EYP is preparing for a future cyberwar: The National Intelligence Service is preparing for the possibility of a large-scale electronic war. In response to the tension in the region, it is starting to shield critical government infrastructure from possible cyberattacks. According to information from "K", in the immediate future and for the coming months, EYP will carry out vulnerability checks on a series of government targets, such as the Maximos Palace, the Presidential Palace and the Ministry of Finance. The results of the tests (penetration tests) will be confidential and the government leadership will be informed about them initially. Depending on the findings, there will be initiatives to strengthen the digital security of sensitive organizations. International developments, moreover, reveal an increasing use of electronic weapons in international conflicts and disputes between states. The recent conflict between Israel and Iran, although it was "minor" due to the pandemic, is a revealing example.

In late April, there were serious irregularities in the operation of Israel’s water and sewage systems. The country’s competent national agency – the corresponding EYDAP – initially attributed the problem to technical malfunctions, but later admitted that its systems had been the target of a cyber attack. There were reports in the country’s press that the attack had been launched by Iran using servers in the US and Europe. On May 9, Iran’s largest commercial port, Shahid Rajaee near the Strait of Hormuz, was put out of service as a result of a large-scale cyberattack. A Washington Post article attributed the attack to Israel, while the revelations were indirectly confirmed by the Chief of the Israeli Defense General Staff, Aviv Kochavi, stating that “Israel will continue to act against its enemies with many and different tools.”
The government and the EYP first thought about shielding critical government infrastructures from the possibility of electronic warfare in January when the Turks managed to disable government websites, such as those of the Ministry of Foreign Affairs, the Ministry of Finance, the Parliament and even the EYP itself. The Turkish group “Anka Neferler” claimed responsibility for those attacks. In a post on Facebook, it wrote: “Greece threatens Turkey in the Aegean and the Eastern Mediterranean. And now it threatens the Libya conference.” The attack did not cause damage to the electronic and computer systems of sensitive government organizations, but it had alarmed the government and the National Intelligence Service. In the period that followed, there were discussions between EYP executives and the competent authority of the Ministry of Digital Policy in order to take immediate measures to strengthen cybersecurity. However, the spread of the coronavirus and the global health crisis only temporarily "froze" developments.

Problem recording
According to information from "K", in the immediate future, the EYP, following consultation with the National Cybersecurity Authority, will begin vulnerability checks on ten "critical" government targets. Executives of the service, with the help of specialized personnel, will carry out virtual electronic attacks and attempts to penetrate the computer systems of ministries and other state bodies. The aim of the process is to identify and record problems that exist in two areas. The first concerns the security policy of the Organizations: Which employees have access to specific computers? Which computers or servers have security codes? When do these codes change? The problems will be highlighted to the Organizations' administrations so that they can be addressed immediately, since their "treatment" does not require money.
The second objective of the tests is to check whether the servers, computers and the programs they use can meet modern security requirements or need to be replaced. There is concern that due to the ten-year economic crisis in the country, most of the systems are technologically outdated and therefore vulnerable to cyberattacks.

As "K" had revealed in April 2019, the Maximos Palace, the Ministry of Foreign Affairs, the Hellenic Security Service and the Hellenic Police were targets of cyber espionage. According to cross-checked information, the perpetrators had managed to gain access to the internal networks of state services and intercept their electronic correspondence. The attack had been detected due to a malfunction in the use of emails, while the audit had revealed that the problem was due to a cyberattack against the registry of Internet names with the endings .gr and .ελ, the technical support of which is provided by the Research Technology Foundation in Heraklion, Crete.
The vulnerability checks by the EYP will last approximately 10 months and will be limited to state services and structures. Furthermore, the Cyber Defense Directorate of the General Staff of National Defense (GHND) is responsible for the digital security of public utility organizations, such as PPC or EYDAP.
Exchange of fire from hackers
Following the cyberattacks of last January, Turkish hackers “broke down” the website of the Municipality of Chalkidonos, Thessaloniki, on June 7. They changed the look of the front page and posted a photo of Kemal Ataturk with the slogan “Know your limits”. A group of Turkish hackers who sign as “the cyber army of Turkey” claimed responsibility for the attack. The peculiar electronic warfare continued, as the Anonymous Greece group attacked – in retaliation – the website of the Turkish Ministry of National Defense, putting it out of operation. “After an attack that Greece and specifically a municipality (something insignificant for us) received from Turkey, we also proceeded with an attack. The Turkish Ministry of National Defense is out,” the members of the Greek group said in a post.
Source: https://www.kathimerini.gr/
