A threat actor calling itself INF GRUPA has listed a database it says contains 4,336,629 unique records of Serbian citizens for sale on the dark web forum darkforums.ru, according to a Brinztech breach alert dated 24 August 2026. The advertised fields reportedly include full names, Unique Citizen Identification Numbers (JMBG), national ID card and passport numbers, dates of birth, home addresses, phone numbers, email addresses and medical histories. Brinztech reports the actor put the set on open sale after a failed extortion attempt against an unnamed Serbian institution that allegedly ignored negotiation attempts and went to law enforcement instead.
One caveat has to lead this brief rather than trail it: every source available on this incident is OTHER-tier. There is no victim statement, no filing with the Commissioner for Information of Public Importance and Personal Data Protection, no national CERT advisory and no vendor report. The listing itself is real and documented; the contents, the origin and the record count remain actor claims that no authoritative party has corroborated. Treat the numbers below as advertised figures, not verified ones.
What Happened
The picture assembled from the available reporting is of two overlapping claims about Serbian citizen data in the same fortnight, not one clean incident.
On 17 August 2026, Dark Web Informer reported a forum user posting as bytetobreach claiming to hold multiple databases belonging to RFZO, the Republic Fund for Health Insurance of Serbia, with links posted across five separate mainstream file hosting services. That post claimed the largest tables held roughly 8 million rows and estimated about 5 million distinct individuals once duplicates and corrupted records were discounted, a figure approaching the size of Serbia's population. Unusually for a leak listing, the poster stated RFZO had been notified directly, that no ransom was demanded and that the data would not be handed to unknown parties. Dark Web Informer labelled the claim unverified and noted the account was created in March 2026.
Undercode News, reporting the same day off a Dark Web Intelligence post, described the RFZO allegation as thin on evidence: no stated intrusion vector, no confirmed extraction scope, no proof the data genuinely originates from RFZO systems. It flagged separate Serbian-language discussion alleging databases offered for sale with screenshots of tables and sensitive identifiers, again unconfirmed.
The Serbian citizen movement Solidarity, citing documentation by the Bezbedan Balkan portal, gave the most specific account of the samples: database structures and records containing JMBG and LBO health insurance numbers, plus data on selected doctors, their specialisations and healthcare institutions, with one sample said to contain 342,732 records of selected physicians. Solidarity was explicit about the limits of what had been shown, stating that it is not confirmed that the data of all insured persons was taken, nor that medical findings, diagnoses or treatments were compromised. The group has called on RFZO and the Ministry of Health to inform the public and to open an independent investigation.
Then on 24 August, the INF GRUPA listing appeared with a different actor name, a different number and, critically, no named victim. Brinztech's alert attributes the dataset to an unnamed Serbian institution rather than to RFZO.
Accounts differ, and the honest reading is that nobody has established whether these are the same data. The record counts cannot be reconciled by rounding: 4,336,629 records advertised by INF GRUPA (Brinztech) against roughly 5 million individuals and ~8 million rows claimed by bytetobreach (Dark Web Informer). The actor names differ, the stated motives are opposite (INF GRUPA sells after a failed extortion; bytetobreach says it demanded nothing and notified the victim), and only the second claim names RFZO at all. This may be one dataset resurfacing under new branding, two slices of the same compromise, or two unrelated claims. No source resolves it.
What Was Taken
The advertised composition, ordered by how well each element is supported:
- National identifiers. JMBG appears in both the INF GRUPA advertisement (Brinztech) and in the samples documented via Bezbedan Balkan and relayed by Solidarity, making it the most consistently attested field across independent claims.
- Health insurance identifiers (LBO). Reported in the RFZO sample material described by Solidarity.
- Identity documents. National ID card numbers and passport details, claimed only in the INF GRUPA listing per Brinztech.
- Contact and demographic data. Dates of birth, residential addresses, telephone numbers and email addresses, per Brinztech.
- Medical data. Brinztech reports that healthcare histories are included in the archive. This is the single most consequential claim in the entire dataset and it rests on one OTHER-tier source describing an actor's own advertisement. Solidarity explicitly states the opposite has not been established, that medical findings, diagnoses and treatments are not confirmed compromised. Defenders should plan for the possibility while recognising it is unproven.
- Provider data. A sample of 342,732 records covering selected doctors, specialisations and institutions, per Solidarity.
Field-level contents were not itemised in the bytetobreach post, per Dark Web Informer, so the overlap between the two claimed datasets cannot be assessed from public material.
Why It Matters
Scale is the first problem. Whether the true figure is 4.3 million or 5 million, either represents a majority of Serbia's population in a single archive, which effectively converts a breach response into a national identity-assurance problem.
Permanence is the second and worse one. JMBG, LBO and passport numbers are not credentials that can be rotated. Once exposed, they are exposed for the lifetime of the holder, which makes every downstream authentication scheme that treats them as proof of identity structurally unreliable from here forward. That includes bank onboarding, telecom SIM issuance, e-government portals and healthcare access. Solidarity's assessment, that confirmation would make this one of the most serious incidents in the history of Serbia's electronic government, is proportionate to the identifiers involved.
Distribution is the third. The RFZO claim involved five mainstream file hosting mirrors rather than a gated criminal marketplace, per Dark Web Informer. Content on mainstream hosts propagates faster and outlives takedowns. INF GRUPA has form here: Undercode News reports the group released roughly 105,000 Croatian citizen records containing names, phone numbers, email addresses and OIB identifiers free of charge rather than for payment, while nsreporter.rs reports an earlier free release of Croatian judicial system data covering 86,000 individuals, built from a prior set of about 60,000 records plus 26,000 new ones. An actor that has repeatedly chosen free publication over sale is one whose current sale listing may convert to open dump without warning.
Fourth, the regional and political dimension. INF GRUPA is described in Serbian reporting as operating from Serbia and targeting Croatian institutions, publishing messages framing its activity as retaliation, including a claim that the Serbian national arrested by Croatian police is not a member and is unconnected to the attacks. Croatian police, per Srpske Novine, charged a 33-year-old Serbian national, Georgije V., owner of the Novi Sad firm Elite Security Systems, over unauthorised access to six systems including MUP, the Finance Ministry, HZZO and HZMO, handing him to detention supervision on 29 July, with the investigation trail reportedly running through Sweden and Belize. Whether the arrest touches the group at all is contested by the group itself and unresolved publicly. What is clear is that this is not ordinary financially-motivated crime and should not be modelled as such.
Finally, the regulatory timing. Serbia's Ministry of Justice published a draft Law on Personal Data Protection on 30 July 2026, open for public consultation through 10 September, expanding the statute from 102 to 175 articles and adding regimes for AI processing and video surveillance, per IAPP. An incident of this scale landing mid-consultation is likely to shape the final text, particularly around public-sector accountability and breach notification.
The Attack Technique
No source establishes an intrusion vector. Undercode News states plainly that the original disclosure provides no basis to determine how access was obtained or whether the data is genuinely from RFZO systems.
The only technical signal in the public record comes from Solidarity, which reports that publicly available analyses showed individual RFZO servers advertising very old software version identifiers, specifically CentOS 7 and PHP 5.4.16. CentOS 7 reached end of regular security support in June 2024 and PHP 5.4 has been unsupported for years. Solidarity is careful, and correct, to note that banner versions do not prove exploitation, since backported patches leave displayed versions unchanged. The group also states that security problems on RFZO web properties have allegedly been documented for years. That is a maintenance question, not an established attack path.
Brinztech's account implies a human-driven extortion sequence rather than opportunistic scraping: compromise, private negotiation attempt, victim escalation to law enforcement, retaliatory commercialisation. That sequencing is the actor's own narrative and carries the reliability that implies.
What Organizations Should Do
- Stop treating national identifiers as authenticators. Banks, telecoms, insurers and public-service portals operating in Serbia and the wider region should assume JMBG, LBO, ID card and passport numbers are known to attackers for a majority of the population, and require a second, non-static factor for any identity-proofing, account recovery or high-value transaction that currently accepts them alone.
- Inventory and patch end-of-life infrastructure on public-facing estates. The CentOS 7 and PHP 5.4 observations reported by Solidarity are a fair prompt to audit your own perimeter for unsupported operating systems and runtimes, confirm whether backported patching is genuinely in place, and suppress version banners where it is not.
- Hunt for your own data on mainstream file hosts, not just dark web forums. The RFZO claim used five ordinary cloud hosting services. Monitoring that only covers criminal marketplaces will miss this distribution pattern entirely. Build takedown workflows for mainstream hosts now, before you need them.
- Rehearse the actor-notification scenario. Both claims involve direct contact with the victim, one demanding payment and one reportedly demanding nothing. Have a defined path for inbound actor communications that routes to incident response and legal without a delay that the actor can interpret as being ignored, which is the exact grievance INF GRUPA cited per Brinztech.
- Model free release as the likely endpoint. Given INF GRUPA's documented pattern of publishing Croatian datasets at no charge, plan citizen notification, fraud monitoring and call-centre capacity for full public exposure rather than limited criminal circulation.
- Prepare for the new regulatory baseline. Organisations processing Serbian personal data should track the draft LPDP through its 10 September consultation close, particularly the restructured public-authority provisions, and align breach-response documentation to the expanded framework rather than the 2018 law.
- Push for authoritative confirmation and do not fill the gap with the actor's numbers. Until RFZO, the Ministry of Health or the Commissioner issues a statement, every figure in circulation is a claim by someone selling the data or reporting on someone selling it. Internal risk assessments should record the range and its provenance, not a single confident total.
Sources: Threat Actor 'INF GRUPA' Claims Sale of 4.3 Million Serbian Citizen... | Serbia's draft Personal Data Protection Law: What changes are on th... | Serbian National Health Insurance Databases Allegedly Published Acr... | Serbia’s Health Insurance System Faces a Disturbing Dark Web Data B... | Citizens' data theft: RFZO and the Ministry of Health owe the publi... | 105,000 Croatian Citizen Records Allegedly Leaked by Serbian Hacker... | Croatia Traces Hacking Breach to Novi Sad Cybersecurity Firm Srpsk... | ODMAZDA ZBOG HAPŠENJA U HRVATSKOJ: Hakerska grupa tvrdi da policija...