
THREAT LEVEL - Critical
20-05-2025
New Critical – Cyberattack Planned Against Critical Infrastructure in Cyprus
Threat Level Description
IthacaLabs has changed the Threat Level (Critical) adding a new observation:
An attack is expected imminently. Maximum protective security measures to meet specific threats and to minimize vulnerability and risk. Critical may also be used if a terrorist attack is expected seeking to destroy, incapacitate, or exploit critical infrastructures in order to threaten national security, cause mass casualties, weaken the economy, and damage public morale and confidence.
Description
We have observed by leveraging Threat Intelligence resources that hacking groups are targeting the critical infrastructure of Cyprus.
Described as “powerful, massive, and extensive,” the planned attack is expected to include Distributed Denial of Service (DDoS) tactics aimed at overwhelming network systems and disrupting essential services. These attacks can severely impact availability by flooding servers with illegitimate traffic, rendering systems inaccessible to legitimate users.
The threat level is further elevated by open calls for broader participation from additional actors, suggesting a coordinated and potentially large-scale campaign intended to magnify the attack’s impact.
Targeted assets include government websites and key public services, raising the risk of service outages, data breaches, and exploitation of system vulnerabilities.
Organizations in Cyprus should urgently prioritize the protection of their systems and data. Immediate actions to enhance cybersecurity postures and defense mechanisms are strongly recommended. It is essential to ensure systems are prepared to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises — key elements of a robust cyber resilience strategy.
Our Advisory and Managed Services, including our Security Operations and Technology Resilience lines, can help safeguard your organization against such threats.
Through proactive monitoring, threat detection, and incident response, our services are designed to keep your systems secure, resilient, and prepared for evolving cyber risks. We advise all organizations to remain vigilant and regularly review their cybersecurity postures.
Recommendation(s):
- Ensure all critical systems are up to date with the latest security patches.
- Enhance monitoring of network traffic for any signs of malicious activity.
- Prepare for potential DDoS attacks by working with your network providers on mitigation strategies.
- Backup essential data to ensure resilience in the event of a breach or system compromise.
- Increase security awareness among staff and partners about phishing attempts or other methods of gaining unauthorized access.
- Have an incident response preparedness plan in place.



