The EETAA ransomware attack in March 2025 resulted in a significant data breach, exposing the personal information of 2.5 million individuals. This event not only impacted the Greek public sector but also highlights broader GDPR and cybersecurity compliance concerns for organisations across the UK and EU.
Details of the EETAA Ransomware Attack
Between 1 and 5 March 2025, the Greek company EETAA (Hellenic Agency for Local Development and Local Government) suffered a severe ransomware attack. The attack compromised critical information systems, leading to the exposure of data belonging to millions of Greek citizens. EETAA is responsible for managing and implementing various social programmes and services, making it a high-value target for threat actors seeking sensitive personal data.
- Victim: EETAA (eetaa.gr), an agency under the Ministry of Social Cohesion and Family
- Attack period: 1 March to 5 March 2025
- Number of affected individuals: 2.5 million
- Type of attack: Ransomware
The data compromised in the breach included names, identification numbers, contact details and potentially other personally identifiable information processed by EETAA in delivering public services.
Attack Timeline and Regulatory Response
The ransomware attack was detected in early March 2025, with systems disrupted over several days. Following discovery, EETAA notified Greece’s data protection authority as required by GDPR. The authority launched an immediate investigation, focusing on both the technical aspects of the breach and the regulatory obligations of the affected organisations.
The investigation uncovered several serious shortcomings:
- No valid data processing agreement was in place between EETAA and the Ministry of Social Cohesion and Family at the time of the incident
- Evidence of inadequate security controls and oversight
- Failure to fully meet GDPR requirements for protecting personal data
As a result, the data protection authority imposed a total fine of 350,000 euros on both the Ministry and EETAA. The regulator highlighted that the absence of a valid data processing contract contributed to the scale and impact of the breach, aggravating the organisations’ liability under GDPR.
How the Ransomware Attack Worked
Although the technical details of the ransomware strain have not been made public, the attack followed a typical pattern: threat actors gained unauthorised access to EETAA’s networks, deployed ransomware to encrypt files, and disrupted access to information systems. Given the volume of data affected and the public-facing role of EETAA, attackers likely exploited vulnerabilities in remote access or internal controls. The breach window from 1 to 5 March 2025 suggests a well-planned incursion, with attackers remaining undetected for several days while exfiltrating and encrypting key data assets.
Impact and Ongoing Risks
The EETAA ransomware incident demonstrates the far-reaching consequences of cyber attacks on public sector organisations. The exposure of 2.5 million individuals’ data represents a significant privacy risk. Once compromised, personal information may be sold, leaked or used for further criminal activity such as phishing or identity fraud.
As of June 2025, there is no public evidence that the stolen data has been posted on criminal forums, but regulators and affected individuals remain on alert. The Greek data protection authority continues to monitor the situation and has ordered EETAA and the Ministry to strengthen security controls and ensure full regulatory compliance.
- The breach has implications for data subjects, who may face increased risk of scams and identity misuse
- The regulatory investigation and fines serve as a warning to other organisations about the need for robust contractor management and clear data processing agreements
- Public sector bodies across Europe are reviewing their incident response and contractual safeguards in light of this case
Key Lessons for GDPR Compliance
The fine imposed in this case underscores that regulatory authorities will scrutinise not only the technical cause of a breach but also the legal basis for data processing and sharing. The absence of a valid data processing agreement was deemed a critical failure, exacerbating the impact and resulting penalties. For UK and EU organisations handling personal data, this case highlights the importance of:
- Ensuring all data sharing arrangements are backed by up-to-date, GDPR-compliant contracts
- Regularly reviewing and testing technical and organisational security controls
- Promptly reporting breaches and cooperating fully with regulatory investigations
Why This Event Matters
The EETAA ransomware attack is one of the largest public sector data breaches in Greece, with direct relevance for organisations throughout the UK and EU. It highlights the regulatory and reputational consequences of failing to implement both technical and contractual safeguards. The size of the fine reflects not just the breach itself but also broader systemic failings in governance and compliance.
What Organisations Should Do Now
Organisations should urgently review data processing agreements with partners and ensure all are GDPR-compliant. Technical security controls must be tested and updated to defend against ransomware threats. Rapid detection, incident response planning and regulatory cooperation are critical to minimising the risk and impact of future attacks.
Originally reported by lawspot.gr.






