risks ranging from electronic fraud and identity theft to the leakage of health information, bank accounts and personal correspondence, following the cyberattack that occurred on October 25, 2024.
Although the incident had been known since the first days, the EAP had not proceeded to substantially inform students, despite their appeals – such as those expressed in official letters from student groups and individual data subjects, who requested transparency, information and clear protection instructions.

Five months later, and while 813 GB of personal data have already been leaked to the dark web, the Foundation is coming – belatedly and without apologetic tone – to admit the size and seriousness of the leak.
Shocking information in files circulating on the dark web
The attack was carried out using ransomware -type malware and caused not only the system to malfunction but also the encryption of a large part of the infrastructure. Despite initial reassurances, the EAP's own announcement confirms that the stolen files contained a wide range of personal data, including:
- Tax ID, Social Security Number, ID numbers, signatures, photographs
- Personal contact information (addresses, telephone numbers, emails)
- Bank accounts and payment details
- Medical data
- Grades, academic qualifications, educational documents
- Contracts, decisions of collective bodies and correspondence
All of the above, according to the Foundation itself, has been located on the dark web, with at least 65 GB already recovered by third parties. No one can know who is in possession of it and for what purposes.
See also: npm packages breached to steal developer data
The EAP was delayed, despite appeals
Students and alumni had expressed their concern about the extent of the attack and the unjustified delay in informing the university since November 2024. In their letters to the administration, they demanded clear answers: what data had been leaked, who had access, and most importantly, what actions they should take to protect themselves.
More specifically, hundreds of students from the Memoria Network had requested in their letter:
- Information on Personal Data Security Measures: What actions are being taken to protect their personal data. At the same time, they were requesting information on what data has been affected, what the next steps are, and what additional measures are being taken to protect against future attacks.
- Regular and Transparent Information: The lack of transparency and continuous information causes great disruption and uncertainty, the students emphasized, and they requested regular and complete communication from the EAP administration regarding the progress of the restoration of the systems and the actions being taken.
The EAP, however, limited itself for months to general assurances about “security checks” and “system restoration”, without ever officially informing data subjects of their potential exposure. Even now, the announcement moves in a vague framework, talking about “theoretical” exposed data and a “limited” number of victims, without any commitment or guarantee.
Responsibilities without responsibilities
Although the Foundation claims to have acted immediately, informed the relevant authorities and taken measures to enhance security, there is no mention of liability for the lack of data protection or the delayed response. Nor is there any provision for compensation or support for affected students and employees who may face consequences from the exposure of their data.
The danger is here – What the EAP now proposes to students
After five months, the EAP is urging those who may be affected to change their passwords, watch out for phishing attempts, not open suspicious emails, and monitor their bank accounts. All this, while their identities may already have been compromised or their data sold to criminal networks.
The shadow of concealment
The EAP incident is yet another episode in an ever- expanding cybersecurity crisis in the public sector. Only this time, the victims are people who entrusted a public university with their most sensitive information – and received delay, opacity, and denial of responsibility in return.
The administration of the EAP is called upon to be accountable – not only to the authorities but also to its students themselves.
See also: NSW breach leads to theft of 9,000+ records
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The official announcement of the EAP in detail
Distinguished gentlemen,
In the context of your responsible and transparent information, regarding the malicious attack that the Foundation received from a group of cybercriminals on 25/10/2024, we would like to initially inform you that the investigation of the incident is ongoing, but based on the findings so far, we are able to provide new information on this issue.
The incident On 25/10/2024, we detected suspicious activity in our information systems, which related to unauthorized access. The attack was carried out with ransomware software, during which the malicious software gained access, by intercepting specific rights, to the main IT infrastructure and the backup infrastructure and caused encryption of the virtual machine management system and malfunctions in secondary systems and the data network.
The encryption did not affect the entire backup set, which was retrieved from the backup infrastructure and used, after a thorough security audit, to recover the University's systems and services. The extent of the leak This attack resulted in a limited leak of personal data. The size of the data leaked amounts to 813GB, according to our information to date.
However, it is important to clarify that this size represents an extremely small percentage, compared to the total volume of data maintained by the Foundation (several terabytes in size), which suggests that the leak is of limited scale. This size can be compared, indicatively, to the local disk capacity of a typical computer.
The leaked files contained, according to the indications so far, personal data in various file formats (mainly doc, pdf, excel). Furthermore, the leaked file is located on the dark web, where access requires specialized, technical knowledge. Furthermore, according to the analyses so far, the specific leaked file is not possible, at this stage, to be downloaded in its entirety.
What may become available for download is considerably less than the original set of data that was compromised (approximately 65 GB has been recovered). Categories of personal data that may have been leaked The Foundation is providing information on the possible categories of data that may have been affected.
Our report includes data/categories of data that could theoretically have been exposed. Full name, Patronymic / Maidenname, Occupation, Relatives' Information, Nationality, Gender, Date of Birth, Tax ID, Social Security Number, Social Security Number, Personal Identification Number, Personal Identification Number, Signature (physical), Photos, username Contact Data (Postal Address, Telephone Number (landline & mobile), Email Address (personal & institution), electronic mail) Academic and Educational Data & Degrees (Grades and performance, Degrees, Certificates of studies) Health Data Financial Data (IBAN, billing information, expense payment information) Professional & Research Activity Data (CV, research / professional / teaching / writing work) Data on Decisions of Collective Bodies, decisions of committees Data on Contracts, Contractors & Offers
However, based on the evidence available so far and the ongoing investigation, the actual leak appears to be limited to a significantly smaller range of data.
The EAP implemented all necessary measures to ensure the minimum possible leakage while at the same time, it cooperated directly with the National Cybersecurity Authority, the Directorate for the Prosecution of Electronic Crime and the Personal Data Protection Authority. More specifically: From the first moment of the incident (25/10/2024) both the National Cybersecurity Authority and the Directorate for the Prosecution of Electronic Crime were informed. The information is continuous.
The incident was promptly notified to the Personal Data Protection Authority (PDPA). The initial statement is updated according to the data. An Incident Management Team was created. The Technical Services of the Foundation, in collaboration with a specialized company, immediately took all actions to address the incident and limit its impacts. More specifically, on the same day (25/10/2024), the incident was isolated (operation of the affected systems was stopped). Data subjects were informed and indicative instructions were provided for the protection of their personal data.
Strengthening the awareness of academic and administrative staff regarding the protection of personal data and the risks of cyberattacks. Preparation of a notice to strengthen the Technical Service with additional specialized personnel. A complaint was filed against an unknown person and against anyone responsible for the malicious attack.
Targeted measures to enhance the security of our information systems have already been implemented, while a comprehensive upgrade of our infrastructure is underway, which includes strengthening existing protection mechanisms and adding additional security controls. For security reasons, the exact technical actions that have already been taken or are planned to be taken cannot be made public.
A data breach can have potential consequences for data subjects, such as: Targeted phishing attacks. Fraud attempts, via email or telephone. Possible unauthorized use of personal information that can lead to fraud and malicious use of this personal information by fraudsters or criminals. Misuse of data to create fake accounts or forge identities.
Information leakage that can lead to social engineering. Malicious use of information, with the aim of fraud (mainly financial). Targeting for unwanted advertising or unwanted calls (spam). Violation of privacy, through the possible leakage of personal data to unauthorized individuals or entities. Identity theft and use of personal information for fraudulent activities.
It is noted that the potential number of subjects involved appears to be significantly limited, while the categories of data that may have been leaked are significantly fewer than those mentioned. Nevertheless, we recommend that all interested parties take appropriate protection measures, ensuring their rights as data subjects. In this way, they not only comply with the protection requirements but also actively enhance their privacy. Protection measures for data subjects
For your protection, we recommend that you follow these instructions: Change your passwords to your accounts (email and registry services) immediately. It is recommended to use a unique and strong password, with at least 10 characters that includes a combination of uppercase and lowercase letters, numbers and symbols. In addition, it is recommended to change your password regularly, ideally every six months. Avoid using the same password on multiple services. Be cautious with emails or phone calls that request personal or financial information. Do not open links or download attachments from unknown or suspicious sources.
Monitor your transactions for any unauthorized transactions and notify your bank immediately if you see any suspicious activity. Use anti-malware software and keep it up to date. Limit posting personal information on public platforms and social networks. Set up alerts for suspicious connections or activity on your accounts. Notify your service provider immediately if you notice any suspicious activity on your personal or business accounts.
In case you start receiving unwanted, commercial calls, consider the possibility of registering yourself, through the relevant, legal procedures, in the registry of par. 2, article 11, Law 3471/2006. In case you receive annoying, advertising emails, messages or messages that are not related to the educational process at the email addresses provided to you by the EAP, please notify the Network and Information Services Office, forwarding these messages to the email address abuse@eap.gr, so that all necessary measures can be taken.
The retrieval, classification and analysis of relevant records are processes that require specialized knowledge and technically advanced methods. Due to the technical nature and complexity of these processes and the need to comply with the legal framework for the protection of personal data, a full investigation can be particularly time-consuming.
We would like to emphasize that the EAP is cooperating fully with the competent supervisory authorities, providing all necessary information and facilities, in the context of the investigation of the incident, in full compliance with the applicable legal and regulatory framework. Given that the digital environment is dynamic and constantly evolving, with new challenges and technological changes that directly affect cybersecurity requirements, the EAP is committed to maintaining a constantly updated and adapted protection framework, aiming at the maximum possible assurance of the integrity, availability and confidentiality of our users' data.
Sincerely, Serafim Karaiskakis Data Protection Officer (DPO)
See also: Educational sector: Cyberattacks and ways to protect

Educational sector: Cyberattack protection strategies
One of the most effective strategies is to educate staff and students about cyberattacks. This can include learning the basics of cybersecurity, understanding the most common attack techniques, and learning best practices for protecting personal and institutional data. For example, it is essential to use strong and unique logins and enable MFA on accounts wherever and whenever possible.
Additionally, the use of advanced security solutions, such as intrusion protection systems (IPS), intrusion detection systems (IDS), and antivirus software, can provide significant protection against cyberattacks. These tools can detect and repel attacks before they cause significant damage.
Network segmentation can also help protect educational institutions by preventing a potential attack from spreading to all systems.
Implementing a least privilege policy, which limits access to systems and applications to only those who truly need that access, can reduce the risk of cyberattacks.
Updating all software and applications is also essential, as it fixes potential security vulnerabilities that hackers can exploit.
Finally, regularly backing up important data and implementing disaster recovery plans can ensure that, even if a cyberattack occurs, data can be recovered.
Source: www.documentonews.gr
