Announcements about the construction of new data centers and supercomputers in Serbia come at a time when the country is trying to accelerate digital transformation and catch up with more developed markets. Greater capacities, processing data within the country and the development of artificial intelligence are becoming priorities for countries in the region. However, the public still lacks insight into how secure modern data management systems actually are.
Controversy is most often about the impact of the construction of data centers on the environment and whether the energy grid can withstand the additional load. The discussion about security is much less frequent, although experiences from around the world show that the biggest problems do not occur where the most investments are made, but where the risks are underestimated.
Data leakage as a global trend
The year behind us was a record for the number of cyber incidents. More than 3.300 major breaches have been registered in the United States alone, with hundreds of millions of user data compromised. Telecommunications and state bases have become one of the main targets of cyber attacks aimed at obtaining personal information about citizens.
In the Netherlands, operator Odido was compromised at the beginning of this year; the attackers obtained the data of up to eight million users, i.e. over 21 million records of standard user data: name and surname, address, telephone, date of birth.
In South Korea, a similar attack on SK Telecom threatened practically half of the country. The data of around 27 million users became the target, a large part of which enabled the attackers to download SIM cards and communications that take place through them.
By far the most serious was the case of the American telco operator AT&T. Between 110 and 176 million user data were affected in the first wave in 2024, with additional databases appearing throughout 2025. According to available information, the company tried to mitigate the problem by paying hackers to remove some of the data.
What links these incidents is not the spectacular "system crash" but the manner in which it occurs. In most cases, it is not the central infrastructure that is breached, but secondary systems: internal applications, service bases, customer support. Exactly where security is often not a priority, and data is most specific.
That is why the potential consequences for users are very specific. When a name, address, identification number and contact are leaked, it is no longer a technical problem, but a direct risk of identity theft. It is especially dangerous when the subject of the leak is financial data, payment card numbers, bank account numbers or passwords for online payments, as was the case with the partial compromise of the financial data of Vodafone 2025 users in the UK. Such cases, as far as is known, have not happened in Serbia so far.
The Serbian army, APR and telecommunications are under attack
In the space of just a few days, the public received information about three serious cases of data theft: two in the civilian sector, and one in the military sector.
On March 17, Telekom Srbija announced that there was unauthorized access to part of the data from the m:SAT TV user database, stating that it was a limited volume of information from the internal application, i.e. about 160.000 records. The SHARE Foundation published an analysis that showed that there were 330.000 unique entries. The attack on Telekom was similar to the attacks on other global telco operators - it was not the central infrastructure that was attacked, but one of the auxiliary services.
Almost simultaneously, information appeared about the compromise of the systems of the Ministry of Defense of the Republic of Serbia, the Military Academy and the Military Academy. According to Radio Free Europe, the email accounts associated with the Fancy Bear group were compromised.
The attackers successfully bypassed two-factor authentication, established automatic forwarding and accessed communications with hundreds of contacts, including European military structures. There are indications that the access took months.
Apart from Telekom and the military, the Agency for Economic Registers was also attacked by hackers. The same hacker group that took responsibility for the compromise of the Telekom Srbije database claims to have sensitive data from the APR database: names, JMBG, addresses, copies of ID cards and passports of company owners, as well as bank account information.
APR confirmed the attack on the external user system, but, as they say, without compromising the central database. In any case, these three March attacks caused a further decline in trust in the state's digital systems and the state's ability to protect its citizens' data in the Internet space.
A special issue is that Serbian institutions do not have clearly developed manuals on how to communicate with the public in such situations, so the public often turns to the analyzes of non-governmental organizations instead of official information.
Can citizens feel safe?
Cyber attacks are not the exception, but the rule. In functioning systems, incidents are quickly recognized, communicated transparently, and their consequences are limited by a responsible reaction.
In the case of domestic incidents, the situation is different: information comes late, assessments differ, and responsibility remains unclear. In such an environment, citizens remain exposed.
Their data is in databases that they do not see and do not control, and they learn about their security only when the problem already becomes public. That is why all new investments in data centers remain accompanied by the same dilemma: not how much data we can process, but how much data we are able to really protect.
Real journalism costs money, and we will not be bought by tycoons and corporations. Support us with a one-time or monthly donation. The time for it is now!