Rapid development: According to information circulating from the Halkidiki, SecNews has information about a powerful ransomware attack that hit the Municipality of Sithonia and the Municipal Port Fund of Sithonia. The Personal Data Protection Authority has been informed, while the Electronic Crime Directorate of the Hellenic Police has taken over the investigation of the case. At this time, it has not been determined what data was intercepted or whether there were functional backup copies. Discussions within the Municipality do not fully clarify the status of the backup copies. The case is evolving and SecNews will inform readers of any new data.
See also: AISI incident: AI created fake GitHub identities to scam developers

The strike in Sithonia: What we know so far
From the information collected, the cyberattack appears to have been coordinated and to have simultaneously affected two critical services in the region: the central administration of the Municipality of Sithonia based in Nikiti, as well as the Municipal Port Fund of Sithonia, which manages the ports and boat shelters in the region. The Municipality of Sithonia serves approximately 13,000 permanent residents and receives hundreds of thousands of visitors every summer, as it includes popular tourist destinations such as Nikiti, Neos Marmaras, Sarti and Pyrgadikia.
The main facts that have been confirmed:
- The ransomware simultaneously affected the Municipality and the Port Fund, which suggests a shared information infrastructure or generalized penetration of the internal network.
- The Personal Data Protection Authority was informed, as required by the General Data Protection Regulation (GDPR EU 2016/679) within 72 hours of becoming aware of the incident.
- The Cybercrime Prosecution Service has taken over the investigation of the case, with the aim of identifying the perpetrators.
- It has not been determined with certainty what data was intercepted — demographic, tax, banking information, port facility data, or a combination thereof
- The status of the backups remains unclear — discussions within the Municipality do not indicate whether there were any working copies
- It is not known whether any ransomware group has claimed responsibility
The SecNews technical team estimates that, while the police investigation is ongoing, the chances of identifying the perpetrators remain low, as modern ransomware groups operate with advanced anonymization techniques, from VPN and Tor to cryptocurrencies for ransom payments.

It's not an isolated incident: The wave of cyberattacks on Greek municipalities
The attack in Sithonia is not an isolated incident. It is yet another case in a worrying wave of cyberattacks against Greek public institutions. The recent example of the Municipality of Alexandria is typical: on June 8, 2026, the Municipality of Alexandria also announced a ransomware incident, with the related investigation still ongoing a month later.
International statistics clearly show that public institutions are now a priority for cybercriminals:
- 187 ransomware attacks against government organizations worldwide in the first half of 2026, according to Comparitech — an average of one attack per day
- 13% increase compared to the second half of 2025
- In France, over 320 municipalities have suffered significant attacks since the beginning of 2026.
- In Europe, ransomware attacks increased by 55.1% in the first four months of 2026 compared to last year
- The average ransom demand for government services is $100,000 — often chosen to be within the means of municipal budgets.
- Most active groups: The Gentlemen (22 attacks), Qilin (21), LockBit (14), APT73/BASHE (12), INC (10)
The attack in Sithonia is clearly part of this generalized wave. Greek municipalities, with limited cybersecurity budgets and often outdated systems, are easy targets for cybercriminals looking to target vulnerable institutions with access to rich citizen data.
Also useful: Apple sues OpenAI: Emails expose trade secrets dispute

What should the Municipality have done before the attack?
The critical question is not whether municipalities will be attacked — but whether they are ready when it happens. The basic precautions that every public entity should have in place are:
- Automatic and isolated backups — Daily backups to at least three locations, with at least one off-network or on immutable storage (immutable storage) that cannot be compromised even if attackers gain administrative access to the network
- Regular recovery testing — It’s not enough to have backups, you need to have tested that restoring them works. Many organizations discover during an attack that their backups were corrupted or incomplete
- Multi-Factor Authentication (MFA) — Required for every administrator account and for all access to sensitive systems
- Network segmentation — Separation of the Municipality's systems from those of the Port Fund and other services. In the case of Sithonia, the simultaneous attack on both indicates a lack of this basic principle
- Endpoint threat detection (EDR) systems — Modern antivirus systems that detect ransomware behaviors, not just known signatures
- Security updates — Apply updates for critical software immediately. Many attacks exploit known vulnerabilities with available fixes
- Staff training — Most attacks start with phishing emails to untrained employees
- Incident Response Plan — A written plan of action that has been tested in exercises, not in the moment of a crisis
Without these precautions, a Municipality is in the same position as a citizen who leaves their home unlocked — the success of the attack is not a matter of “if”, but “when”.
Organized campaign against Greek Municipalities: What needs to be done now
The attack in Sithonia confirms that there is an organized cybercriminal campaign against Greek local government. The reasons are clear: rich data (tax, demographic, banking), limited security budgets, insufficient staff specialization, and high pressure for quick recovery that may lead to ransom payments.
The SecNews editorial team proposes seven immediate actions that all Greek Municipalities should take:
- Utilizing the National Cybersecurity Authority — The authority offers free guidance, assessment tools, and technical support to public entities. Each Municipality should have direct communication with the authority for assessment
- Participation in the national CSIRT — The country's Computer Security Incident Response Team coordinates crisis response and distributes early warnings
- Sharing a technical team — Many small municipalities do not have the resources for their own security team. Collaborating with neighboring municipalities on a shared cybersecurity team is a practical solution
- Collaboration with Greek CERT teams — Collaboration with national private incident response teams for 24/7 monitoring
- Mandatory cyber insurance policies — Ransomware insurance with built-in technical support in the event of an attack
- Annual specialized audits — Independent audits by certified cybersecurity providers, not just standard financial audits
- Funding through the NSRF 2021-2027 — Activating available European funds for digital resilience and cybersecurity of local government

See also: Claude or Copilot in a Greek business: AWS Bedrock for GDPR and DORA compliance
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What should the citizens of Sithonia pay attention to now?
Until the investigation is complete and the extent of the data breach is clarified, residents and visitors who have done business with the Municipality of Sithonia or the Port Fund should be especially cautious. Cybercriminals often use stolen data for a second phase of attacks — phishing targeting victims who already pay a specific Municipality.
- Beware of suspicious emails purporting to come from the Municipality of Sithonia, especially if they ask for bank details or passwords.
- Do not respond to phone calls or SMS asking you to confirm tax or municipal fees.
- Contact the Municipality directly via phone 2375350116 when you have doubts.
- Monitor bank accounts for unusual movements in the coming months
- Update passwords to online services that may share data with the Municipality
- Enable two-step verification in banking and public services (e.g. TAXISnet, GOV.gr)
Enabling these basic precautions significantly reduces the damage that targeted second-stage phishing attacks can cause, even if your personal data is now in the hands of criminals.
The legal obligations of the Municipality of Sithonia now
As a public body that processes citizens' personal data, the Municipality of Sithonia has clear obligations arising from the GDPR and data protection legislation. The critical 72-hour deadline for informing the Data Protection Authority has been met, as reported. The following obligations are:
- Detailed report to the Data Protection Authority with a full description of the incident, the affected data categories, and the response measures
- Informing data subjects — if a high risk to their rights and freedoms arises (Article 34 GDPR), citizens must be informed individually
- Contact with the Municipality's Data Protection Officer (DPO) , who coordinates communication with the Data Protection Authority
- Complete recording of the incident for future reference — time of calibration, response measures, communications, decisions
- Contact with the National Cybersecurity Authority for a coordinated technical response
- Independent investigation by certified cybersecurity analysts to determine the cause and scope
Penalties for non-compliance with GDPR obligations are up to €20 million or 4% of global turnover. Although penalties are calculated differently for public bodies, the impact on reputation and public trust remains significant.
Frequently asked questions about ransomware in Sithonia
What is ransomware and how does it work?
Ransomware is malicious software that encrypts all of a system's files and demands a ransom to restore them. In its most modern form, attackers first steal a copy of the data before encryption, then threaten to publicly disclose it if payment is not made — a technique known as double blackmail.
Should the Municipality pay the ransom?
The official instructions of the National Cybersecurity Authority and the European Union are clear: no ransom should be paid. First, there is no guarantee of recovery. Second, the payment finances further attacks. Third, it may violate EU sanctions if the perpetrators are linked to sanctioned entities. Municipalities should invest in prevention rather than in compliant crisis management.
How long can recovery take?
It depends entirely on the quality of the backups and the speed of response. Organizations with a well-prepared action plan and tested off-site backups can recover in 5-10 days. Organizations without proper backups can take months, and often lose data permanently. The Municipality of Alexandria, for example, is still in the recovery phase a month later.
Will the perpetrators be found?
Historically, the chances are limited. Modern ransomware groups operate from countries where the Greek police do not have direct jurisdiction, use cryptocurrencies for payments and anonymous networks for their communication. International collaborations such as Europol and the FBI have succeeded in some large operations (e.g. LockBit debacle February 2024), but for individual attacks on smaller targets the perpetrators are rarely identified.
Which services of the Municipality of Sithonia are affected?
Although the specific services affected have not been disclosed, an attack of this scale typically renders municipal registry, tax revenue, protocol, and port facility management systems non-functional. Residents and visitors should plan alternative arrangements for any procedural issues until full restoration.
I am a businessman in Sithonia and I do business regularly with the Municipality. What should I watch out for?
In addition to general precautions, check if your business data (company VAT number, IBAN, employee details) may have been leaked. Inform your bank so that it can be alert to any unusual movements, and consider whether you need to change the IBAN of accounts you use in your transactions with the Municipality. Also, tourist businesses in the area must verify any communication claiming to come from representatives of the Port Fund, before paying any fee.
Will there be consequences for the Municipality's managers?
It depends on the seriousness of the omissions that will emerge from the investigation. If it is proven that basic security measures required by the GDPR were not implemented, administrative sanctions may be imposed. The Data Protection Authority will examine whether the Municipality had adopted the "appropriate technical and organizational measures" as defined in Article 32 of the GDPR. Municipal authorities also have a political responsibility towards citizens.
The ransomware attack on the Municipality of Sithonia and the Port Fund is a stark reminder that Greek local governments are in the firing line of international cybercriminal groups. SecNews calls on every Greek Municipality to immediately assess the status of its backups, the quality of network segmentation, staff training, and the existence of an incident response plan. The Sithonia story is ongoing and SecNews will keep readers informed of any new data, the form of the ransomware, the identity of the possible perpetrators, and the recovery process. Sources: National Cybersecurity Authority, Data Protection Authority, Comparitech H1 2026 Report, Municipality of Sithonia.
