Hackers targeting Croatian and Serbian institutions arrested; police thwart data sale on darknet
Translated from Croatian and summarized by DistantNews. Read the original for the full story.
At a glance
- Serbian police arrested three members of the hacker group "INF Group," linked to numerous ransomware attacks and data breaches in Serbia, Croatia, and other regional countries.
- The group is suspected of unauthorized access to protected computer systems, data theft, and demanding ransoms in cryptocurrency to prevent the public release of stolen information.
- Targeted institutions included Serbian health insurance funds, public executor databases, and the Football Association of Serbia, as well as Croatia's Ministry of Labor and judicial system.
Serbian police have apprehended three individuals believed to be members of the hacker group "INF Group," a cybercriminal organization implicated in a series of high-profile attacks across the region. Investigators from the Service for Combating High-Technology Crime have identified the group as the most active and successful to date in the region, citing the significant number of attacks and compromised information systems.
Given the number of attacks and compromised information systems established so far, investigators consider 'INF Group' to be the most active and operationally successful hacker group identified in the region to date.
The arrested individuals, identified as N. M. S. (born 2004) from Belgrade, L. D. (born 2003) from Zajeฤar, and a 17-year-old from Belgrade, are suspected of unauthorized access to protected computers, networks, and data processing systems. L. D. faces additional charges of computer sabotage, while the minor is also suspected of extortion.
According to the investigation, the group targeted the information systems of state bodies, major corporations, and other organizations. They are suspected of gaining control over systems, encrypting data, or extracting large volumes of information, including personal and sensitive data of citizens. In some cases, the hackers allegedly demanded ransoms in cryptocurrency to prevent the public disclosure of the stolen data.
They are suspected of unauthorized access to protected computers, computer networks, and data processing systems.
Notable targets included the Republican Health Insurance Fund of Serbia, the database of public executors, the registry of the Serbian Ministry of Internal Affairs' Directorate for Foreigners, and the Football Association of Serbia. Systems belonging to Croatia's Ministry of Labor and its judicial system are also believed to have been attacked. The group is further linked to attacks on public transport systems in Belgrade and the information systems of several large companies across the region.
In some cases, ransoms were allegedly demanded in cryptocurrency so that the stolen data would not be published publicly.
Authorities emphasize that the swift action by the Service for Combating High-Technology Crime prevented the sale of compromised data from a state institution on the darknet. Additionally, several other planned cyberattacks on state and private entities in Serbia were thwarted. During searches of the suspects' residences, police seized items believed to have been used in the commission of these crimes. Serbian authorities consider this operation one of the most significant investigations against ransomware-related crime in the region.
Among the systems suspected of being attacked are the Ministry of Labor of the Republic of Croatia and the Croatian judicial system.
Originally published by Veฤernji List in Croatian. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.