< Back to situation

[REVISION HISTORY]

INF Grupa cyberattacks on Croatia

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-08-23 21:23 UTC → 2026-08-25 15:03 UTC · added removed

The Serbian-based hacking group INF Grupa has conducted a series of cyberattacks targeting Croatian infrastructure and personal data. In mid-August, the group claimed to have leaked the personal information of 86,000 Croatian citizens, asserting the data was obtained from the Croatian judicial system. The compromised details included names, personal identification numbers (OIB), dates of birth, and citizen registration numbers (JMBG). The group stated they were releasing the data for free as retaliation for recent arrests. By late August, the group expanded its targeting to include the Fininfo.hr portal and an unnamed healthcare facility. Reports indicated Cybersecurity expert Leon Juranić noted that the release group posted claims on a dark web forum regarding the compromise of 34,000 records from the Fininfo.hr database FinInfo.hr financial platform and an unidentified medical institution. The group alleges it has leaked approximately 9,000 34,000 business records from a medical institution, and 9,000 individual records, which reportedly contained include sensitive patient information data and medical diagnoses. The group has This follows a history of targeting various Croatian institutions, including the Ministry of Labour and previous incident involving the Croatian Pension Insurance Institute. Institute (HZMO), where the group claimed to have accessed personal identification numbers and contact details; however, HZMO stated that its services and pension payments remained unaffected.

Versions

  1. 2026-08-25 15:03 UTC INF Grupa cyberattacks on Croatia
  2. 2026-08-23 21:23 UTC INF Grupa cyberattacks on Croatia

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.