HomeRapidalertPhishing attacks on gov.gr and Greek Banks

Phishing attacks on gov.gr and Greek Banks

In recent weeks, there has been a dramatic increase in phishing attacks targeting Greek citizens, using fake versions of the gov.gr as well as websites of well-known Greek banks, such as Alpha Bank, the National Bank of Greece, and others.

Phishing is a common cyberattack tactic where scammers impersonate legitimate services in order to obtain sensitive data, such as passwords, credit card numbers, or personal information. Unfortunately, these types of attacks are becoming increasingly sophisticated, making it difficult for unsuspecting users to distinguish between genuine websites and fake ones.

Phishing attacks on gov.gr and Greek Banks
Warning: Dangerous increase in phishing attacks imitating gov.gr and Greece's largest banks

What are phishing attacks?

Phishing is a form of social engineering attack. Typically, phishing attacks occur when attackers send deceptive messages designed to trick the recipient into revealing sensitive information or installing malicious software, such as ransomware, on their system.

In this case, the attackers design fake pages that resemble the official websites of gov.gr and the largest Greek banks. These pages trick users into believing that they are logging into their real account. When users enter their details, this information is recorded by the attackers.

How the attack works: The example of phishing on gov.gr

The latest phishing campaign is exploiting users who regularly use gov.gr, Greece’s official digital services portal. Gov.gr is essential for completing many government tasks, such as tax returns, document submissions, and digital identification. So it’s no surprise that cybercriminals are trying to exploit the platform’s popularity.

The message the victim receives
The initial message received by the victim of the Phishing attack [1]
Phishing attacks on gov.gr and Greek Banks
Initial Message received by the victim [1]
Phishing attacks on gov.gr and Greek Banks
This appears after clicking on the malicious link [2]
Phishing attacks on gov.gr and Greek Banks
The victim must select the desired Bank to enter access codes [3]
Phishing attacks on gov.gr and Greek Banks
By entering the access codes, the interception takes place. Some banks were NOT active during our audit. [3]

See how the attack is carried out:

  1. Initial Contact: Deceptive Email or SMS The victim receives an email or SMS that appears to come from gov.gr or a related government agency. The message may include urgent language, such as “Update your details” or “Complete your digital signature to avoid account suspension.” The message contains a link that redirects the user to a page that appears to be the authentic gov.gr.
  2. Fake Login Pages
    Once the user clicks on the link, they are taken to a website that is almost identical to the real gov.gr. The images you provide show the precision with which these phishing websites have been created. They include logos of well-known Greek banks, such as the National Bank of Greece, Alpha Bank, Eurobank, and others. The fake page asks users to select their bank to continue.
  3. Credential Theft
    After selecting their bank, users are redirected to a fake version of their bank’s e-banking portal. There, they are asked to enter their login details, such as their username and password, and possibly two-factor authentication (2FA) codes. Once the details are entered, the attackers collect them and gain access to the user’s accounts.
  4. Secondary Phishing Attacks
    In some cases, after gaining access to personal credentials, attackers send further emails or SMS, requesting additional information or asking users to log in again. Each such interaction gives cybercriminals more opportunities to steal sensitive data or withdraw money from bank accounts.
phishing gov.gr
Warning: Dangerous increase in phishing attacks imitating gov.gr and Greece's largest banks

How to Recognize a Phishing Attack: Warning Signs

Despite the complexity of these attacks, there are several signs that can help you identify a fake website or message:

  1. Domain Name (URL)
    One of the most obvious signs of a phishing website is the URL or domain name. Official websites like gov.gr have a secure domain and start with “https://”. Fake websites, like the ones shown in your images, use different domains that may look similar to the authentic one, but have slight differences, such as additional letters, numbers or symbols.
  2. Urgent or Threatening Language
    Phishing emails and SMS often use language that creates a sense of urgency, such as “Your account will be suspended if you do not take action within 24 hours.” Official messages from banks and government agencies typically do not use such phrases.
  3. Unexpected Requests for Information
    Official bodies such as gov.gr or your bank will never ask you to provide sensitive information, such as passwords or PINs, via email or SMS. If a message asks for such information, it is almost certainly a phishing attack.
  4. Suspicious Attachments or Links
    Be cautious of any file attachments or links included in an email or SMS. Even if the message appears to come from a trusted source, it is always a good idea to hover over the link (on a computer) to see if the URL matches the organization's official website.
  5. Poor Grammar or Spelling Errors
    Many phishing attacks contain grammatical errors or spelling mistakes. Although these errors may be minor, they can act as indicators that the message is not authentic.

Steps to Protect Yourself from Phishing

Now that you understand how these attacks work, it's important to take steps to protect yourself and your personal information.

  1. Verify the Source
    If you receive an email or SMS asking you to click on a link, first confirm that the message is authentic. Contact the organization directly using the official contact information (from their website or customer service) to verify the request.
  2. Check the URL
    Always check the URL of the website you are on. If you notice anything suspicious in the domain name or if the website does not start with “https://”, do not proceed. This is a clear sign of a possible phishing attack.
  3. Enable Two-Factor Authentication (2FA)
    Enabling two-factor authentication on your accounts adds an extra layer of security. Even if a phishing attack manages to steal your credentials, attackers will still need access to the second factor of authentication to gain access to your account.
  4. Use Security Software
    Using up-to-date security software on your devices can help prevent malware, keyloggers, and other threats resulting from phishing attacks.
  5. Report Phishing Attacks
    If you believe you have been targeted by a phishing attack, report it immediately to your bank or the official service the attacker is impersonating. In Greece, you can also report phishing attacks to the Cybercrime Investigation Service.
phishing gov.gr banks phishing
Warning: Dangerous increase in phishing attacks imitating gov.gr and Greece's largest banks

Real-Life Examples: Phishing Websites Targeting Greek Banks

The images below show examples of phishing attacks targeting users of major Greek banks, such as Alpha Bank, National Bank of Greece, and Eurobank. Each of these fake pages mimics the bank's legitimate interface, tricking users into entering their login details.

  • Alpha Bank Phishing
    The fake Alpha Bank login page closely resembles the design of the real website, with similar colors, fonts, and layout. However, if you look at the URL, you will see that the domain is different. This detail is crucial for identifying the fake website.
  • National Bank of Greece (NBG) Phishing
    The fake National Bank of Greece website, once again, mimics the real platform. The website even includes icons that resemble security symbols, making it difficult for unsuspecting users to distinguish it.
  • Eurobank Phishing
    The fake Eurobank page has similar visual elements to the bank's real e-banking portal. It asks users to enter their username and password, but this data is transferred directly to the attackers.
Phishing attacks on gov.gr and Greek Banks
National Bank Phishing Page
National Bank phishing
Eurobank Phishing Page
Phishing attacks on gov.gr and Greek Banks
Attica Bank Phishing Page
phishing gov.gr gov.gr banks
Optimabank Phishing Page

The SecNews research team found that the phishing attack is carried out using the domain simantiko.info. It was also found that the campaign does not only concern Greek Banks and gov.gr but also a number of other businesses (with associated domains) while the origin of the attack, according to indications and data that cannot be made public at this time, is from Russia! The campaign began in Greece on September 4, 2024, and it was found that preparatory actions are being taken for additional variations of this phishing campaign.

What to Do If You Are Targeted

If you suspect you have been a victim of phishing, follow these steps:

  1. Change Your Passwords
    Immediately change the passwords on any account you believe has been compromised. Make sure your new password is strong and unique.
  2. Notify Your Bank
    Contact your bank immediately if you think your login details have been stolen. They will help you secure your account and monitor for suspicious activity.
  3. Monitor Your Accounts
    Regularly check your bank and online accounts for any unusual activity. If you notice unauthorized transactions, report them immediately.
  4. Notify the Authorities
    File a complaint with the Cybercrime Prosecution Service and keep copies of evidence of the attack (e.g. screenshots, email headers). This will help the authorities identify the perpetrators.

Conclusion

Phishing attacks are becoming increasingly complex and difficult to detect. However, with a little caution and the right information, you can protect yourself from these types of threats. Always check the authenticity of a website before entering sensitive information and be alert to signs that can help you spot phishing attacks.

The Greek government and the gov.gr management team, in collaboration with the Banks, should IMMEDIATELY proceed with blocking the domain in question and inform unsuspecting citizens with press releases!

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Stay safe online, and remember: if something seems suspicious, it's better to err on the side of caution and verify the source than to become the next victim of a phishing attack.

For the latest updates on cybersecurity threats, visit SecNews.gr and stay informed!

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS