Back to all lessons
Awareness Lessons
2 months ago

Human Error Enables Ransomware Breach of 30,000 Records at Greek University

The Hellenic Open University suffered a ransomware attack traced back to human error, resulting in the exposure of 813 GB of personal data belonging to 30,000 individuals. Inadequate authentication measures and insufficient training for system administrators created the conditions that allowed attackers to succeed. This case underscores that even when an organisation meets GDPR notification requirements, preventable technical and human failures can still lead to massive data breaches. Regulatory compliance with notification rules is a floor, not a ceiling — organisations must proactively invest in people, processes, and controls to prevent incidents in the first place.

Tactical Insight

Immediate actions

  • Enforce multi-factor authentication (MFA) on all administrator and privileged accounts immediately.
  • Conduct an emergency audit of system administrator access rights to remove unnecessary privileges.

Training & awareness improvements

  • Deliver targeted, role-specific cybersecurity training for all system administrators covering phishing, credential hygiene, and ransomware vectors.
  • Establish a recurring security awareness programme with simulated attacks to reinforce good practices over time.

Long-term technical controls

  • Implement privileged access management (PAM) tooling to monitor, log, and control all administrator sessions.
  • Deploy endpoint detection and response (EDR) solutions across university infrastructure to detect ransomware behaviour early.
  • Maintain tested, offline backups of critical data and regularly validate restoration procedures to minimise ransomware impact.