A website was hacked and a message was posted to the Decentralized Administration of Crete, according to information brought to the attention of SecNews. As reported by SecNews associates, a Brazilian hacking group called “Slayers Brazil HackTeam” carried out a cyberattack by exploiting a vulnerability on the website of the Decentralized Administration of Crete.
The Decentralized Administration of Crete, as established in January 2011 by the Kallikratis Programme, includes the four prefectures of Crete (Lassithi, Heraklion, Rethymno and Chania) headed by the General Secretary.
The basic responsibilities of the ADC as it emerges from its Structure and consequently the data it manages mainly concern administrative issues of internal operation and control, spatial planning, environmental, water, agricultural, forestry. There is also data on issues related to civil protection, but also data of various content that have arisen from the various European Programs in which the ADC has participated.
The website https://www.opencrete.gov.gr/ , which was targeted by the “Slayers Brazil HackTeam”, has been designed to be constantly updated with data from more and more Public Administration bodies, while it is constantly enriched with additional functionality.
The Brazilian hackers “Slayers Brazil HackTeam”, of low cognitive level (as we found out through relevant research), possibly using a weakness of the website, proceeded to post their logo/message as shown below. We speculate that some weakness of the CMS or the website in general, allowed them to obtain administrator rights or rights to change the records displayed. The website that was altered is the internal website https://www.opencrete.gov.gr/group:
![[ΑΠΟΚΛΕΙΣΤΙΚΟ] Αλλοίωση ιστοσελίδας στην Αποκεντρωμένη Διοίκηση Κρήτης 2 Opencrete.gov.gr: Αλλοίωση ιστοσελίδας στην Κρήτη](https://cdnglobal.secnews.gr/wp-content/uploads/2014/11/20185638/hacked.opencrete.gov_.gr_.1-1024x615.jpg)
The group of Brazilian hackers (of low cognitive level, as we mentioned above), directed their “electronic” fire against Greek targets either by chance (using automated tools that identified the agency’s website as insecure) or for reasons that remain unclear to this day. Since the website is in the gov.gr subdomain and within the Syzefxis network, the competent authorities must IMMEDIATELY take action and check the website.
As we have mentioned many times in the past, Syzefxis as a provider DOES NOT essentially bear the responsibility for managing the servers of each entity, but simply provides the means of access.
Comprehensive measures must be taken to ensure that at least the entities managing sensitive personal data draw on expertise from the Syzefxis management staff, who are properly trained and tasked with security issues.
The server that is indicated to have been attacked must be placed off the network and thoroughly analyzed for digital evidence, in order to identify the exact way the intrusion was carried out and to expel the attackers in case they have penetrated other servers in the network under investigation.
Stay tuned to SecNews, the reliable 24-hour information website on information systems security and cyber breaches.

![[CONFIDENTIAL] Website defacement in the Decentralized Administration of Crete 1 Decentralized Administration in Crete](https://www.secnews.gr/wp-content/uploads/2014/11/hacked.opencrete.gov_.gr_.2.jpg)
![[CONFIDENTIAL] Website defacement in the Decentralized Administration of Crete 3 syzefxis](https://www.secnews.gr/wp-content/uploads/2013/01/syzefxis.jpg)
![[CONFIDENTIAL] Website defacement in the Decentralized Administration of Crete 4 cyber-crime-hackers-arrested](https://www.secnews.gr/wp-content/uploads/2014/04/cyber-crime-hackers-arrested.jpg)