President’s, officials’ data leak not linked to hacking, assessment finds

by Fanis Makrides

Source: in-cyprus.philenews.com

Cyprus authorities have investigated and assessed a leak of personal contact details belonging to President Nikos Christodoulides and other senior government and state officials, Phileleftheros can reveal.

According to cross-checked information, the issue, first uncovered in a Phileleftheros report last Saturday, occupied officials and several state departments intensively over the past 24 hours.

Those involved included the Deputy Minister of Research, Innovation and Digital Policy, Dr Nikodimos Damianou, the office of the Commissioner of Electronic Communications, Marios Pieris, and other state services responsible for safeguarding national security. Sources said that after experts examined the issue, a memo was drawn up to be forwarded to the Presidential Palace and other relevant authorities.

At the centre of the inquiry was whether phone numbers and email addresses belonging to Greek Cypriot officials, found gathered together on privately-run platforms, had been obtained through hacking. A government source told Phileleftheros that this does not appear to be the case, indicating instead that the information had been collected over time from open sources, meaning there is no indication it was acquired through malicious means.

Those who spoke to Phileleftheros about the sensitive cybersecurity issue generally wanted to convey that there is no immediate security threat, while still pointing to the standing advice to limit the amount of personal data people expose online. Phileleftheros said it had itself accessed the data in question and confirmed it is both genuine and available to companies offering specialised data services, and that it had also located a mobile number used by one official while in Brussels.

The issue was first raised with the newspaper by cybersecurity and data protection expert Andrea Mavilla, who showed how the leaked contact details could, under certain conditions, be accessed by anyone intending to use them maliciously. Mavilla, who had previously exposed a similar case in Italy involving a leak of Prime Minister Giorgia Meloni’s data, demonstrated how an official’s email account could be spoofed. He explained that, using a dedicated service, someone could send an email with a falsified sender field, making it appear to the recipient as though it came from an official’s genuine address, without actually having gained access to that person’s account.

“Someone with bad intentions could potentially impersonate senior state officials,” Mavilla said, adding that such a person could fabricate an entirely false announcement about government policy and present it as authentic, which is why he considers the exposure of this personal and professional data so serious.

You may also like