Director of the EAK Michalis Bletsas: "The dissemination of telephone numbers and personal emails in any way automatically violates all types of online privacy. Unsubstantiated publications deal with the obvious."
In connection with press reports and starting from them, the National Cyber Security Authority points out:
On September 7, 2026, many Greek officials, including the Director, as well as Greek journalists, received messages from an Italian telephone number on WhatsApp which highlighted the leakage of personal data concerning senior government officials. Three screenshots from a supposed information collection application were shared with the Director of the Authority, which concerned himself, the Prime Minister, and the President of the Republic of Cyprus, and which, in a particularly flamboyant and colorful way that resembles scenes from a film, provided emails and telephone numbers.
In the case of the Prime Minister, the mobile number that "leaked" to the sender of the messages is old and has even appeared on a publicly accessible website on the internet since 2018.
In the case of the Director of the EAK, some of the telephone numbers belonged to his associates and not to him (likely from publicly accessible online naming registrations made 25 years or more ago), and as in the case of the Prime Minister, the mobile phone that appears is very old and has been shared on dozens of applications and websites, while the email address was also secondary in importance with its main use being sharing on websites and online applications.
That is to say: the material did not result from a system breach, malicious access to state infrastructure, or theft. It is a collection of old, publicly available, or voluntarily shared information, typical of data broker commercial platforms that recycle old WHOIS registrations, directories, third-party service leaks, and public profiles.
Based on the above, the specific allegations did not contain any substantial new information that justifies the initiation of a technical investigation into the cybersecurity incident: there was no indication of an event in a network or system, nor any evidence of unauthorized access.
It is obvious to everyone that from the moment we share our telephone number or send an email, there is no issue of privacy for this information: it becomes accessible on the internet in various ways and is often used against its holders.
It is clarified, finally, that the legality of the commercial exploitation of personal data by such platforms is a matter of the General Data Protection Regulation and falls under the jurisdiction of the Data Protection Authority, which has already highlighted the seriousness of the phenomenon, while any criminal aspects concern the judicial and police authorities.
The EAK does not diminish the issue—it places it in the correct context. A telephone number or an email is not a "key" to any system, but it is an entry point for social engineering. The real threats are:
- Targeted phishing / smishing / vishing and impersonation of third parties, often using synthetic voice.
- "Phishing" scams, where the first contact is made through a targeted email address and followed by the extraction of information from the target itself—a tactic that has already occupied the country publicly.
- SIM card replacement and misuse of recovery codes where the mobile acts as a second factor.
- Data correlation: the worrying thing is not the individual piece of information, but the possibility of mass linking of numbers, roles, and relationships—an issue that touches upon national security.
- Doxxing (malicious collection and publication of personal information about a person online, without their consent) and harassment of public officials, journalists, and members of Security Forces.
The Authority recommends to officials, public servants, and citizens:
- Separation of identities: strictly separate data for (a) official use, (b) registrations in services/commercial platforms, (c) close personal circle. Never a common number for all three.
- Critical information is not disclosed anywhere: the number used for second-factor authentication is not provided on websites, applications, tenders, or loyalty programs.
- Abolition of SMS as a second factor and transition to physical FIDO2/passkeys for high-value accounts.
- Clearing the imprint history: checking and anonymizing old WHOIS registrations, removing information from old provider pages, requests for deletion to data brokers.
- Institutional obligation for bodies not to republish personal mobile numbers and private emails in announcements, transparency reports, profiles, and attachments.
- Verification of a second channel in every request received from an unknown number, no matter how "official" or "urgent" it appears.
- Reporting incidents on a documented basis: the Authority examines every report with technical criteria and not based on impressive presentation.
The EAK will continue to evaluate every report based on actual incidents and technical documentation, without fueling a climate of insecurity with material that does not withstand basic scrutiny. At the same time, it considers useful that public discussion is directed towards an existing structural problem: the unregulated trade of personal data and the need for institutional response at the European level. The Authority remains at the disposal of bodies and citizens for technical guidance and information.
