Ransomware Attack at Greek University Exposes 30,000 Records Due to Human Error
The Hellenic Open University suffered a ransomware attack traced back to human error, resulting in 813 GB of personal data being leaked to the dark web and affecting 30,000 individuals. Weak authentication measures and insufficient training for system administrators created exploitable gaps that attackers leveraged to gain access and exfiltrate data. This incident highlights how technical defenses alone are insufficient without a well-trained workforce and robust access controls. The HDPA's enforcement action underscores that universities and public institutions are held to the same data protection standards as commercial entities under GDPR. Failure to invest in both people and processes can result in devastating breaches with lasting reputational and regulatory consequences.
Tactical Insight
Immediate actions
- Enforce multi-factor authentication (MFA) on all administrative and privileged accounts immediately.
- Conduct an emergency audit of all system administrator accounts to remove unnecessary privileges and disable inactive credentials.
Long-term improvements
- Deliver role-specific, recurring security training for system administrators covering phishing, credential hygiene, and ransomware prevention.
- Implement a formal Privileged Access Management (PAM) solution to control, monitor, and log all privileged user sessions.
- Establish a data classification and minimisation policy to limit exposure of sensitive personal data across systems.
Detection & response measures
- Deploy endpoint detection and response (EDR) tools across all university servers and endpoints to identify ransomware behaviour early.
- Develop and regularly test an incident response plan that includes ransomware-specific playbooks and GDPR breach notification procedures.
- Maintain offline, tested backups of critical data to enable recovery without paying ransom.