
A strong debate has erupted in Greece over the security of the personal data of senior officials, following an investigation published by the Greek newspaper To Vima, according to which contact details of Prime Minister Kyriakos Mitsotakis, ministers, state officials, military personnel and persons connected to security structures appeared accessible on commercial data trading platforms.
To Vima's article, with the significant title "The Prime Minister's Phone is Not a Secret," raises the alarm about a phenomenon that is not necessarily related to a classic cyberattack on state systems, but to something perhaps even more worrying: the collection, packaging, and sale of digital traces of people holding key positions in the state.
According to Greek media reports, these platforms could contain mobile phone numbers, email addresses and other contact details that allegedly belonged to high-ranking political and institutional figures. Prime Minister Mitsotakis himself was mentioned among them. To Vima writes that similar data could be obtained not on the “dark web”, but on platforms accessible with a few clicks and, in some cases, for relatively low fees.
The issue immediately took on political dimensions. The opposition PASOK party demanded that the government and the competent authorities clarify whether they were aware of this exposure of personal data and what measures they had taken to protect senior officials. In its response, PASOK described the case as a problem that affects not only privacy, but also cybersecurity and potentially national security.
Greece's National Cybersecurity Authority responded by clarifying that the case does not necessarily constitute a hacking of government systems. The head of the authority, Michalis Bletsas, said that such data is often easily found online, as for years people leave digital traces on social networks, public websites, apps, hotel bookings, airlines or private services, which can then end up in the hands of data brokers.
In the specific case of the Greek Prime Minister, the Cybersecurity Authority said that the mobile phone number that was allegedly “leaked” was old and had been displayed on a public page since 2018. However, this clarification did not end the debate. On the contrary, it highlighted a broader problem: even when there is no direct hacking, the personal data of officials can be exposed and marketable in a worrying way.
Security experts warn that the risk doesn't just lie in publishing a phone number or email address. When this data is combined with other information, it can be used for targeted attacks, electronic fraud, phishing, social engineering, impersonation or attempts to install spyware on the devices of important people.
In this sense, the Greek scandal is not just a privacy story. It is a warning about how the gray market for personal data operates in the digital age. The state may have protected systems, secure servers, and official protocols, but if the personal data of the people who run institutions circulate freely on commercial platforms, then the vulnerability shifts from the system to the person.
This is precisely what makes the Greek case important for other countries as well. It doesn't always take a spectacular cyberattack to create a security risk. Sometimes all it takes is an old phone number, an email address used over the years, a registration with a private company, and a platform that brings it all together to sell as a product.






















