isSelectedEnd\"><strong>We cannot upgrade it because it is old.<br \/>\nWe cannot replace it because it is critical.<br \/>\nWe cannot shut it down because it supports an essential service.<br \/>\nSo we continue protecting it with infrastructure and processes that are also aging.<\/strong><\/p>\n<p class=\"isSelectedEnd\">This is technical debt.<\/p>\n<p>But in cybersecurity, technical debt can become <strong>security debt<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-5013\" src=\"https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5043368_1920-1024x609.jpg\" alt=\"Security-3\" width=\"1024\" height=\"609\" srcset=\"https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5043368_1920-1024x609.jpg 1024w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5043368_1920-300x178.jpg 300w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5043368_1920-768x457.jpg 768w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5043368_1920-1536x914.jpg 1536w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5043368_1920-18x12.jpg 18w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5043368_1920-1320x785.jpg 1320w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/elchinator-security-5043368_1920.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<h3>The Weakest Point May Not Be the System<\/h3>\n<p class=\"isSelectedEnd\">It may be the human being operating it.<\/p>\n<p class=\"isSelectedEnd\">And this is perhaps one of the most important lessons from every ransomware incident.<\/p>\n<p class=\"isSelectedEnd\">It is not enough to train the IT department.<\/p>\n<p class=\"isSelectedEnd\">A system administrator needs to understand:<\/p>\n<ul data-spread=\"false\">\n<li>how ransomware operates,<\/li>\n<li>how lateral movement works,<\/li>\n<li>why Domain Admin accounts should not be used for everyday activities,<\/li>\n<li>how privileged credentials should be protected,<\/li>\n<li>why MFA matters,<\/li>\n<li>how to isolate a compromised endpoint,<\/li>\n<li>why backups should be immutable or offline,<\/li>\n<li>what logs need to be collected,<\/li>\n<li>and how suspicious behavior can be identified.<\/li>\n<\/ul>\n<p class=\"isSelectedEnd\">But the ordinary employee also needs to understand:<\/p>\n<ul data-spread=\"false\">\n<li>what a phishing email looks like,<\/li>\n<li>why suspicious attachments should not be opened,<\/li>\n<li>why passwords should not be reused,<\/li>\n<li>why MFA matters,<\/li>\n<li>why unauthorized software should not be installed,<\/li>\n<li>when suspicious activity should be reported,<\/li>\n<li>and, most importantly:<\/li>\n<\/ul>\n<p><strong>Reporting a suspicious email is not &#8220;bothering IT.&#8221; It is a security control.<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-5009\" src=\"https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-security-4302572_1920-1024x707.jpg\" alt=\"Security-2\" width=\"1024\" height=\"707\" srcset=\"https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-security-4302572_1920-1024x707.jpg 1024w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-security-4302572_1920-300x207.jpg 300w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-security-4302572_1920-768x530.jpg 768w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-security-4302572_1920-1536x1061.jpg 1536w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-security-4302572_1920-18x12.jpg 18w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-security-4302572_1920-1320x912.jpg 1320w, https:\/\/webembed.gr\/wp-content\/uploads\/2026\/08\/thedigitalartist-security-4302572_1920.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<h3>Responsibility Cannot Always Fall on the IT Administrator<\/h3>\n<p class=\"isSelectedEnd\">There is another issue that is often overlooked.<\/p>\n<p class=\"isSelectedEnd\">When an information system is 15 or 20 years old, an administrator can do an excellent job and still face serious technical limitations.<\/p>\n<ul>\n<li class=\"isSelectedEnd\">They cannot install a security update that the application does not support.<\/li>\n<li class=\"isSelectedEnd\">They cannot enforce MFA on an application that was designed before MFA became standard.<\/li>\n<li class=\"isSelectedEnd\">They cannot deploy modern EDR on an unsupported operating system.<\/li>\n<li class=\"isSelectedEnd\">They cannot fully isolate a system when it has to communicate with ten other legacy systems.<\/li>\n<li class=\"isSelectedEnd\">They cannot replace a critical application without budget, time, planning, and management approval.<\/li>\n<\/ul>\n<p class=\"isSelectedEnd\">Therefore, cybersecurity is not exclusively a technical responsibility.<\/p>\n<p class=\"isSelectedEnd\"><strong>It is a management responsibility.<\/strong><\/p>\n<p class=\"isSelectedEnd\">Management determines how much cyber risk an organization is willing to accept.<\/p>\n<div contenteditable=\"false\">\n<hr \/>\n<\/div>\n<h3>From Cybersecurity to Cyber Resilience<\/h3>\n<p class=\"isSelectedEnd\">Perhaps this is the most important lesson.<\/p>\n<p class=\"isSelectedEnd\">The goal cannot be:<\/p>\n<p class=\"isSelectedEnd\"><strong>&#8220;We must never be attacked.&#8221;<\/strong><\/p>\n<p class=\"isSelectedEnd\">That is unrealistic.<\/p>\n<p class=\"isSelectedEnd\">The goal should be:<\/p>\n<p class=\"isSelectedEnd\"><strong>&#8220;If we are attacked, we must detect it quickly, contain it, protect our data, and restore critical services in a controlled manner.&#8221;<\/strong><\/p>\n<p class=\"isSelectedEnd\">That is <strong>Cyber Resilience<\/strong>.<\/p>\n<p class=\"isSelectedEnd\">And for a public-sector organization, this is even more important.<\/p>\n<p class=\"isSelectedEnd\">When an organization&#8217;s information system goes down, it is not simply a company experiencing downtime.<\/p>\n<ul>\n<li class=\"isSelectedEnd\">A public service may become unavailable.<\/li>\n<li class=\"isSelectedEnd\">A citizen&#8217;s application may be delayed.<\/li>\n<li class=\"isSelectedEnd\">A deadline may be affected.<\/li>\n<li class=\"isSelectedEnd\">Administrative and financial costs may increase.<\/li>\n<li class=\"isSelectedEnd\">And, in the worst-case scenario, citizens&#8217; personal data may be compromised.<\/li>\n<\/ul>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The recent ransomware cyberattack against EOPPEP is another reminder of something we often overlook: Cybersecurity is not only about technology. It is about people, processes, infrastructure, and organizational culture. On August 5, 2026, EOPPEP was targeted by a ransomware-type cyberattack, affecting the operation of its network and information systems. The organization has stated that recovery [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4999,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[96,86,79,216,217,102,158],"class_list":["post-4991","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cyber-security","tag-cyberawareness","tag-cybersecurity","tag-gdpr","tag-hacking","tag-hacking-prevention","tag-ransomware"],"_links":{"self":[{"href":"https:\/\/webembed.gr\/el\/wp-json\/wp\/v2\/posts\/4991","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/webembed.gr\/el\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/webembed.gr\/el\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/webembed.gr\/el\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/webembed.gr\/el\/wp-json\/wp\/v2\/comments?post=4991"}],"version-history":[{"count":5,"href":"https:\/\/webembed.gr\/el\/wp-json\/wp\/v2\/posts\/4991\/revisions"}],"predecessor-version":[{"id":5018,"href":"https:\/\/webembed.gr\/el\/wp-json\/wp\/v2\/posts\/4991\/revisions\/5018"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/webembed.gr\/el\/wp-json\/wp\/v2\/media\/4999"}],"wp:attachment":[{"href":"https:\/\/webembed.gr\/el\/wp-json\/wp\/v2\/media?parent=4991"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/webembed.gr\/el\/wp-json\/wp\/v2\/categories?post=4991"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/webembed.gr\/el\/wp-json\/wp\/v2\/tags?post=4991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}