President Christodoulides’s contact details exposed online, cybersecurity expert says

by Fanis Makrides

Source: in-cyprus.philenews.com

Mobile phone numbers and email addresses belonging to executive branch officials in Cyprus, including President Nikos Christodoulides, are under certain conditions accessible to anyone seeking to carry out a malicious act, according to an Italian cybersecurity expert who warns the exposure could evolve into a security threat for the Republic.

The warning comes from Andrea Mavilla, a specialist in cybersecurity and personal data protection who has previously spoken to media about leaks of personal data belonging to senior officials and security service personnel in various countries, including Italian Prime Minister Giorgia Meloni.

Mavilla sent Phileleftheros a screenshot from a specialised console showing personal data gathered on Christodoulides and other officials, including phone numbers allegedly used by the President and his email address. Phileleftheros’s own efforts to verify the material confirmed that some of the leaked phone numbers belonging to Greek Cypriot officials are indeed the ones they use, though for obvious reasons the newspaper cannot elaborate further.

The wider picture

To support his warning about the risks of such data being obtained, Mavilla demonstrated how an official’s email account can be spoofed. Through a relevant online service, he showed how a malicious actor can send a message with a faked sender field, so that it appears to the recipient to come from an official’s real email address, without this meaning the account itself has been accessed.

Screenshots shown by Mavilla also indicated leaked data for members of Christodoulides’s government, officials of the Republic’s services and departments, and executives of semi-state organisations, as well as phone numbers belonging to cybersecurity officials.

The concern

Before hearing what Mavilla had to say, and in an effort to confirm his identity, Phileleftheros contacted a member of a journalistic team from a European country that had previously reported on the Italian expert’s findings.

Asked about his motives for examining cybersecurity issues in various countries, including Cyprus, Mavilla said his concern is that someone with bad intentions could impersonate senior state officials or media executives to send convincing but misleading messages, for example fabricating a false government policy announcement and presenting it as authentic. This, he said, is why he considers the exposure of this personal and professional data so serious. He added that if the exposed data falls into the wrong hands, it could be misused for phishing, malware distribution, social engineering or other types of attacks.

Asked specifically about the Greek Cypriot officials’ data shown to him, Mavilla said the situation should not be underestimated, stressing: “I have absolutely no intention of misusing this information.”

Authorities aware

Phileleftheros understands that officials responsible for cybersecurity in the Republic of Cyprus are aware of the issues raised by Mavilla and are evaluating them according to their standard procedures. This does not necessarily mean the authorities share the views he has expressed.

RAI3: Mavilla contacted the CIA

The cybersecurity issues raised publicly by Mavilla were also covered by the journalistic team behind “Report,” a long-running programme on Italian state broadcaster RAI 3. In a written item accompanying the episode, broadcast on November 30, 2025, the programme said Mavilla had accessed several platforms, including Lusha, Contact Kasper, Apollo.io and UpLead, based in the United States, Russia and Israel, without breaching their systems, and obtained databases containing mobile numbers, landline numbers and email addresses of heads of state, from Italian President Sergio Mattarella to Prime Minister Meloni, as well as of every government ministry, including sensitive ones such as Defence, Foreign Affairs and the Interior.

According to the programme, the data included contact details for ministers Guido Crosetto, Antonio Tajani and Matteo Piantedosi, along with databases holding contact information for Italy’s own Cybersecurity Agency, the DIS intelligence service, the police, the Carabinieri, the Guardia di Finanza, police chiefs, prefects, and judicial officials across the country. It also reportedly extended to executives at major Italian companies including Eni, Leonardo, Enel and Fincantieri, banks including CDP, UniCredit, Intesa Sanpaolo, MPS, Mediobanca, Generali and Mediolanum, and the Vatican Bank (IOR), as well as databases of political parties, employers’ federation Confindustria, trade unions, and broadcasters Mediaset and Sky.

The same reportedly applied to major newspapers including Repubblica, Corriere, Il Fatto, Il Giornale and La Verità, and to Italian and foreign media ranging from the New York Times to CNN, along with data on bishops and cardinals, thousands of Vatican contacts, and embassies worldwide.

Mavilla contacted the CIA on March 27, and the agency subsequently deleted the relevant contact details, according to the programme. In Italy, he reported the matter to the Cybersecurity Agency and the Data Protection Authority, which opened an investigation in April, though the data reportedly remains accessible. The case eventually reached the Polizia Postale, Italy’s postal and communications police, which is now investigating.

A July 2026 investigation by Portuguese weekly Expresso reported that Mavilla had handed over personal data on around twelve high-profile individuals, which the newspaper said it verified one by one and found to be accurate.

You may also like