ELTA's IT systems were subjected to a cyberattack early Monday morning. According to media outlets that published an ELTA press release, the hackers demanded a ransom in order to "free" the services they had effectively held hostage. ELTA's outdated IT systems appear to have made it easier for the hackers to breach them, while their actions are believed to have begun months earlier without being noticed.
The breach of the Hellenic Post Office (ELTA) that took place on the night of Sunday, March 20, was significant enough to cause disruptions in government agencies, companies, and citizens for whom the delivery of mail is particularly important.

During the cyberattack on ELTA, the hackers appear to have had full access to the organization's internal network (Intranet). They had the ability to extract data, delete data or alter it as they pleased, or even make money by selling a large amount of information on Greek citizens.
ELTA Cyberattack: The Chronicle of the Breach
According to the information that has been made public, malicious code initially infected an ELTA workstation (possibly an employee) which then connected to a server controlled by a group of cybercriminals via the https reverse shell technique. The attackers then pivoted within the Organization's internal network, resulting in the infection of additional systems.

Subsequently, malicious code was executed on the systems under the hackers' control, resulting in the mass encryption of ELTA's main servers and terminals. They even locked the information systems with a random encryption key, known only to the cybercriminals, demanding a ransom in order to restore them to proper functioning.
The targeted cyberattack against the Hellenic Postal Services (ELTA), with simultaneous encryption of the infected terminals & servers, resulted in the organization's financial transactions not being possible for many days.
In fact, as an official who wishes to remain anonymous told SecNews, "Think about how ELTA manages the names, accounts and addresses of almost every citizen of this country. The personal data base they have at their disposal is highly up-to-date and valuable. The theft of this information will certainly have a high price for any would-be hacker in the illegal darknet markets where databases are exchanged..."

During the attack, the hackers appear to have had full access to the organization's internal network (Intranet). They had the ability to extract data, delete data or alter it as they pleased, or even make money by selling a large amount of information on Greek citizens.
It seems that due to the outdated equipment & software used by ELTA, the actions of the malicious users did not require particularly high knowledge. Furthermore, as is evident from the result, no measures had been taken to protect the terminals & servers containing personal data (a fact that should have been a top priority for the Organization) as a result of which the hackers were able to gainaccess with particularly easy techniques, without being detected by threat detection systems.
The EYP has already advanced its investigation and is reported to have identified the perpetrators. At the same time, the organization assures that there is no longer any danger from the attack and the information systems have been partially restored.
The Ministry of Digital Policy, Communications and Information Technology said that the Athens-based ELTA was targeted byone of the most damaging cyberattacks ever against a Greek company. Authorities say most of the company’s back-end systems have already been restored, while additional security controls have been put in place to prevent a similar cyberattack from happening again. The company’s multiple IT systems include email, web development, invoicing and payment processing software, as well as pension payments.
ELTA Cyberattack: Greek citizens' databases on the Dark Web "under the hammer"?
According to similar attacks in the past on organizations that managed a large volume of personal data, when a database containing data from almost 1 million users was breached, its sale on the Darknet started at prices of 600 thousand euros and above. Depending on the organization or company from which the data was intercepted, the sale prices can be much higher.
Finally, are Turkish hackers behind the damaging cyberattack on ELTA? If so, are we probably talking about an attack that is an omen of a larger-scale threat from the neighboring country? Is the successful cyberattack on critical state infrastructure a warning to Greece or a reminder that in an impending cyberwar our cyberdefenses are nonexistent? Are we such an easy target, after all? Today ELTA, tomorrow who?
Hackers have become increasingly active in recent years. We have witnessed several successful attacks not only on Greek agencies, but also on foreign ones. Think of the revelations of Edward Snowden, who revealed impressive evidence of US spying in Greece and throughout Europe. But how effective can their actions be? We recently learned that the said spy agency purchased a database containing information on over 750,000 citizens for approximately 500,000 euros. One would think that such an amount could be even higher given the value that these databases provide to the spy agency itself – simply because the information would be enough to create a new identity for each citizen or even multiple identities!
ELTA Cyberattack: Mapping the Threat Landscape
SecNews conducted research to determine the Organization's level of exposure to threats (Threat landscape), in order to possibly determine the entry point of the malicious hackers from where the attack began.
But how sure can we be that cyberspies did not leave malware or backdoors in ELTA to maintain their access to critical infrastructure?
Using specialized tools and services, it was found that the IT infrastructure of ELTA was exposed to a number of open access ports (21/FTP, 1723/VPN, 22/SSH, 3389 Remote Desktop) already in 2018. All the data shown in this research is data that is available to EVERYONE via the internet using specialized threat landscape monitoring services. This data could therefore be at the disposal of hackers/ cyber spies for use.

As of 2018, it already appears that there were open entry/access ports (by authorized personnel) that could be exploited by malicious hackers. The diagram below shows the ports that were active.

We also find that in March 2022 (we assume after the attack) the authorities began to gradually close the exposed access ports. An important element is the fact that there was a server (server/workstation) that had port 3389 (Remote Desktop) enabled. Many malware, according to studies by security companies abroad, use this specific port, so that with brute force techniques, they identify weak passwords and gain access to the infrastructure.

The data in this snapshot shows the exact entry ports that were active from November 2021 to April 2022. We note that port 3389 (Remote Desktop), which may have been the backdoor for hackers/attackers, remained open for a very long time.

As is evident in the diagram, the Organization's exposed services were increasing until March 2022, when measures were taken to limit the exposed services.
The officials of the Information Technology Directorate appear to have taken action by restricting access to the specific server and service that was fully open to the internet for anyone after the attack.

The entries that can be found in vulnerability search engines refer to the IP addresses below.

But how sure can we be that cyberspies did not leave malware or backdoors in ELTA in order to maintain their access to critical infrastructure? A question that should certainly concern the responsible IT Department.

From the above information available on the internet, one can see that the attackers did not have a particularly high level of knowledge, since they were able to use publicly available tools to identify weak access points in the Organization and achieve their goal.
ELTA Cyberattack: The Disaster Recovery site is still... on the way!
According to EXCLUSIVE information that reached SecNews through the anonymous complaints platform that SecNews has created and provides to anyone who wishes to securely share any information, ELTA had announced a tender for the creation of a Datacenter Recovery Center. More specifically, ELTA had announced an open tender to select a contractor for the project "Creation and provision to ELTA of a main and backup Data center infrastructure (disaster recovery site) as a service. All documents are freely posted on the internet. This tender had a deadline for submitting bids on 05-01-2022 of this year.

However, it appears that it received a second postponement (for unspecified reasons) on 07-02-2022 to 31-03-2022

And a third postponement for 08.04.2022. We note that the attack was detected according to ELTA on the evening of Sunday, March 20 to March 21, 2022.

Can the authorities answer the question: if ELTA's information systems had a main and backup Datacenter infrastructure (Disaster recovery), would the incident in question have been avoided without the slightest problem?
Furthermore, what are the reasons why this competition has not been deemed fruitful to date?
ELTA Cyberattack: Identity of hackers & Phishing SMS to unsuspecting citizens!
A few days after the cybercriminals' attack, according to information received by SecNews from readers who do not wish to make their identities public, the following SMS messages began to appear to Greek citizens.

In these SMS, unknown people, with Phishing URLs, try to gain access to personal data. The website mentioned rb.gy is a well-known URL Shorterner that allows the destination URL to be masked. Investigating this link, the SecNews research team found that it connects to a Turkish company related to health applications based in Istanbul.
Finally, are Turkish hackers behind the damaging cyberattack on ELTA? If so, are we probably talking about an attack that is an omen of a larger-scale threat from the neighboring country? Is the successful cyberattack on critical state infrastructure a warning to Greece or a reminder that in an impending cyberwar our cyberdefenses are nonexistent? Are we such an easy target, after all? Today ELTA, tomorrow who?



In communication between the SecNews editorial team and the responsible officials of ELTA, prior to the publication of this article, they refused to make statements to us due to a high workload.
