Image 1 — [RFZO.RS] Serbia Health Insurance Fund hacked
Image 2 — [RFZO.RS] Serbia Health Insurance Fund hacked
Image 3 — [RFZO.RS] Serbia Health Insurance Fund hacked
Image 4 — [RFZO.RS] Serbia Health Insurance Fund hacked
▲ 195 r/Malware+2 crossposts

[RFZO.RS] Serbia Health Insurance Fund hacked

Different posts regarding the sales of databases belonging to RFZO (The Republic Health Insurance Fund of Serbia) have appeared on the dark web by ByteToBreach, who recently also attacked government infrastructure in Hungary and Romania, causing major shutdowns.

The alleged dataset shown in the screenshots shows astonishing figures of 9 millions rows of data per table, which represents a huge risks to the national safety of the citizens of Serbia, if those claims turns out to be true.

The Republic Health Insurance Fund (RFZO) communicated that it has taken preventive measures and is conducting a detailed check of information systems regarding the allegations.

The affected websites are down, but it seems a decision from the management, rather than the consequence of the attack, which seems to have simply targeted the extraction of the data, without any sign of deployment of ransomwares.

https://spear.cx/Thread-Selling-RS-Serbia-Health-Insurance-Databases-RFZO-RS

https://www.rtv.rs/sr_lat/drustvo/rfzo-preduzete-preventivne-mere-i-provera-bezbednosti-podataka_1736930.html

https://bezbedanbalkan.net/thread-2684.html

u/Fit_Asidy — 2 days ago

(unverified) Cyber attack on Hungary Allamkincstar

Bytetobreach, the same threat actor who recently attacked the Romanian cadastre (ANCPI) and deleted records after failed extortion attempts, recently put for sale an unverified claim on the Hungarian State Treasury through a compromise of 'MVH' (development agency).

This claim is unverified, despite the screenshots which were posted in the dark web forums.

Any feedback from professionals in the Hungarian cyber space is appreciated.

Sources :

https://spear.cx/Thread-Selling-GE-The-Magyar-Conquest

https://darkwebinformer.com/hungarian-state-treasury-allegedly-compromised-actor-claims-vcenter-and-identity-vault-access/

https://cybernews.com/security/hacker-deletes-romanian-land-registry-database/

u/Fit_Asidy — 20 days ago

(unverified) Cyber attack on Hungary Allamkincstar

Bytetobreach, the same threat actor who recently attacked the Romanian cadastre (ANCPI) and deleted records after failed extortion attempts, recently put for sale an unverified claim on the Hungarian State Treasury through a compromise of 'MVH' (development agency).

This claim is unverified, despite the screenshots which were posted in the dark web forums.

Any feedback from professionals in the Hungarian cyber space is appreciated.

Sources :

https://spear.cx/Thread-Selling-GE-The-Magyar-Conquest

https://darkwebinformer.com/hungarian-state-treasury-allegedly-compromised-actor-claims-vcenter-and-identity-vault-access/

https://cybernews.com/security/hacker-deletes-romanian-land-registry-database/

reddit.com
u/Fit_Asidy — 20 days ago

Romanian Government Cadastre (ANCPI) cyber attack / ransomware

Romanian Government Cadastre (ANCPI) cyber attack

A very serious ransomware attack is underway on the networks of ANCPI, Romania’s national cadastre agency.

Our close monitoring of the threat actor Bytetobreach — who carried out a similar attack last month on Latvia State Forests — detected simultaneous uploads on dark web forums regarding this incident. These claims were later confirmed on ANCPI’s official website.

What was described as a “small technical incident” in yesterday’s press release has suddenly been recharacterized by ANCPI itself as “the most serious technical incident in the institution’s history.”

Sources :

https://www.ancpi.ro/ (official press releases )
https://pwnforums.st/Thread-DATABASE-RO-Thy-arss-shall-be-spanked-Romania-ANCPIhttps://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked-Romania-ANCPI

reddit.com
u/Fit_Asidy — 1 month ago

Romanian Government Cadastre (ANCPI) cyber attack / ransomware

Romanian Government Cadastre (ANCPI) cyber attack

A very serious ransomware attack is underway on the networks of ANCPI, Romania’s national cadastre agency.

Our close monitoring of the threat actor Bytetobreach — who carried out a similar attack last month on Latvia State Forests — detected simultaneous uploads on dark web forums regarding this incident. These claims were later confirmed on ANCPI’s official website.

What was described as a “small technical incident” in yesterday’s press release has suddenly been recharacterized by ANCPI itself as “the most serious technical incident in the institution’s history.”

Sources :

https://www.ancpi.ro/ (official press releases )
https://pwnforums.st/Thread-DATABASE-RO-Thy-arss-shall-be-spanked-Romania-ANCPIhttps://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked-Romania-ANCPI

reddit.com
u/Fit_Asidy — 1 month ago
▲ 16 r/programare+1 crossposts

Romanian Government Cadastre (ANCPI) cyber attack / ransomware

A very serious ransomware attack is underway on the networks of ANCPI, Romania’s national cadastre agency.

Our close monitoring of the threat actor Bytetobreach — who carried out a similar attack last month on Latvia State Forests — detected simultaneous uploads on dark web forums regarding this incident. These claims were later confirmed on ANCPI’s official website.

What was described as a “small technical incident” in yesterday’s press release has suddenly been recharacterized by ANCPI itself as “the most serious technical incident in the institution’s history.”

Sources :

https://www.ancpi.ro/ (official press releases)
https://pwnforums.st/Thread-DATABASE-RO-Thy-arss-shall-be-spanked-Romania-ANCPIhttps://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked-Romania-ANCPI

reddit.com
u/Fit_Asidy — 1 month ago
▲ 33 r/hacking

Latvia's State Forests = Kaboom, kablaow

Someone is having fun not just defacing websites in Latvia, but taking down whole vCenters that were hosting hundreds of critical infrastructure belonging to the ministry of Agriculture through Latvijas valsts meži. The rascal is also brandishing a 7000~ password list as a proud loot of his cyber crimes from the vault of LVM, some of which seems to connect to Latvia registered government domains.

No confirmation from LVM official's, this is simply my own analysis did on the material collected. The threat actor, tracked by the name of Bytetobreach, documents each steps of his attacks.

He also seems to have deployed a ransomware called 'bytetocrypt' with a video recording that also shows full control over LVM's backup infrastructure .

Sources: My own analysis on the material available.

EDIT (LVM statement): https://www.lvm.lv/jaunumi/8018-lvm-saskaries-ar-kiberdrosibas-incidentu

https://eng.lsm.lv/article/society/crime/25.06.2026-cyberattack-on-latvian-state-forests-detected.a652645/

https://x.com/DailyDarkWeb/status/2069509041877844091

https://spear.cx/Thread-Database-LV-Latvia-s-State-Forests-Kaboom-kablaow

https://pwnforums.st/Thread-DATABASE-LV-Latvia-s-State-Forests-Kaboom-kablaow

https://breached.su/threads/lv-latvias-state-forests-kaboom-kablaow.88525/

u/Fit_Asidy — 2 months ago
▲ 72 r/latvia

Latvia's State Forests = Kaboom, kablaow

Someone is having fun not just defacing websites in Latvia, but taking down whole vCenters that were hosting hundreds of critical infrastructure belonging to the ministry of Agriculture through Latvijas valsts meži. The rascal is also brandishing a 7000~ password list as a proud loot of his cyber crimes from the vault of LVM, some of which seems to connect to Latvia registered government domains.

No confirmation from LVM official's, this is simply my own analysis did on the material collected. The threat actor, tracked by the name of Bytetobreach, documents each steps of his attacks.

He also seems to have deployed a ransomware called bytetocrypt with a video recording that also shows full control over LVM's backup infrastructure .

Sources: My own analysis on the material available.

EDIT (LVM statement): https://www.lvm.lv/jaunumi/8018-lvm-saskaries-ar-kiberdrosibas-incidentu

https://eng.lsm.lv/article/society/crime/25.06.2026-cyberattack-on-latvian-state-forests-detected.a652645/

https://x.com/DailyDarkWeb/status/2069509041877844091

https://spear.cx/Thread-Database-LV-Latvia-s-State-Forests-Kaboom-kablaow

https://pwnforums.st/Thread-DATABASE-LV-Latvia-s-State-Forests-Kaboom-kablaow

https://breached.su/threads/lv-latvias-state-forests-kaboom-kablaow.88525/

u/Fit_Asidy — 2 months ago

Latvia's State Forests = Kaboom, kablaow

Someone is having fun not just defacing websites in Latvia, but taking down whole vCenters that were hosting hundreds of critical infrastructure belonging to the ministry of Agriculture through Latvijas valsts meži. The rascal is also brandishing a 7000~ password list as a proud loot of his cyber crimes from the vault of LVM, some of which seems to connect to Latvia registered government domains.

No confirmation from LVM official's, this is simply my own analysis did on the material collected. The threat actor, tracked by the name of Bytetobreach, documents each steps of his attacks.

He also seems to have deployed a ransomware called bytetocrypt with a video recording that also shows full control over LVM's backup infrastructure .

Sources: My own analysis on the material available.

EDIT (LVM statement): https://www.lvm.lv/jaunumi/8018-lvm-saskaries-ar-kiberdrosibas-incidentu

https://eng.lsm.lv/article/society/crime/25.06.2026-cyberattack-on-latvian-state-forests-detected.a652645/

https://spear.cx/Thread-Database-LV-Latvia-s-State-Forests-Kaboom-kablaow

https://pwnforums.st/Thread-DATABASE-LV-Latvia-s-State-Forests-Kaboom-kablaow

https://breached.su/threads/lv-latvias-state-forests-kaboom-kablaow.88525/

https://x.com/DailyDarkWeb/status/2069509041877844091

u/Fit_Asidy — 2 months ago

ByteToBreach have breached Ikeja Electric, encrypting 50+ hosts, disrupting systems, and taking multiple subdomains offline. The actor also have stolen customer, employee, and business databases, source code, Active Directory data with offline cracked passwords, and impacted metering platforms linked to several vendors.

Threat actor: ByteToBreach

Sector: Energy / Utilities

Data type: Customer records, employee data, business databases, source code, Active Directory credentials

Observed: Apr 28, 2026

Sources:

https://x.com/H4ckmanac/status/2049126582694875608

https://x.com/CyhawkAfrica/status/2049109369522934179

https://darkforums.su/Thread-NG-Ikeja-Electric-Databases-Ransomware

https://preview.redd.it/ucx5htva8yxg1.png?width=2503&format=png&auto=webp&s=dd43e1915cc196076da0ef77c74cfe735daf131b

reddit.com
u/Fit_Asidy — 4 months ago

ByteToBreach have breached Ikeja Electric, encrypting 50+ hosts, disrupting systems, and taking multiple subdomains offline. The actor also have stolen customer, employee, and business databases, source code, Active Directory data with offline cracked passwords, and impacted metering platforms linked to several vendors.

Threat actor: ByteToBreach

Sector: Energy / Utilities

Data type: Customer records, employee data, business databases, source code, Active Directory credentials

Observed: Apr 28, 2026

Sources:

https://x.com/H4ckmanac/status/2049126582694875608

https://x.com/CyhawkAfrica/status/2049109369522934179

https://darkforums.su/Thread-NG-Ikeja-Electric-Databases-Ransomware

https://preview.redd.it/5wua149b7yxg1.png?width=2503&format=png&auto=webp&s=133a682cd6ee178877db97f9cb59f7c60d3d8cc8

reddit.com
u/Fit_Asidy — 4 months ago

ByteToBreach have breached Ikeja Electric, encrypting 50+ hosts, disrupting systems, and taking multiple subdomains offline. The actor also have stolen customer, employee, and business databases, source code, Active Directory data with offline cracked passwords, and impacted metering platforms linked to several vendors.

Threat actor: ByteToBreach

Sector: Energy / Utilities

Data type: Customer records, employee data, business databases, source code, Active Directory credentials

Observed: Apr 28, 2026

Sources:

https://x.com/H4ckmanac/status/2049126582694875608

https://x.com/CyhawkAfrica/status/2049109369522934179

https://darkforums.su/Thread-NG-Ikeja-Electric-Databases-Ransomware

https://preview.redd.it/ydh2bdu07yxg1.png?width=2501&format=png&auto=webp&s=70ba4c757ea53c3ac73c9f73bbe0f4f72ec30332

reddit.com
u/Fit_Asidy — 4 months ago