Suspected Members of “INF” Ransomware Group Arrested in Serbia
By DefendMe Team · · Hot News
Serbian police have arrested three suspected members of a hacker group known as the “INF Group”, which has been linked to a series of ransomware attacks targeting government institutions, companies and other organisations in Serbia and across the region. The suspects reportedly include two young men from Belgrade and Zaječar, as well as a 17-year-old minor. According to information reported by Serbian media, the group allegedly gained unauthorised access to information systems, extracted large quantities of data and subsequently demanded cryptocurrency payments from victims, threatening to publish or sell the stolen information on the Dark Web. Government Institutions and Sensitive Data Targeted The group has reportedly been linked to attacks involving Serbia’s National Health Insurance Fund (RFZO), a database of public enforcement officers, records maintained by the Serbian Ministry of Interior’s Foreigners Administration, the Football Association of Serbia and Belgrade’s public transport system. According to available information, the group has also been linked to attacks targeting institutions and organisations elsewhere in the region. The alleged attack involving RFZO is particularly significant because of the nature of the information contained in its databases. According to media reports, the police operation was carried out while there was a risk that compromised data could be offered for sale on the Dark Web. Ransomware and Cryptocurrency Extortion After gaining access to information systems, the attackers allegedly extracted data and provided victims with samples as evidence that their systems had been compromised. They then demanded ransom payments in cryptocurrency, threatening to publish or sell the stolen information if their demands were not met. According to published information, the amounts demanded reportedly ranged from tens of thousands to several hundred thousand euros, depending on the organisation targeted and the significance of the compromised data. This model is commonly known as “double extortion” ransomware, in which attackers use not only the possibility of disrupting access to systems but also the theft of data and the threat of disclosure as additional leverage against victims. Banks Were Allegedly Among Future Targets According to information from the investigation reported by Serbian media, the suspects were allegedly preparing additional attacks, including attacks against information systems belonging to banks in Serbia and other databases containing large quantities of citizens’ personal information. The police operation reportedly prevented the sale of compromised RFZO data, while a database containing stolen information was removed from the servers. Why Does This Case Matter? The case is another reminder that ransomware attacks represent a serious risk not only to individuals and businesses but also to government institutions, healthcare systems, banks and other organisations holding large quantities of personal and financial information. A particular concern is that stolen information can subsequently be used for further extortion, sold on the Dark Web or exploited for other forms of fraud and identity abuse. If you have been affected by a ransomware attack, cyber extortion or another form of cybercrime, preserve all communications, payment demands, cryptocurrency wallet addresses and transaction records, as well as any other available digital evidence. These records may be crucial for tracing funds, connecting an attack to related cases and assessing possible legal action. DefendMe Global