Listen to this Post
A New Data Leak Claim Puts Croatian Citizens in the Crosshairs
A new alleged data breach is drawing attention across the cybersecurity community after a threat actor identifying itself as the Serbian hacking group “INF GRUPA” claimed to have obtained and publicly released information belonging to 105,000 Croatian citizens.
The alleged dataset reportedly contains highly sensitive personal information, including names, telephone numbers, email addresses and Croatian personal identification numbers, known as OIBs. If the claims are genuine, the exposure could create serious risks for identity theft, impersonation, targeted phishing and other forms of social engineering.
The most concerning aspect is that the alleged dataset was reportedly made available free of charge, rather than being offered exclusively to criminals for payment. That changes the potential impact significantly: information that might normally remain behind a criminal marketplace could potentially circulate much more quickly among threat actors.
At the same time, there is an important reason to treat the incident cautiously. The claim has not been independently verified, and the available information contains an institutional inconsistency that raises questions about where the alleged data actually originated.
What the Threat Actor Claims
According to the dark web post reported by Dark Web Intelligence, INF GRUPA claims to have compromised systems associated with Croatian government institutions and obtained approximately 105,000 records.
The actor reportedly claims that the information was released publicly and without charge.
The alleged dataset is said to contain full names and surnames, telephone numbers, email addresses and Croatian OIB identification numbers.
The combination of those fields would make the dataset particularly valuable to criminals if authentic. A name by itself may have limited value, but when combined with an official identification number, telephone number and email address, it can become a powerful tool for impersonation.
The Political Motivation Claim
The alleged attackers reportedly described the operation as politically motivated rather than financially motivated.
That distinction matters because politically motivated intrusions often operate differently from conventional financially driven cybercrime.
A financially motivated group typically seeks to monetize stolen information through ransomware, extortion, fraud or underground data sales.
A politically motivated actor may instead prioritize disruption, public embarrassment, ideological messaging or the release of information designed to create pressure on a government or institution.
If INF
A Claimed Campaign Against Croatian Institutions
The threat actor reportedly characterized the alleged breach as part of an ongoing campaign targeting Croatian institutions.
That claim is significant, but it should not automatically be interpreted as proof that a coordinated campaign is actually underway.
Threat actors frequently exaggerate the scale, sophistication or political importance of their operations.
Claims of ongoing campaigns can also be used as psychological warfare, particularly when an attacker wants victims, journalists or security researchers to believe that additional attacks are imminent.
For that reason, the alleged campaign should be treated as an intelligence lead rather than an established fact until technical evidence confirms it.
Why the Alleged Data Is So Sensitive
The reported combination of personal information is what makes this claim particularly serious.
An exposed email address can be used for phishing.
A telephone number can support SMS scams, voice impersonation and account-recovery attacks.
A full name can help criminals construct convincing messages that appear to come from banks, government offices, employers or other trusted organizations.
An OIB adds another layer of sensitivity because it is a persistent personal identifier.
When these pieces are combined, attackers can build highly convincing profiles of individuals and use them to make fraudulent communications appear legitimate.
The Identity Fraud Risk
If the dataset is authentic, identity fraud would be one of the most obvious risks.
Criminals could potentially use leaked information to impersonate individuals when communicating with organizations that rely on personal information for verification.
The danger becomes greater when victims assume that a caller or email sender already knows private details about them.
For example, a fraudulent message containing a
That psychological advantage is exactly what makes large personal datasets so valuable to attackers.
The Phishing Threat Could Be Even Larger
The alleged leak could also provide attackers with a ready-made target list for phishing campaigns.
Instead of sending millions of random messages, criminals could target people using their real names and known contact details.
A phishing message could theoretically impersonate a government department, financial institution, telecommunications provider or another organization familiar to the victim.
The more accurate the information in the dataset, the easier it becomes to construct convincing social-engineering attacks.
Free Publication Creates a Different Problem
The reported decision to release the information publicly for free could make the situation more difficult to contain.
Data sold privately may remain within a relatively small criminal ecosystem.
Publicly released information can spread between forums, messaging channels, automated scraping systems and secondary data repositories.
Once personal information begins circulating across multiple platforms, removing the original publication does not necessarily eliminate the copies.
This creates a long-term privacy problem even if the original compromised system is secured.
The HZMO and HZZO Confusion
One of the most important details in the original report is an inconsistency involving Croatian government institutions.
The threat actor reportedly identifies HZMO while describing it as Croatia’s health insurance fund.
That description does not match the
HZMO refers to the Croatian Pension Insurance Institute, while HZZO is the Croatian Health Insurance Fund.
This discrepancy is important because it creates uncertainty over the alleged source of the data.
The dataset could potentially have originated from HZMO, HZZO, another government system or an unrelated source entirely.
It is also possible that the attacker simply used the wrong institutional description.
Why This Mistake Matters
A simple naming error does not automatically prove that a breach claim is false.
Threat actors can misunderstand the organizations they target, deliberately mislabel stolen information or use inaccurate translations.
However, institutional inconsistencies are useful warning signs when evaluating an unverified dark web claim.
Cybersecurity researchers should therefore avoid treating the claimed origin of the dataset as established until the data can be technically attributed.
No Independent Verification Yet
At the time of the original report, there was no independent confirmation that the alleged 105,000 records were authentic.
There is also no confirmed evidence establishing exactly which Croatian system was compromised.
That means the incident should currently be described as an alleged data leak, not a confirmed government breach.
This distinction is essential.
A threat
Threat Actors Have an Incentive to Exaggerate
Dark web actors have several reasons to exaggerate their claims.
A larger number of allegedly stolen records attracts attention.
Government-related claims can generate media coverage.
Political narratives can increase an
Even fabricated datasets can sometimes be used to establish credibility or intimidate future targets.
For defenders, the correct response is therefore neither blind acceptance nor immediate dismissal.
The claim should be investigated as potentially actionable intelligence.
What Croatian Organizations Should Watch For
Organizations potentially connected to the alleged dataset should look for unusual authentication activity, suspicious account-recovery requests and abnormal access patterns.
Security teams should also monitor for phishing campaigns that reference Croatian government services or contain unusually specific personal information.
Credential reuse should receive particular attention because exposed email addresses can become stepping stones toward additional compromises.
Organizations should also review whether sensitive personal information is unnecessarily exposed through external-facing systems.
What Individuals Should Watch For
Potentially affected individuals should be particularly cautious with unexpected emails, SMS messages and telephone calls requesting personal information.
A message containing
Victims should independently verify requests through official channels rather than relying on links, telephone numbers or contact details contained in suspicious messages.
The biggest danger after a data leak is often not the initial publication itself, but the wave of follow-up social engineering that may come afterward.
The Broader Balkan Cybersecurity Picture
The alleged incident also highlights a broader reality in cybersecurity: geopolitical tensions increasingly have a digital dimension.
Croatia and Serbia have a complicated regional history, and cyber operations can sometimes become another avenue for political confrontation.
That does not prove that the current allegation is state-sponsored or politically coordinated.
However, the claim demonstrates how cybercriminal branding, nationalism and political messaging can overlap in underground communities.
Attribution should therefore remain evidence-based rather than being inferred solely from an attacker’s stated identity.
Data Breaches Are Becoming More Than Extortion Events
The cybersecurity landscape has moved far beyond traditional ransomware.
Attackers increasingly steal information simply because the information itself has strategic, political or intelligence value.
A database does not need to generate a ransom payment to become dangerous.
Personal information can be weaponized for surveillance, influence operations, fraud, impersonation and targeted attacks.
The alleged Croatian incident illustrates why defenders must consider the downstream consequences of exposed data rather than focusing only on whether ransomware was deployed.
The Psychological Impact of Public Leaks
Large-scale leaks also create psychological pressure.
When people hear that tens of thousands of citizens may have been exposed, uncertainty spreads quickly.
Individuals may not know whether their own information is included.
Organizations may not know whether the attacker still has access.
Government agencies may face pressure to respond before forensic investigations are complete.
That uncertainty is itself a weapon that threat actors can exploit.
The Importance of Evidence Preservation
If the alleged dataset is being investigated, security researchers should preserve relevant evidence carefully.
Screenshots, timestamps, hashes, sample records and publication metadata can help investigators establish whether the material is genuine and where it originated.
However, researchers should avoid unnecessarily redistributing sensitive personal information.
Verifying a breach does not require amplifying the exposure of innocent victims.
The Bigger Question: Where Did the Data Come From?
The central unanswered question is not simply whether 105,000 records exist.
The more important question is whether those records actually came from the Croatian institution identified by the attacker.
Data circulating on underground forums can originate from older breaches, scraped databases, previously leaked information or completely unrelated sources.
A threat actor may claim ownership of data that was stolen by someone else.
Therefore, determining the provenance of the dataset is essential.
Why Provenance Matters
If the data originated from an old breach, the incident could be significantly different from a newly discovered intrusion.
If it came from an unrelated commercial database, the government attribution could be false.
If it genuinely came from a Croatian government system, however, the incident could represent a serious security failure requiring immediate forensic investigation.
The same dataset can therefore produce very different conclusions depending on its origin.
The Potential for Secondary Criminal Activity
Even if the original attacker is politically motivated, other criminals may not share that motivation.
Once personal information becomes public, financially motivated actors can potentially repurpose it.
The same data could be used for phishing, fraud, impersonation, account takeover attempts or targeted scams.
This is one of the most dangerous characteristics of public data leaks: the original attacker may no longer control how the stolen information is used.
The Difference Between Exposure and Exploitation
It is also important to distinguish between data exposure and confirmed criminal exploitation.
The publication of personal information does not automatically mean that every victim will experience identity theft.
However, exposure increases the opportunity for exploitation.
The larger the dataset and the more detailed the information, the more opportunities attackers have to select valuable targets.
This makes rapid verification and defensive monitoring particularly important.
What Undercode Say:
A Claim That Deserves Investigation
Undercode’s assessment is that the alleged 105,000-record leak should be treated as a serious threat-intelligence claim, but not yet as a confirmed breach.
The Number Is Attention-Grabbing
A dataset allegedly containing 105,000 people is large enough to attract significant attention, particularly when the claimed victims are connected to government systems.
Sensitive Fields Increase the Risk
The reported combination of names, OIB numbers, phone numbers and email addresses would be considerably more dangerous than a simple list of names.
The OIB Detail Is Particularly Important
A persistent personal identifier can make exposed records much more useful for impersonation and targeted fraud than ordinary contact information.
Free Distribution Changes the Threat
If the dataset really was released without charge, it could spread more rapidly than information restricted to a small group of buyers.
The Institutional Error Is a Red Flag
The HZMO-versus-HZZO confusion is one of the strongest reasons to maintain skepticism until the source can be independently established.
But the Error Is Not Proof of Fabrication
Attackers frequently misidentify institutions, especially when operating across languages, jurisdictions and political narratives.
Attribution Remains Unclear
The available claim does not independently establish that INF GRUPA actually compromised a Croatian government system.
The Serbian Identity Requires Verification
An attacker calling itself a Serbian group does not, by itself, prove the geographic origin or organizational structure of the actor behind the account.
Political Motivation Should Be Treated Carefully
The
Government Targets Increase Pressure
Even an unverified claim involving government infrastructure can force organizations to investigate because the potential consequences are substantial.
The Dataset Could Have Another Origin
The alleged records may have originated from a different Croatian institution, an older breach, a third-party provider or another unrelated source.
Old Data Can Be Repackaged
Threat actors sometimes recycle previously leaked information and present it as a new compromise.
Public Availability Can Accelerate Abuse
If the information is genuinely new and publicly accessible, criminals outside the original group could quickly begin exploiting it.
Phishing Is the Immediate Concern
The combination of personal information creates an obvious foundation for highly personalized phishing campaigns.
Social Engineering Could Follow
Attackers could potentially use the information to make fraudulent communications appear more convincing.
Government Branding Could Be Weaponized
Croatian government-related themes could provide a believable cover for phishing messages aimed at people whose information appears in the dataset.
Victims May Trust Familiar Details
People are more likely to believe a scam when the attacker already knows accurate information about them.
Data Breaches Have Long Tails
The consequences of a leaked identity record can persist for years, particularly when identifiers cannot easily be changed.
Public Leaks Are Difficult to Reverse
Even if the original post disappears, copies can continue circulating across underground communities.
Defensive Monitoring Matters
Organizations should monitor for unusual authentication events, suspicious password resets and abnormal account activity.
Individuals Need Verification Habits
People should independently confirm unexpected requests rather than trusting messages simply because the sender knows their personal details.
The Claim Could Become More Serious
If independent researchers confirm that the records are genuine and newly stolen, the incident would move from an allegation toward a verified breach.
Confirmation Could Change the Risk Assessment
Technical confirmation of the source system would significantly strengthen the credibility and seriousness of the claim.
False Attribution Is Also Possible
If the records are authentic but came from somewhere else, the alleged Croatian government connection could prove misleading.
The Dark Web Is Not Automatically Reliable
Underground forums contain a mixture of genuine stolen information, recycled material, exaggerated claims and outright fabrication.
Intelligence Requires Corroboration
The most reliable conclusions come from combining threat-actor claims with technical evidence, victim confirmation and independent research.
The 105,000 Figure Needs Validation
The claimed number should not be repeated as a confirmed count until the dataset itself and its uniqueness can be established.
The Same Applies to the Alleged Government Source
Attribution to HZMO, HZZO or another institution requires evidence beyond the attacker’s description.
Political Context Can Distort Reporting
Because the alleged attacker identifies as Serbian and claims political motivation, the story carries a geopolitical dimension that requires especially careful attribution.
Security Teams Should Avoid Panic
Unverified breach claims should trigger investigation and monitoring, not unsupported public conclusions.
Transparency Will Matter
If a Croatian institution confirms exposure, timely communication could help affected individuals recognize subsequent scams.
The Incident Demonstrates a Larger Trend
Cyber operations increasingly combine data theft, political messaging and psychological pressure.
Personal Data Has Strategic Value
Attackers do not always need ransomware or extortion when stolen identity information itself can create influence and disruption.
The Real Damage May Come Later
The most serious consequences could emerge after the alleged leak through fraud, phishing and impersonation campaigns.
Verification Is the Critical Next Step
Until independent evidence establishes the
Deep Analysis: What the Incident Could Mean
Command 1 — Verify the Dataset
Researchers should determine whether the alleged records contain genuine Croatian personal information and whether the records appear internally consistent.
Command 2 — Establish Provenance
Investigators should compare the dataset against known breaches and determine whether it can actually be traced to the claimed institution.
Command 3 — Check for Previously Leaked Information
Sample records should be examined against historical exposures to determine whether the material is genuinely new.
Command 4 — Investigate the Institutional Reference
The HZMO/HZZO discrepancy should be specifically investigated because it could reveal either attacker confusion or a misleading attribution.
Command 5 — Monitor Secondary Abuse
Security teams should watch for phishing, impersonation and fraud campaigns that appear to use information contained in the alleged dataset.
Command 6 — Preserve Evidence
Researchers should preserve relevant metadata and evidence without unnecessarily spreading victims’ personal information.
Command 7 — Avoid Premature Attribution
The identity claimed by the threat actor should not be treated as proof of the actor’s nationality, affiliation or sponsorship.
Command 8 — Prepare for Escalation
If the dataset is confirmed, affected organizations should be prepared for secondary attacks against both individuals and institutions.
✅ The alleged leak is not independently confirmed in the supplied report. The information should therefore be described as a claim rather than a verified 105,000-record Croatian government breach.
✅ The HZMO/HZZO distinction is materially important. HZMO refers to Croatia’s pension insurance institution, while HZZO refers to the country’s health insurance fund, making the threat actor’s description inconsistent.
❌ There is not enough evidence in the supplied material to confirm that INF GRUPA actually compromised HZMO, HZZO or another Croatian government system. The alleged origin of the records remains unresolved.
❌ The claim that the operation was politically motivated cannot be independently established from the threat actor’s statement alone. Motivation remains an allegation until supported by additional evidence.
Prediction
(-1) If the dataset is authentic, the biggest danger may emerge after the alleged leak rather than at the moment of publication. Criminals could potentially repurpose exposed contact and identity information for phishing, impersonation and fraud.
(-1) If the information spreads publicly, containment could become increasingly difficult. Multiple copies could appear across underground communities, making complete removal nearly impossible.
(-1) A confirmed government-origin breach would likely trigger deeper scrutiny of the affected institution’s security controls. Investigators would need to determine how the information was accessed, how long attackers had access and whether additional systems were compromised.
(+1) If the claim proves exaggerated or fabricated, the immediate risk to Croatian citizens would be considerably lower. However, the incident would still demonstrate why dark web breach claims require rapid verification rather than immediate acceptance.
(-1) The HZMO/HZZO inconsistency means the story is likely to remain uncertain until independent researchers validate the dataset. The coming evidence—not the attacker’s statement—will ultimately determine whether this was a genuine government breach, recycled data or a fabricated claim.
▶️ Related Video (66% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com/topic/Technology
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




