top of page

Citizens' data theft: RFZO and the Ministry of Health owe the public answers

  • Writer: GP Solidarnost
    GP Solidarnost
  • 6 hours ago
  • 5 min read

The Citizen Movement “Solidarity” demands that the Republic Health Insurance Fund (RFZO) and the Ministry of Health immediately and fully inform the public about the possible theft of personal data from the Fund's information systems, and that an independent investigation be launched.

What happened

The “Bezbedan Balkan” portal documented on 17 August 2026 a post by an unknown actor claiming to have accessed RFZO databases. As alleged evidence, the actor presented database structures and samples of data — including citizens' national identification numbers (JMBG) and insurance numbers (LBO), as well as information about selected doctors, their specialisations and healthcare institutions. One sample allegedly contains 342,732 records of selected doctors.

We emphasize what has not yet been confirmed: that the data of all insured persons was taken, or that medical findings, diagnoses and treatments were compromised. But what has already been published is sufficient reason for an immediate response. If it is confirmed that JMBG, LBO and other identifying data were indeed extracted from RFZO systems, this would constitute one of the most serious incidents in the history of Serbia's electronic government. Such data can be misused for identity theft, fraud and impersonation.

Outdated systems and previous warnings

Publicly available analyses indicate that individual RFZO servers displayed identifiers of very old software versions — CentOS 7 and PHP 5.4.16. CentOS 7 reached the end of regular security support in June 2024, while PHP 5.4 has been unsupported for years. The presence of these version identifiers alone does not prove how any potential attack was carried out, since individual security fixes can be implemented without changing the displayed software version. But they require a clear answer: when was the infrastructure last thoroughly updated, and who was responsible for maintaining it?

Particularly concerning is the fact that potential security problems on RFZO websites have allegedly been documented for years — a vulnerability recorded as early as 2021, traces of possible command execution on a server from 2023, and compromised parts of the website during February 2025. These findings by themselves do not prove a connection with the current case, but they raise an important question: was the management aware of previous warnings, and what action did it take?

Why the response so far is not enough

RFZO issued a statement on 18 August 2026 saying that it had launched an investigation of its systems, but that at that point it could not confirm whether an incident had occurred or determine the extent of the potentially affected data. The main website and public procurement page were temporarily unavailable.

Temporarily taking systems offline may be a justified protective measure, but a brief statement does not answer the key questions:

  • When did RFZO first learn about the possible incident?

  • Which systems were compromised or taken offline?

  • Has it been established that data was actually extracted?

  • Were the Commissioner for Information of Public Importance and Personal Data Protection, the National CERT, and the competent prosecutor's office notified?

Under the Law on Personal Data Protection, a confirmed personal data breach must generally be reported to the Commissioner no later than 72 hours after becoming aware of it. If a breach is likely to result in a high risk to the rights and freedoms of individuals, the controller is also required to notify the affected individuals without undue delay.

How responsible states respond

This is not an isolated case, nor is it solely a Serbian problem. But the way other countries have responded to similar incidents shows what should also be done here — quickly, publicly and with clear accountability.

Singapore (SingHealth, 2018). In the largest data breach in the country's history, data belonging to 1.5 million patients was stolen, including that of the then prime minister. The government immediately established an independent committee of inquiry and published a detailed public report with specific recommendations. The data protection regulator imposed what were, at the time, the largest penalties, while both the technology partner and the healthcare institution itself were held accountable — with a clear position that the owner of the database remains responsible even when work is outsourced to another company. Several members of management were sanctioned, and some were removed from their positions.

Finland (Vastaamo, 2018–2020). Extremely sensitive data belonging to around 33,000 patients was stolen from a psychotherapy centre. The key lesson concerns delays in notification: concealing the incident deepened the damage, while the former director was ultimately convicted for failing to protect clients' data. The case deeply shook Finnish society, led to the institution's bankruptcy, and the state later considered making it easier for victims to change their national identification numbers. The attacker was eventually sentenced to several years in prison.

Ireland (HSE, 2021). The entire state healthcare system was affected by an attack, and data belonging to around 100,000 people was stolen. An independent report showed that attackers had remained inside the system undetected for weeks, that outdated software was running on thousands of computers, and that multiple warnings had not been taken seriously — raising almost the same question that is now being asked of RFZO. The state refused to pay the ransom, publicly released a detailed report on the failures, notified affected citizens in accordance with the law, and later offered them compensation.

The common thread in all these cases is clear: an independent investigation, a public report, prompt notification of regulators and citizens, and identification of those responsible. That is the standard we expect here as well.

What we demand

  1. Full and truthful information for the public about what happened, when the Fund became aware of it, and what data was compromised.

  2. An independent security investigation and a public report on its findings.

  3. A clear answer as to who was responsible for maintaining and securing the systems, who assessed the risks, and how much was invested in data protection.

  4. Confirmation that the Commissioner, CERT and the prosecution authorities have been notified, and that citizens have been informed in accordance with the law.

  5. Establishment of responsibility for everyone who failed to act promptly on previous warnings.

Data protection is not a public relations issue

The protection of personal data is not a technical problem to be dealt with behind closed doors, nor is it a matter of managing public perception. It is a legal obligation of the state and a matter of personal security for every citizen. When state institutions become closed systems without professional and public oversight, the consequence is not merely political — it is a threat to the privacy and security of millions of people whose data the state is obliged to protect.

Citizens of Serbia have the right to know who protects their data, how it is protected, and who is responsible when that protection fails.

Comments


bottom of page