[REVISION HISTORY]
Data breaches targeting Serbian institutions
Updated 1 time since CLSTR started tracking revisions of this situation.
What changed
2026-09-01 10:13 UTC → 2026-09-01 18:32 UTC ·
added
removed
In late August 2026, reports emerged regarding a potential data breach targeting a Serbian government portal used for student loan and scholarship applications. A group identifying as the ‘Albanian Electronic Army’ claimed to have released a data package containing information on approximately 83,000 individuals, including pupils and students. The Serbian Ministry of Education denied the claims, stating that all data remained secure and that technical measures were implemented to prevent leakage. Shortly thereafter, a separate breach was confirmed involving the Football Association of Serbia (FSS). Hackers stole the personal information of over 11,000 individuals, including high-profile Serbian athletes such as Aleksandar Mitrović, Dušan Tadić, Bogdan Bogdanović, and Nikola Milutinov. The stolen data was published on a dark web forum after ransom demands were not met. The breach reportedly began in April 2026 via a phishing email sent to the FSS. Many affected individuals had previously stayed at the Srbija Luks hotel within the FSS sports center in Stara Pazova. Following an investigation by police and prosecution, a man was arrested in late August on suspicion of unauthorized access to the FSS database. While the FSS stated they took measures to protect those compromised, many athletes and coaches reported they were never officially notified of the theft. Additionally, there are reports that the obligation to inform the Commissioner for Personal Data Protection has not been fulfilled.
Versions
- 2026-09-01 18:32 UTC Data breaches targeting Serbian institutions
- 2026-09-01 10:13 UTC Data breaches targeting Serbian institutions
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.