The Gov.gr platform and the Topic Bank were subjected to a serious cyberattack this morning (21/05/2025) , as confirmed in statements on state television by the Minister of Digital Governance, Dimitris Papastergiou . The attack resulted in temporary malfunction and access problems to important public systems , with direct consequences for the start of the high school entrance and graduation exams.

The Minister of Education, Sofia Zacharaki, has been in constant communication since 6 am with the Minister of Digital Governance, the Secretary General of Information Systems and the administration of OTE. She informed them that the failure of the General Secretariat of Information Systems platform directly affects the operation of the Subject Bank.
She herself requested that priority be given to the restoration of the Subject Bank platform, so that the exams in Lyceums can be conducted smoothly and without delays.
See also: Cellcom: Service outage due to cyberattack
Target the Ministry of Education and the Topic Bank platform
The cyberattack was large-scale and affected the public administration network SYZEFXIS, causing temporary inability to access many public services. The Institute of Educational Policy (IEP) Topic Bank, through which exam questions. School principals were faced with problems accessing the platform this morning, resulting in a delay in delivering the questions to students.
As Mr. Papastergiou reported, the attack targeted the user identification mechanism, which caused the services to go down. Although the situation initially caused tension, the technical team of Gov.gr in collaboration with contractor companies managed to deal with the attack very quickly. Shortly after 8 a.m. the services were back in full operation and the Subject Bank was fully restored, thus enabling students to start the exams with only a short delay.
Statement by the Minister of Digital Governance on the cyberattack on Gov.gr
«The day did not start easily. On the phones with the Ministry of Education mainly. The attack was on the entire gov.gr but mainly on the operation of the Subject Bank since the users were teachers due to the fact that the exams started today. The attack was on the way users were identified, resulting in all services going down. It was a cyberattack that was dealt with very quickly by the people of gov.gr, resulting in 7:20, 7:25 we were up, however, just outside the daily routine of gov.gr there was today and the first day of the exams there was mobilization from the Ministry of Education, from 7:00 on the phones with Sofia Zacharaki“.
See also: Arla Foods: Cyberattack affected production
The attack was escalating and created very serious problems that the authorities are currently trying to resolve, as reported by Manolis Sfakianakis, founder of the non-governmental and non-profit organization CSI Institute ("International Institute for Cybersecurity") and former Commander of the Cybercrime Prosecution with particular experience in similar cases.

What do we know about the attack?
The cyberattack was characterized as a DDoS (Denial of Service) and resulted in the "crashing" of the State's systems, making it difficult for many users, especially teachers who were trying to connect to the Subject Database. The speed of reaction of the technical team prevented further spread and significant delays.
The case highlights the significant challenge that public sector digital infrastructures face in the face of increasingly sophisticated cyber threats, especially during critical periods such as the start of school exams.
The effective management of the crisis by Gov.gr and the co-responsible ministries demonstrates the need for continuous investment in security and rapid response, in order to ensure the smooth operation of services that serve thousands of citizens daily.
See also: Glibc vulnerability exposes Linux systems to attacks
Improving the infrastructure and the topic drawing process
Given that there have been problems with the Topic Bank in the past, the Institute for Educational Policy (IEP) has commissioned a private company to implement targeted improvements to the infrastructure and the topic drawing process, with the aim of avoiding past problems.
The interventions carried out include:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Transfer of content to Amazon's cloud infrastructure, using the AWS S3 service and appropriate encoding (for retrieval by other applications).
- Configuring the AWS Content Delivery Network to protect against malicious attacks.
- Optimization of the existing database.
- Migration of existing PHP applications to cloud infrastructure AWS, using elastic technologies.
- Implementation of an alternative interface with TAXIS elements, integrating it into the existing system.
- Create an alternative topic submission in case the web application is unavailable.
The project also includes supporting design, implementation, production operation and maintenance services, such as:
- Application study and requirements analysis.
- Security study and compliance with the General Data Protection Regulation (GDPR).
- Disaster Recovery Plan.
- Installation, configuration and development services for specific software components.
For the upgrade of the Lottery, Distribution and Management System of the Bank of Graded Difficulty Topics, a budget of 595,200 euros is provided, according to a relevant invitation from the Ministry of Education to the IEP and the Information Society.
For the upgrade of the Lottery, Distribution and Management System of the Bank of Graded Difficulty Topics, a budget of 595,200 euros is provided, according to a relevant invitation from the Ministry of Education to the IEP and the Information Society.
See also: Legal Aid Agency: Data breach following cyberattack

The invitation provides for the following actions:
Action 1: Implementation Study – Requirements Analysis
- Finalization of user requirements analysis, infrastructure software and digital services.
- Prioritization of business, functional and technical requirements.
- Documentation of proposed architecture according to international practices.
- Design of an operating environment for mobile devices and digital infrastructure.
- Guide to analyzing interoperability requirements at the business and technological level.
Action 2: Application Development
- Delivery of ready-to-use software for testing in the cloud infrastructure.
- Development of software testing scenarios (User Acceptance Tests) and test planning.
- Functionality test results report.
Action 3: Quality Control and Training – Trial Operation
- Test operation results document confirming the smooth operation of the system.
- Administration & user manual.
Action 4: Installation in Production Mode
- Delivery of ready-made software for full production operation in the cloud infrastructure.
Action 5: System Security and Performance
- Safety study and risk assessment.
- Performance study under high load conditions (stress tests).
These interventions are expected to significantly enhance the reliability and security of the platform, ensuring the smooth operation of the Topic Bank in future examination periods.
