We protect corporate and service credentials from theft and malicious use.
The National Cybersecurity Authority determines that a significant number of corporate and service credentials circulate in illegal online markets. These credentials mainly originate from malicious stealing software (infostealers), phishing attacks, and the reuse of passwords in third-party services that have been breached. Their use forms the basis for many cybersecurity incidents, as it allows not only the violation of infrastructures but also direct access to correspondence, documents, and personal data.
A password does not grant access to just one account, but also to the owner's correspondence, documents, and data. When it falls into the wrong hands, the attacker does not need to breach any system... they just log in.
This situation is not just Greek. As the European Union Agency for Cybersecurity (ENISA) points out in its 2026 threat landscape report, credentials stolen by infostealers fuel phishing attacks, scams, ransomware attacks, and the sale of access to organizations through illegal markets.
For fundamental and important entities, the protection of credentials is a legal obligation under Law 5160/2024 and Presidential Decree 1689/2025, the observance of which is the responsibility of their governing bodies. The Authority has already requested that public sector bodies, through its circulars of June 8th and July 30th, 2026, implement multi-factor authentication (MFA) and promptly address vulnerabilities. The same measures are equally critical for every business, regardless of size or affiliation.
The National Cybersecurity Authority recommends:
- Use a different and strong password for each service; never use the corporate or service password on personal accounts and store your passwords in a reliable password manager, preferably the one chosen by our organization.
- Enable MFA on every account, preferably through an authenticator app or a security key, and never approve a login request that we have not initiated ourselves.
- Install software only from trusted sources and do not store service passwords on personal or shared devices.
- IT departments systematically monitor for potential leaks, immediately change exposed passwords, terminate active sessions, disable old authentication protocols, and implement security updates promptly.
Bodies and businesses report any suspicious access to a corporate or service account to incident@cyber.gov.gr, while citizens can contact the Directorate for Cybercrime Investigation of the Hellenic Police (tel. 11188).
We protect our credentials like the keys to our office: we do not share them, we do not leave them exposed, and we change them immediately when we suspect they have been lost.
