The web defacement cyberattack on the website of the Unified Food Control Agency (EFET) on Friday, July 3, 2026 is the latest in a chain of incidents that systematically affect the public sector . Behind the characteristic message "HACKED BY TRENGGALEK CETAR" and the skull that appeared on the homepage, lies one of the most active hacktivist communities internationally — and a very serious question about the digital shielding of the Greek State in view of the new National Cybersecurity Strategy 2026-2030.
SecNews analyzed the technical characteristics of the attack, the profile of the group that claimed responsibility, the history of similar incidents in Greece over the last four years, and the gaps in compliance with the NIS2 directive that make Greek public bodies an easy target.
📑 Table of Contents
- The chronicle of the attack on EFET
- Who are the Trenggalek Cetar?
- Technical analysis: how easy a target was EFET?
- What protective measures should EFET have taken?
- The common pattern of web defacement attacks
- History of attacks on the Greek public sector
- The NIS2 compliance gap
- What should have happened the next day?
- The lesson for other public bodies
- Conclusions and prospects
- Frequently Asked Questions (FAQ)
See also: Cyberattack on EFET website — “HACKED BY TRENGGALEK CETAR”
The chronicle of the attack on EFET
At noon on Friday, July 3, 2026, the official website of EFET was taken down, with visitors seeing on the home page an image of a skull and the message “HACKED BY TRENGGALEK CETAR.” This is a classic case of web defacement — a form of attack that the literature refers to as “digital graffiti,” as the attackers do not seek profit but rather the visibility of their message or presence.
The EFET website was fully operational later that afternoon, but the agency did not issue an official technical analysis on the causes, the entry point of the perpetrators, or any possible data leaks. The case sparked immediate political reactions about cybersecurity gaps in public digital infrastructure, with the incident being described as a “wake-up call” for the security of the Greek State.
The critical question, however, is not whether the website is back. It is the digital forensics that must prove whether the attackers were limited to the public environment of the website or whether deeper access was gained to databases, administrative accounts, or internal systems. Without this analysis, the incident cannot be considered “closed” — it may simply be that the main entrance has been restored, while the perpetrators have remained with persistent access to other endpoints.
Who are the Trenggalek Cetar?
The name Trenggalek Cetar does not appear by chance in the international hacktivism scene. Trenggalek is a Regency (province) of East Java in Indonesia and has developed into a particularly active center of Indonesian hacktivists and defacers. This geographical association is confirmed both by the linguistic identity of the name ("Cetar" is a slang expression of Indonesian pop culture) and by the reports of international security researchers who classify the Trenggalek region as one of the most active "hotspots" of the Indonesian defacement scene.
The same region has also been on the list of targets — and not just of attackers. In 2022, more than 60 official websites of the Trenggalek Regency municipality were hacked by a group called “Anon7” during national political tensions in Indonesia. Two years later, in March 2025, Trenggalek municipality itself was the target of another defacement attack by the hacker “skk.” The region is therefore not just a source of hacktivists — it is both a source and a target of attacks.
The Indonesian defacement scene is one of the most organized in the world. According to recent data from the mirror archive Zone-Xsec, the top positions in the global defacer rankings are held almost exclusively by Indonesians — “AnonSec Team”, “KELELAWAR CYBER TEAM”, “INDONESIAN CYBER JAWA”, “Ganest Seven”, “TangerangXploit Team” — with a total of more than 400,000 recorded defacement attacks. In the same database, the Trenggalek Cetar subgroup appears with a history of attacks in dozens of domains worldwide, with a particular preference for government domains with low technical maturity.

Analysis of past attacks by Indonesian defacers reveals a clear pattern: victims are rarely chosen politically. They are usually targets of opportunity — websites that appear in automated scans as vulnerable to known WordPress, Joomla, Drupal vulnerabilities, or vulnerable web servers with outdated Apache/nginx versions. The attackers run mass scans for specific CVEs that allow arbitrary file upload or SQL injection, target entire ranges of IPs, and replace the homepage with their “graffiti.”
Technical analysis: how easy a target was EFET?
Passive identification of efet.gr's infrastructure reveals a picture that fully explains why the attack was successful. EFET hosts its main critical information infrastructure on Bluehost shared hosting (server hostname: box5700.bluehost.com, IP 162.241.252.89, Utah USA). This is a US shared server — the same model used by thousands of personal blogs and small businesses worldwide.
This choice is a serious issue in itself. A public body that manages information critical to public health and food safety cannot rely on shared hosting. It is not just a question of speed or availability — it is a question of jurisdiction, control, GDPR compliance and the ability to perform full forensic analysis. On a shared server, EFET cannot independently check the server logs, nor does it have full root administration rights.
The website runs on Joomla! CMS, with the following extensions installed visible from the public HTML structure: SP Page Builder, K2, News Pro GK5, and com_sppagebuilder. All three of these extensions have a documented history of vulnerabilities, with K2 in particular having an arbitrary file upload issue that allows .php files to be uploaded via zip/tar archives to the path /media/k2/galleries/. This is a classic vector for web defacement attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The context of Joomla vulnerabilities in general, however, is equally concerning. The French ANSSI issued an alert in June 2026 for multiple vulnerabilities in Joomla 5.x before version 5.4.4 and 6.x before 6.0.4, including SQL injection, cross-site scripting (XSS), and arbitrary file deletion. At the same time, the US CISA has imposed an explicit order on all federal agencies to fix CVE-2026-48907 — a critical maximum severity vulnerability in the Joomla Content Editor (JCE) plugin that allows unauthenticated arbitrary code execution by creating rogue editor profiles.
The exact mechanics of this vulnerability are diagnostic for the hacktivism scene: it allows unauthenticated attackers to create new editor profiles without authentication and through them to upload and execute malicious PHP code, resulting in full pre-authentication remote code execution. Attackers gain persistent backdoor access, with the potential for data theft, defacement, lateral movement, and total takeover of the hosting environment.
The most instructive piece of evidence, however, came from Malaysia just a week before the EFET attack. On June 26, 2026, Malaysia’s National Cyber Security Agency (NACSA) issued an advisory noting that several government websites — including those of the Ministry of Health, the Cooperatives Commission, and the Handicrafts Development Agency — had been compromised using this very Joomla vulnerability. This was a wave of attacks that hit dozens of organizations in different countries in a matter of weeks, with EFET being yet another notable addition to the list.
Another finding from efet.gr's HTTP response headers is equally important. The website lacks basic security headers: no Content-Security-Policy, no Strict-Transport-Security, no X-Frame-Options, no X-Content-Type-Options. This means that there is no basic protection against clickjacking, MITM upgrades, or stored XSS. It is the digital equivalent of a government building without locks — and a building that a visitor should trust with food safety data.
The combined picture, therefore, is clear. EFET was an extremely easy target: shared hosting outside the EU, Joomla with known vulnerable extensions, no HTTP headers protection, no indicative WAF (Web Application Firewall), and almost certainly no MFA on administrative accounts. Trenggalek Cetar didn’t have to invent anything — they simply ran the same automated scan that the Indonesian defacement scene uses every day.
What protective measures should EFET have taken?
The attack on EFET is one of the rare incidents where we can say with precision what should have been done and what wasn't. The practices that would almost certainly have prevented the attack are not exotic — they have been industry standards for critical infrastructure for a decade.
First, hosting on a certified European provider with SLA, guaranteed patching cadence, and full forensic support. For critical public health infrastructure, the minimum is an ISO 27001 certified datacenter within the EU (e.g. Amazon Web Services eu-central, Microsoft Azure Europe, or Greek providers such as Nova Cloud or OTE Cloud). The cost difference from Bluehost shared hosting on a serious enterprise plan is in the range of €200-500/month — negligible for a public institution.
Second, Web Application Firewall along the way. A Cloudflare Pro subscription (€20/month) or AWS WAF would have automatically blocked almost all known-CVE exploitation attempts against Joomla, as well as the suspicious behavior of automated scanners. It's not rocket science, it's an industry-standard front-end that all serious websites have.
Third, patching cadence with SLA. CVE-2026-48907 (JCE plugin) was publicly disclosed on June 20, 2026, with an explicit CISA mandate to patch within a week. The attack on EFET occurred 13 days later. If there had been staff or an SLA with a CMS management provider to promptly apply security patches, the attack would have been almost certainly prevented.
Fourth, MFA on all administrative accounts. Joomla has had native two-factor authentication support since version 3.2 (December 2013). There is no technical justification for admin accounts without MFA in 2026 — especially for a government agency.
Fifth, vulnerability scanning and penetration testing on a regular basis. A quarterly external vulnerability scan by a certified provider would have identified vulnerable Joomla extensions and missing security headers months before the attack. The cost of such an engagement is in the range of €2,000-5,000 — negligible compared to the damage of an incident.
Sixth, central SIEM monitoring. Real-time logging with alerts for anomalous behavior — POST requests to unusual endpoints, brute force attempts in the admin panel, unusual outbound traffic patterns. This is the bare minimum for a critical public entity and is an explicit requirement of NIS2.
Seventh and perhaps most importantly, a documented incident response plan with tabletop exercises on an annual basis. The goal is not only rapid recovery, but also timely transparency and full forensic analysis. The fact that EFET did not issue any technical update within the first 24 hours of the attack demonstrates that such a plan either did not exist or was not implemented.
The total cost of all of the above for an institution like EFET ranges from €25,000-50,000 per year. An amount negligible in relation to the damage caused by the incident to the institution's credibility, to the country's national visibility as digitally mature, and to the general trust of citizens in the state's digital services.
The common pattern of web defacement attacks
Web defacement attacks, like the one at EFET, are not technically complex. In the vast majority of cases, they exploit one of the following typical vulnerabilities: old WordPress themes and plugins with known CVEs that have not been patched, admin credentials leaked in old breaches, misconfigured file upload endpoints that accept arbitrary file extensions, or exposed administrative panels without multi-factor authentication (MFA).
An instructive parallel comes from Arctic Wolf Labs’ analysis of the Indonesian collective INDOHAXSEC — one of the most active in the field. The group maintains a public GitHub repository of “rudimentary in nature” tools: DDoS scripts (the “NUKLIR,” “Rudal-shell,” “Xss_Fucker”), PHP backdoors, defacement kits, and a custom stealer called ExorLock. These are tools that don’t require advanced knowledge — just well-known techniques automated.
The very philosophy of defacers reinforces this “mass” approach. Michigan State University, in its official study of web defacement attacks against government agencies, finds that “perpetrators prefer publicly displayed websites so that their success is visible to as many people as possible.” The “self-claiming” pattern — i.e., the ostentatious signature on the defaced site with the name of the group or hacker — is a central part of community culture.
In the case of EFET, the signature “TRENGGALEK CETAR” with the skull follows exactly this pattern. No political message, no reference to geopolitical or religious strife — just a signature. This almost certainly indicates that EFET was not targeted, but a target of opportunity in a mass scan. The selection of a Greek gov.gr entity was most likely the product of automatic detection of a vulnerable endpoint and not a targeted operation against Greece.
See also: Armored Likho targets government agencies with BusySnake stealer
History of attacks on the Greek public sector
The attack on EFET is not the first such incident. The last four years have seen a clear upward trend in cyberattacks on Greek public institutions — with particularly critical incidents that have exposed the gaps in our digital security.
The most costly attack on a Greek public institution was the ransomware incident at ELTA in March 2022.According to the ELTA announcement, the attack was initiated by zero-day malware that was installed on a workstation and connected to a command-and-control infrastructure via HTTPS reverse shell . The organization was forced to suspend its commercial information system in all stores, with immediate financial damage exceeding 20 million euros. The restoration was completed only in February 2023.
In 2024, ELTA was also ordered to pay a fine of 2.99 million euros by the Personal Data Protection Authority. The fine specifically concerned “failure to comply with the required technical and organizational security measures” — a diagnostic finding that, had it acted on in time, would have prevented the attack.

The National Cybersecurity Authority has recorded in its official review that cyberattacks against the public sector have tripled at the beginning of 2025 compared to the same period in 2024. At the same time, according to Kaspersky data, 15.2 million digital threats, with ransomware attacks increasing by 10 times and attacks on banking data by 25 times on an annual basis.
The most worrying element, however, is not the number of attacks. It is Greece’s ranking in the European context. According to Eurostat, only 52% of Greek businesses implement at least three basic security measures — a percentage that ranks the country in last place in the EU. The private sector, in other words, is in a similar position to the public sector. The attack on EFET is not an isolated incident, but a symptom of a broader systemic problem.
The NIS2 compliance gap
Greece has implemented the NIS2 with Law 5160/2024, making a significant number of public and private entities legally liable. EFET, as a public entity that manages critical information for public health and food safety, is included in the category of “critical” organizations under NIS2. The resulting obligations are specific: risk assessment, incident response plan, business continuity procedures, security awareness training, as well as an obligation to notify incidents within 24 hours.
The failure of EFET to issue a timely technical update on the incident — a few hours after the attack, there had been no public announcement with technical details — is a significant indication that the required procedures under NIS2 did not function as they should. Under the new directive, timely transparency is not just a political demand — it is a legal obligation with a potential fine of up to €10 million or 2% of global turnover for non-compliance.
The National Cybersecurity Strategy 2026-2030, published in December 2025 by the National Cybersecurity Authority, explicitly classifies the Public Sector among the “sectors most affected in our country”, along with digital providers, transport and health. The fact that the national authority itself recognizes the public sector as vulnerable, but incidents continue to increase, shows that the problem is not in the diagnosis but in the execution.
The new National Strategy includes priorities such as “establishing and activating a coherent national cybersecurity community.” The question, however, remains technical: which of the public bodies covered by NIS2 have actually completed vulnerability assessments, real incident response procedures, patch management workflows and secure development practices? The attack on EFET, by a group that does not even possess advanced techniques, suggests that the answer is unfortunately clear.
What should have happened the next day?
Beyond restoring the website, the real work for EFET now begins. The first step is a full digital forensics analysis — not just of the web server, but of all connected systems. The key question is whether the perpetrators installed web shells, backdoors, or cron jobs that would allow them to return at a later point. Classic defacement techniques rely on persistence mechanisms — files with random names in accessible directories, timing-based scheduled tasks, or modified .htaccess.
The second step is to analyze the logs — access logs, error logs, database query logs, SSH logs. In the vast majority of incidents, the entry point is visible in the logs if one knows what to look for: look for known WordPress exploit paths, POST requests to unusual endpoints, brute force attempts on /wp-admin/, or strange user agents. Without this analysis, EFET cannot know what the attacker actually achieved.

The third step is credential rotation. All administrative accounts — WordPress admin, database, FTP, SSH — should be changed to new, strong credentials and MFA required. At the same time, all session tokens that existed before the attack should be invalidated. If the attackers managed to gain even one admin account, their comeback would be a matter of minutes without this step.
The fourth step is to fully upgrade the stack. If the attack came from an outdated CMS, plugin or server software version, upgrading to current versions is necessary. At the same time, installing WAF (Web Application Firewall), fail2ban, rate limiting, and monitoring with real notifications to a specific group of people who will act immediately.
The fifth and perhaps most essential step is public information. EFET must publish a technical incident report explaining what happened, what data (if any) was exposed, what steps were taken, and what measures are in place to prevent recurrence. This transparency is not just a matter of trust — it is a legal obligation under NIS2 and a minimum sign of respect for citizens.
The lesson for other public bodies
The central finding of the attack on EFET is not technical, but systemic. EFET, like dozens of other Greek public institutions, operates with infrastructure that has not been sufficiently upgraded for today's threat. Attackers — even when they are extremely low-level, as in the case of Trenggalek Cetar — constantly find easy victims.
The root of the problem lies on three levels. First, in the lack of sufficient budget for cybersecurity in public institutions. Second, in the lack of qualified personnel — the CISO or IT Security Officer positions in many institutions are vacant or filled by personnel without the necessary training. Third, in the lax implementation of legislation: the laws exist (NIS2, GDPR, Law 5160/2024), but their enforcement is selective.
The argument that “just one defacement attack is not serious” misses the point. The real risk is not the skull on the homepage — it’s what we don’t see underneath it. A successful defacement means that someone has gained access to server-side code, possibly a database, possibly connected internal systems. The question is not whether Trenggalek Cetar exploited that access — it’s whether someone else, following them, will exploit it.
The new National Cybersecurity Strategy 2026-2030 aspires to provide answers. However, it will be judged not by its texts and intentions, but by specific indicators: number of public bodies with certified ISMS, percentage of resolution of critical CVEs within SLAs, mean time to detect incidents (MTTD), number of trained security executives per body, percentage of MFA coverage in admin accounts. Without measurable progress in these, attacks like Trenggalek Cetar will continue to be easily impressive incidents.
Conclusions and prospects
The attack on EFET was neither political nor targeted. It was, in all likelihood, another incident in the massive chain of defacement that the Indonesian hacktivism scene produces daily internationally. But that is precisely what makes it all the more worrying. A Greek public institution was compromised by a group of low technical skill, without political targeting, without specialized tools, simply because it appeared vulnerable to an automated scan.
The real question for the Greek digital strategy is not whether the Trenggalek Cetar will return — they probably won’t, because they did their job. The question is how many other public institutions are currently on the list of the next automatic scan. The only reliable answers will come from measurable progress in the implementation of NIS2, strict oversight by the National Cybersecurity Authority, and the diffusion of a security culture at all levels of public administration.
Until then, every EFET-type attack will be another lesson that we pay twice: once by repairing the incident itself, and once by undermining citizens' trust in the state's digital services. The second damage is always more expensive than the first
Frequently Asked Questions (FAQ)
What is web defacement and how dangerous is it?
Web defacement is a form of cyberattack where attackers replace the content of a website’s home page with their own message or images. Although the alteration itself may seem limited, it means that the attackers have gained write access to server-side files. This can be the “tip of the iceberg” of a deeper compromise involving databases, internal systems, or administrative accounts.
Who are Trenggalek Cetar?
Trenggalek Cetar is a name that has been associated with hacktivists from the Trenggalek region of East Java, Indonesia, one of the most active geographic areas in the global defacement scene. They are not a state-sponsored or politically motivated group — they are typical hacktivists who massively target vulnerable websites worldwide and sign their defacements with the distinctive skull icon.
Was the attack on EFET targeted?
Based on technical analysis of defacement attacks by Indonesian groups, the attack on EFET was almost certainly opportunistic — the result of an automated scan that identified a vulnerable endpoint. There is no evidence of political targeting or connections to foreign governments. The message was purely a signature, with no political or geopolitical messages.
Was personal data leaked in the attack?
So far, EFET has not issued an official technical update on the scope of the breach. Without a full digital forensics analysis, it cannot be ruled out that the perpetrators gained access beyond the public environment of the website. This is critical transparency that the body must provide in the coming days.
What does the incident mean for NIS2 compliance?
As a public body that manages information of critical importance for public health, EFET is subject to NIS2 through Law 5160/2024. The delay in issuing a technical update and the lack of clear incident response procedures indicate compliance gaps. Fines under NIS2 can reach 10 million euros or 2% of global turnover.
How many cyberattacks have been recorded on Greek public institutions?
According to the National Cybersecurity Authority, attacks against the public sector have tripled at the beginning of 2025 compared to the same period in 2024. In 2024, Kaspersky alone recorded 15.2 million digital threats in Greece, with ransomware attacks increasing 10 times annually.
What should a public body do to protect itself?
The key priorities are: (1) full vulnerability assessment and regular patching, (2) MFA on all admin accounts, (3) WAF and monitoring with real alerts, (4) documented incident response plan with simulation exercises, (5) staff training, (6) SOC-as-a-Service if there is no internal capability, and (7) full compliance with NIS2 requirements through a certified ISMS.
