Lyce · Hybrid Watch

hw_1779d34251f575a7

Pro-Kremlin hackers target multiple Greek institutions, including public transport and infrastructure networks.

The hacker group known as NoName057(16), widely recognised as pro-Russian, launched distributed-denial-of-service (DDoS) attacks that overwhelmed access to public-services and transport-infrastructure websites in Greece. The targets were not limited to government ministries but extended into transport hubs and banking institutions, suggesting an intent beyond mere espionage to disruption of critical infrastructure. Geographically the attack struck across multiple nodes within the Greek institutional network rather than a border zone or maritime region. The dynamics indicate a shift by Russian-linked actors toward striking the digital underpinnings of infrastructure in NATO/EU states: by disabling key portals and services they impose cost and uncertainty while staying below traditional battlefield thresholds. The inclusion of transport hubs (metro, airport), shipping-registry, and banking targets points to a hybrid-warfare logic of degrading resilience rather than outright physical attack. The attribution is described as “pro-Kremlin hackers” and the list of affected institutions underscores how Greece, a geostrategic Mediterranean partner, is being exposed to these forms of attack.

Occurrence
2024-03-24
Publication
2024-03-23T23:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
GR
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2024-03-23T23:00:00Z

    The hacker group known as NoName057(16), widely recognised as pro-Russian, launched distributed-denial-of-service (DDoS) attacks that overwhelmed access to public-services and transport-infrastructure websites in Greece. The targets were not limited to government ministries but extended into transport hubs and banking institutions, suggesting an intent beyond mere espionage to disruption of critical infrastructure. Geographically the attack struck across multiple nodes within the Greek institutional network rather than a border zone or maritime region. The dynamics indicate a shift by Russian-linked actors toward striking the digital underpinnings of infrastructure in NATO/EU states: by disabling key portals and services they impose cost and uncertainty while staying below traditional battlefield thresholds. The inclusion of transport hubs (metro, airport), shipping-registry, and banking targets points to a hybrid-warfare logic of degrading resilience rather than outright physical attack. The attribution is described as “pro-Kremlin hackers” and the list of affected institutions underscores how Greece, a geostrategic Mediterranean partner, is being exposed to these forms of attack.