Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Attacks - Greece’s 2024 Cyber Threat Landscape: A Year of Increased and Varied Attacks
Attacks Articles Data Protection Security

Greece’s 2024 Cyber Threat Landscape: A Year of Increased and Varied Attacks

Anastasios ArampatzisBy Anastasios ArampatzisJanuary 7, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Cyber Threat
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The year 2024 proved challenging for cybersecurity in Greece, with a significant surge in the volume and sophistication of cyberattacks. Ransomware attacks, Distributed Denial-of-Service (DDoS) attacks, and Advanced Persistent Threats (APTs) all significantly disrupted businesses, government services, and critical infrastructure. Efstratios Lontzetidis, a Cyber Threat Intelligence Researcher based in Greece, provided a compelling round up of the most essential threats facing Greece in the past year. Let’s take a quick look at the highlights.

Ransomware Attacks Intensify

Ransomware emerged as a dominant threat in Greece throughout 2024, affecting education, retail, shipping, and media sectors. Notably, groups like RansomHub and Akira expanded their operations within the country, utilizing double-extortion tactics to maximize impact.

The education sector was notably impacted when the Hellenic Open University (HOU) was victim to a RansomHub attack on November 1st. The attack exfiltrated 813 GB of sensitive data, disrupting operations at Greece’s sole institution dedicated to open and distance learning.

In the retail sector, Fourlis Group, which operates IKEA and Intersport in Greece and neighboring countries, suffered a ransomware attack on November 27th—the timing, coinciding with the Black Friday shopping period, crippled e-commerce operations. Although no data leaks were detected, the disruption highlighted vulnerabilities in interconnected retail systems.

Other significant ransomware incidents included attacks on Eurobulk Ltd. (shipping), Barkingwell Media S.A. (media), and Antaeus Travel Group (travel), demonstrating the varied targeting strategies of ransomware groups.

Critical Infrastructure Under Attack

Government websites and online services were frequently targeted, impacting citizen access to essential information and resources.

For example, in July 2024, the Greek Land Registry agency was breached, compromising employee terminals and stealing 1.2 GB of administrative documents. Although no citizens’ personal information was affected, the incident highlighted the vulnerabilities within critical government systems.

On March 15, 2024, the Anonymous Collective launched a DDoS campaign against Greece’s largest ISP provider, COSMOTE. The attackers accused the country of supporting Israel amid ongoing tensions in the Middle East. The attackers claimed that they temporarily disabled the ISP’s website and DNS servers.

Similarly, a threat actor known as NoName057(16) collective orchestrated a wave of DDoS attacks on Greek institutions, including the Ministry of Infrastructure and Transport, Thessaloniki Metro, and Piraeus Bank. These incidents targeted various sectors, including government, transport, and finance, highlighting the wide range of essential services at risk. The attacks caused temporary disruptions in operations, underscoring Greece’s need to enhance its cyber resilience.

APT Groups Target Strategic Sectors

Advanced Persistent Threat (APT) groups, known for their sophisticated tactics and long-term objectives, targeted various sectors in Greece, including maritime and government. These groups often engage in espionage and data exfiltration, seeking to gain access to sensitive information and intellectual property.

The maritime industry, a key contributor to Greece’s economy, faced persistent threats from APT groups seeking to disrupt operations and steal valuable data. Government institutions also remained a prime target, with APT groups aiming to infiltrate critical systems and gain access to confidential information.

Emerging Trends and Predictions for 2025

The cyber threat landscape in Greece is expected to evolve further in 2025, following similar trends in the EU and elsewhere:

  • Increased Sophistication of Attacks: Cybercriminals will likely continue employing AI to advance their techniques further, making detection and prevention increasingly challenging.
  • Targeting of Critical Infrastructure: Sectors such as energy, transportation, and healthcare may face heightened risks as attackers aim to disrupt essential services.
  • Supply Chain Vulnerabilities: As organizations continue to digitize and integrate with third-party vendors, supply chain attacks, exploiting weaker links in the security chain, are expected to rise.
  • Regulatory Pressures: With cyber incidents increasing in frequency, regulatory bodies have imposed stricter compliance requirements, such as DORA and NIS2, compelling organizations to enhance their cybersecurity postures.

Recommendations for Organizations

To mitigate these evolving threats, organizations in Greece (and not only) should consider the following measures:

  1. Implement Comprehensive Security Frameworks: Adopting robust cybersecurity frameworks can help identify and address potential vulnerabilities.
  2. Conduct Regular Risk Assessments: Periodic evaluations of security measures can ensure they remain effective against emerging threats.
  3. Enhance Employee Training: Educating staff about cybersecurity best practices can reduce the risk of successful phishing and social engineering attacks.
  4. Establish Incident Response Plans: A well-defined response strategy can minimize the impact of potential breaches.
  5. Collaborate with Cybersecurity Experts: Engaging with professionals can provide insights into the latest threat intelligence and effective defense mechanisms.

Concluding Thoughts

“The cyber threat landscape of Greece in 2024 is an eye-opener, showing just how critical it is to stay alert and take proactive steps to defend against attacks,” said Lontzetidis when asked to comment. “From Ransomware and DDoS campaigns to APT activities, none of these seemed to exclude any sector from its ambit. This underlines the need for organizations to harden their defenses through advanced technologies, adherence to proven security frameworks, and collaboration with cybersecurity experts.”

The cyber threat landscape in Greece has become increasingly complex, necessitating proactive and comprehensive approaches to cybersecurity. Organizations can better protect themselves against the evolving cyber threats anticipated in 2025 by staying informed about emerging trends and implementing robust security measures.

“As we move into 2025, flexibility and preparedness are more critical than ever as attackers leverage AI. Cybersecurity is no longer a technical issue; it’s a strategic imperative to protect national and organizational assets,” states Lontzetidis.

Anastasios Arampatzis
Anastasios Arampatzis

Anastasios Arampatzis is a cybersecurity content strategist, writer, and consultant with expertise in cybersecurity, digital identity, and regulatory compliance. Tassos has a strong background in creating thought leadership content, marketing materials, and strategic communications tailored to CISOs, security professionals, and business leaders. He has contributed to various cybersecurity publications and collaborates with organizations to develop compelling, insightful content that addresses industry challenges. He is a privacy advocate and a member of the ISC2 Hellenic Chapter. Before joining Bora, Tassos was an Hellenic Air Force Officer with a solid background on IT and Infosec.

  • Anastasios Arampatzis
    The quiet revolt: what the world happiness report 2026 tells security professionals
  • Anastasios Arampatzis
    Cybersecurity and the Power of Words: Why Security Must Be in Our DNA
  • Anastasios Arampatzis
    Have You Read the F***ing Policy?
  • Anastasios Arampatzis
    When Innovation Meets Education: Caution Before Celebrating ‘OpenAI for Greece’

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet

June 1, 20265 Mins Read

Threat Actors Deploy Tiflux RMM for Persistent Remote Access

May 29, 20263 Mins Read

Cyberattack on West Pharmaceutical halts manufacturing across multiple sites

May 15, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}