The response of the General Secretariat for Information Systems (GSIS) of the Ministry of Finance was immediate, following the announcement of the SecNews report.
The SecNews research team, following a report it conducted and presented a few hours ago, stated that the concern caused by press reports that spoke of an electronic attack against the General Secretariat of Information Systems and all Greek Banks.
The GSIS, with its announcement immediately after the article was posted, essentially fully confirms the journalistic investigation of SecNews. That is, that no attack was carried out on the GSIS systems, no leak of data of Greek taxpayers occurred and the concern caused by publications on the internet is unfounded, since such incidents appear daily, targeting unsuspecting users.
Essentially, the only targeting that took place was on individual personal computers of users of the GGPS applications, who, at their own risk, "opened" false emails sent by the cybercriminals.
See the relevant announcement below, which confirms the journalistic success of SecNews:
GSP PRESS RELEASE ON THE ELECTRONIC ATTACK
In relation to the announcement of 12-12-2014 by the Police Headquarters regarding "sending fraudulent e-mails (phishing)" and a series of related posts on the internet with reports of "hacker attacks on the General Secretariat for Information Systems", the General Secretariat for Information Systems points out that it was not attacked by hackers.
It is recalled that the GSPS, in the context of preventing the deception of users of its electronic services in cases of phishing, has posted on its official website a page with Security Instructions for users following the following path:
www.gsis.gr → “Help” → “Frequently Asked Questions – Answers” → “Security of Electronic Services” (https://www.gsis.gr/gsis/info/gsis_site/Help/FAQsPages/FAQs_asfaleia.html).
For example, on this page, and in relation to the aforementioned publications, detailed instructions are given for the protection of users in the following cases:
- "I have received a message from the General Secretariat for Information Systems. How can I know if it is genuine?"
- "How do I know at all times that I have connected to an authentic G.G.P.S. electronic service page?"
- "What security measures should I follow for the safe use of the GSPS electronic services?"
The General Secretariat for Information Systems does not send taxpayers emails with attached files.
The GSS takes all necessary measures to protect its systems from electronic attacks and urges taxpayers to comply with the relevant instructions on security rules.
We have observed in recent years (corresponding to world-renowned services or companies), Greek State bodies, Organizations and companies to give immediate & honest responses with press releases after the announcement of electronic attacks against their infrastructures or to possible suspicions of attacks. SecNews has criticized many times in the past, the incorrect practice of not announcing breaches or security problems. Many bodies chose to essentially hide the problem “under the rug”, fearing negative publicity, which essentially magnified the problem of data breaches. To the credit of the responsible executives, this now seems to be a thing of the past.
We salute and commend the competent management teams for their practices in informing the public both about false incidents (as was the case in this particular case) and about real incidents due to lack of security measures or incorrect configuration.



