Na social networks information has emerged that it is the same hacking group that recently attacked Telecom now also hacked the Agency for Business Registers (APR), the institution that keeps records of companies and other legal entities in Serbia. The Agency for Economic Registers responds that the information is safe, and that the user's data has not been compromised.
The hackers claim to have taken part of the data from the APR system after, they say, the agency ignored them. In the announcements, they state that they have sensitive information - from names and surnames, home addresses and dates of birth, to passwords, copies of ID cards and passports, as well as financial reports, credit ratings and data on bank transactions.
Among the compromised data are shareholder records, real estate ownership, professional licenses, injunctions, liens and leases.
The hacker group threatened to publish the complete database if the authorities from the APR did not contact them within 24 hours.

Photo: Freepik/DC-StudioHackers
APR: The information system is completely secure and functional
"After a detailed check, it was determined that an external user account was compromised through which one of the APR application systems was accessed. This detected incident did not in any way threaten the security and integrity of the Agency's information system, which functions smoothly all the time," the Business Registers Agency announced regarding the information that the APR system was hacked.
"The Agency for Business Registers (APR) informs the public that the databases of the APR have not been compromised, that the entire information system is completely safe, as well as the personal and other data of service users submitted in the procedures conducted through the Agency's application systems," announced the APR.
APR reminds the public that all data and documents, which are prescribed as the subject of registration in the registers and records kept by the Agency for Economic Registers, are publicly published and available through the Agency's website. Also, in the process of ensuring public availability of data, "APR acts fully in accordance with the relevant regulations governing this area".
"We especially point out that, in accordance with the Law on the Registration Procedure at the Agency for Business Registers, the registration procedure is based, among other things, on the principle of publicity and availability, according to which registered data and documents are public and available to all persons, through the APR website and direct inspection of the register, which is a unique, central, electronic database of documents prescribed as the subject of registration, as well as the documents on the basis of which the registration was carried out," the statement reads.
In addition to ensuring transparency, APR, as stated - "professionally and responsibly, by applying the highest national and international standards of information security, takes care of the protection of the electronic databases that it maintains on the basis of the law. In support of the above, it is also said that APR has a certificate of the achieved ISO/IEC 27001:2022 standard, which confirms that an information security management system (ISMS) has been established and maintained at a level that complies with the requirements of this standard".
"In this sense, a defined incident response plan was implemented, which includes the steps of detection, classification, coordination and communication with expert teams for data security, including the application of prescribed procedures, and APR, in the case of an attempted hacker attack, without delay, took all prescribed technical and legal measures within its jurisdiction. After a detailed check, it was determined that an external user account through which one of APR's application systems was accessed was compromised. This detected incident did not in any way threaten the security and integrity of the Agency's information system, which functions smoothly all the time", stated APR.
APR, as it was added, continues to continuously monitor the state of the information system and applies all security protection mechanisms to ensure the smooth provision of services to citizens and the economy.
A little earlier, the cyber security company Vecert announced that the data of the Agency for Commercial Registers had been leaked.
"Our platform has identified an active extortion operation carried out by the attacker Zeus_kos against APR Serbia. Due to the lack of response from the institution - the attacker published a sample of data and set an ultimatum of 24 hours", it was announced on the company's website.
The announcement states that the attacker on APR is connected to this week's hacker attack on Telekom Srbija.
Real journalism costs money, and we will not be bought by tycoons and corporations. Support us with a one-time or monthly donation. The time for it is now!