HomeSecurityEOPPEP ransomware: Attack on the Qualifications Certification Organization

EOPPEP ransomware: Attack on the Qualifications Certification Organization

On Wednesday, August 5, 2026, the National Organization for Qualifications Certification and Vocational Guidance (EOPPEP) became the latest victim in a long series of ransomware attacks against Greek public institutions. The attack disabled the organization’s information systems and electronic services, with the malfunction remaining for eight days until the official announcement on August 12. The EOPPEP ransomware claim bears the hallmarks of state-sponsored attacks that have repeatedly targeted the country’s educational and certification authorities.

Read also: Mikel Coffee: Allegation of ransomware attack by TheGentlemen

EOPPEP ransomware attack Greece

What happened at EOPPEP and what does the Organization claim?

According to the official announcement republished by esos.gr on August 12, 2026, EOPPEP was subjected to a ransomware-type cyberattack last Wednesday, with the attack date being August 5. The malfunction affected the network and information systems that support the operation of the Organization, as well as the electronic services it provides to citizens, employers and educational institutions.

The Organization states that it has preserved the integrity of all files, registers and data it maintains. The announcement explicitly states that this was achieved “thanks to the security measures it implements internally and its cooperation with the competent authorities”. However, EOPPEP does not clarify whether preserving integrity means that was not stolen or simply that it was not destroyed. These are two completely different concepts in the context of ransomware attacks.

The official statement also states that every effort is being made to quickly restore full service and make services available to the public. The Organization states that it remains at the disposal of the competent services for information regarding obligations and deadlines that may have been affected during the malfunction, including deadlines for fees and submission of supporting documents.

What is EOPPEP and what data does it manage?

EOPPEP is a Legal Entity of Private Law, supervised by the Ministry of Education, Religious Affairs and Sports. It grants professional qualification certifications, diplomas and certificates to graduates of IEK and other training structures. Its database includes, according to the official privacy policy, full names, parents' names, VAT number, country and place of birth, gender, date of birth, email addresses, police identity card or passport numbers, postal addresses, telephone numbers and other sensitive personal data.

This is an extremely attractive data set for attackers. The EOPPEP registry includes tens of thousands of candidates and certified professionals, from private security guards to museum guards and craftsmen. A complete set of ATT, VAT number and professional certificate is sufficient to set up an entire identity for sale on the dark web. If it is indeed confirmed that there was no leak, EOPPEP will have avoided an extremely serious risk.

EOPPEP certification data

EOPPEP ransomware in the broader pattern of attacks on the Greek public sector

The attack on EOPPEP is not an isolated incident. It is part of an intensifying pattern targeting the Greek education and certification sector. In October 2024, the Hellenic Open University was hit by a ransomware attack that resulted in a confirmed leak of 813 GB of data, according to Insomnia.gr. The stolen files contained personal data in Word, PDF and Excel formats, and were found on the dark web. It took the EAP five months to make an official announcement.

In March 2025, the Hellenic Society for Local Development and Self-Government (EETAA) was attacked by ransomware between March 1 and 5, 2025, with the systems being completely disrupted. According to the Press Release of the Hellenic Informatics Association, the attack affected approximately 700,000 applications over a 10-year period, with estimates of up to 2.5 million affected subjects, including school-age children, adolescents and people with disabilities. The National Intelligence Service itself, in its annual report for the period September 2024-December 2025, recorded 19 serious attacks on public infrastructure, of which 6 were ransomware, according to an analysis by Libre.

Greek public sector attack pattern

It should also be noted that EOPPEP itself points out in its announcement that the new incident is independent and does not appear to be connected to other cyberattacks that have been recorded in the past, as reported by the analysis of the Student News. However, retrospective examination shows that the education sector remains the most targeted worldwide, with an average of 4,632 weekly attacks per organization according to March 2026 data from Check Point Research.

The blank pages of the official announcement

The EOPPEP announcement has significant omissions that raise questions. First, the ransomware group that claimed responsibility is not named. This could mean either that the attackers have not yet made their victim public on a leak site, or that the Organization does not wish to support them with a public report. Both hypotheses are possible. The available ransomware trackers (RansomLook, SOCRadar, GalaxyWarden) have not listed EOPPEP as a victim on public leak sites at the time of writing.

Second, no technical details are provided on the method of entry, the ransomware variant, or whether a ransom was demanded. The Agency does not specify whether the Personal Data Protection Authority within the mandatory 72 hours of the discovery of the attack, as required by Article 33 of the GDPR. This obligation is absolute and applies whether a leak is confirmed or not.

Third, and perhaps most importantly, eight days between the attack and the official announcement is too long. The EAP had taken five months for the full announcement, but had sent initial updates much earlier. EOPPEP remained practically silent for a week while its services were out of operation, which does not help either the affected citizens or transparency.

Related: Lazarus: Fake job offers become zero-day attacks

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What should those who have data in EOPPEP do?

Regardless of EOPPEP's assurance that the data remains intact, citizens who have an account on the Organization's platform must take preventive measures. First step, immediately change the password on the relevant platform. If the same password is used in other services (email, banking applications, e-shops, TAXISnet), the change must be immediately extended there as well. Credential stuffing attacks exploit precisely the reuse of passwords between platforms.

Second, enable two-factor authentication (2FA) where supported, especially on accounts containing financial or public data (TAXISnet, banks, ΙδΙΚΑ). The SecNews technical team recommends authentication applications such as Google Authenticator or hardware keys, instead of SMS which is vulnerable to SIM-swap attacks. Third, carefully monitor for suspicious emails or phone calls requesting verification of personal information. Attackers exploit the confusion after such attacks for spear-phishing.

Fourth, document any suspicious activity. If you notice unusual transactions, unexpected emails, or calls that mention your professional credentials, record the details. In case of a leak, this information will be useful for filing a complaint with the Data Protection Authority.

The institutional shortcomings that make them easy targets

The recurrence of ransomware attacks on Greek public institutions shows systemic deficiencies that go beyond the responsibility of any single organization. The National Cybersecurity Strategy 2026-2030, published in December 2025, recognizes the need to strengthen the defense capabilities of the public sector, especially in light of the NIS2 Directive. However, the implementation of these measures is slow, and the actual state of public institutions’ infrastructure remains in many cases underinvested.

The attacks on EAP, EETAA and now EOPPEP show that critical certification and educational institutions have not invested sufficiently in a defense-in-depth architecture. The problem is not that the attackers are highly sophisticated. Most ransomware attacks exploit known vulnerabilities, outdated systems, weak credentials, or phishing employees. The problem is that the targets have a low defense posture, which makes them attractive and easy. The next attack on a Greek public institution is not a matter of if, but when.

Useful: Eurobank phishing SMS: Customers in the spotlight

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS