A shocking cyberattack took place at EETAA, which brought sensitive personal data into the hands of hackers.

The Hellenic Society for Local Development and Self-Government (EETAA) was subjected to a cyberattack, which led to the leakage of sensitive data of approximately 2.5 million citizens, mainly parents, children and infants.
The attack occurred on the morning of Saturday, March 1, until 2:00 p.m. on Wednesday, March 5, 2025, and targeted the information systems of EETAA, which manage a multitude of social programs and actions, including the inclusion of children in preschool and school education, as well as the "Neighborhood Nannies".
Among these are identity details, VAT number, AMKA and IBAN, as shown by the information provided by the EETAA administration, following a relevant question from SYRIZA in Parliament.
Personal data that fell into the hands of hackers
The information obtained by the hackers includes full names, maiden names, patronymics, dates of birth, gender, citizenship, indication of whether the person is disabled, bank account IBAN, VAT number, AMKA, DOY, income information, employment status, residential address, marital status, and indication of tax and insurance awareness.
This data is for parents and children for:
-The Action "Promotion and support of children for their inclusion in preschool education as well as for the access of school-age children, adolescents and people with disabilities to creative employment services" for the periods 2014-2015 to 2024-2025 and
-The pilot implementation of the "Neighborhood Nannies".
Who are the victims?
For the Action "Promotion and support of children for their inclusion in preschool education as well as for the access of school-age children, adolescents and people with disabilities to creative employment services", the breach concerns in particular the personal data of applicants for participation in the Program, other members (spouses/partners) as well as their minor children. More specifically, the data concerns:
a) To the beneficiary person (infant, toddler and preschool child as well as school-age child, teenager and disabled person, who falls into the categories and meets the conditions of the respective Joint Ministerial Decree in order to receive a "placement value" (voucher)).
b) To the legal representative of the applicant (parent or person with parental responsibility or custody, the foster parent, the guardian or the supporter of the beneficiary).
c) To the legal representative of the Organization/Structure (legal representative of the Organization that provides preschool education and care and creative employment positions for children and/or people with disabilities, within the framework of the Action).
d) To the executive of an Agency/Structure (employee of an Agency of par. c) above)
Given the scope covered by the retention period of the data that was breached (a total of 10 years), it is roughly estimated that the number of requests may amount to 700,000 and concern approximately 2,500,000 subjects.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Regarding the pilot implementation of the "Neighborhood Nannies" Action, the breach concerns the personal data of the beneficiary person (person who has custody of an infant or toddler). Due to the pilot nature of the project, the total number of the above subjects amounts to approximately 700 people.
