Informatika A.D. Listed by worldleaks Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Informatika A.D. was listed by the Worldleaks ransomware group on May 23, 2025, after internal files were exfiltrated in an attack. An undisclosed number of people may be affected; individuals should review any notifications from the organisation and follow its guidance on protective steps.
On 23 May 2025, the ransomware group known as worldleaks listed Informatika A.D. on its leak site, claiming responsibility for a ransomware attack in which internal files were exfiltrated. The number of people whose information may be involved remains unknown, and public detail on the precise contents of those files is limited. For customers, partners, employees and the public-sector and financial organisations that rely on the company, the listing raises practical questions about whether personal or operational data has left the organisation’s control and what that could mean for privacy, fraud risk and service continuity.
Because Informatika A.D. supplies IT systems and services across sensitive sectors in Serbia and beyond, even an unverified claim of data theft carries weight. Individuals and organisations connected to the firm have a clear interest in understanding what is known, what remains unconfirmed, and what steps they can take while fuller information is awaited.
What happened
According to the public listing, worldleaks claims to have conducted a ransomware attack against Informatika A.D. and to have exfiltrated internal files. The listing was reported on 23 May 2025. No confirmed figure for the volume of data, the number of affected individuals, the exact date of intrusion, or the technical method of access has been released in the available record. The group’s claim that internal files were taken is the sole description of the exposed material; further specifics have not been disclosed. As with other ransomware listings, the appearance of a victim’s name on a leak site constitutes an assertion by the threat actor rather than independent verification that the attack succeeded or that the files will be published.
Who is worldleaks?
Worldleaks is a ransomware operation that follows the now-familiar double-extortion model: after gaining access to a network, operators encrypt systems and simultaneously copy data, then threaten to release the stolen material on a dedicated leak site if a ransom is not paid. The group maintains a public portal where it posts victim names, sample files and, in some cases, full archives. Like other actors in this space, worldleaks typically targets organisations whose data or operational disruption would create pressure to negotiate. Prior public activity has included listings of companies across multiple countries and sectors; the group’s communications emphasise the volume or sensitivity of the material it claims to hold. In the present case, the only statement attributable to worldleaks about Informatika A.D. is the listing itself and the assertion that internal files were exfiltrated. No additional claims specific to this victim appear in the available facts.
Informatika A.D. and its sector
Informatika A.D. is an information-technology and services company headquartered in Belgrade, Serbia. It provides system integration, IT consulting, application development, infrastructure solutions, outsourcing, cloud services and digital-transformation support. Its client base includes public administration, financial institutions, healthcare providers, telecommunications operators, energy and utilities companies, and other organisations both inside Serbia and internationally. Firms of this type routinely hold network credentials, configuration data, project documentation, contracts, and sometimes personal or regulated information belonging to their customers’ employees and end users. A successful intrusion into such a provider can therefore affect not only the company itself but also the wider ecosystem of organisations that depend on its systems and advice. The consequential nature of a breach here stems from that central role rather than from any confirmed scale of compromise.
The information in question
The available record states only that “internal files” were exfiltrated in a ransomware attack. No inventory of file types, no count of records, and no confirmation of personal data, financial data or credentials have been published. Organisations that deliver IT services typically store source code, system diagrams, customer contracts, employee records, authentication material and project archives. Whether any of those categories were among the files claimed by worldleaks remains unconfirmed. Readers should treat the precise contents as unknown until independent verification or an official statement from Informatika A.D. becomes available.
What's at stake
For individuals whose data may have been among the internal files, the principal risks are identity misuse, targeted phishing and, in some cases, financial fraud if contact details or identifiers were present. Because the company serves public-administration, healthcare and financial clients, any leakage of operational or personal data could also expose those clients’ own staff or service users to secondary harm. For Informatika A.D. itself, the stakes include potential regulatory scrutiny, contractual liability toward customers, reputational damage and the operational cost of recovery and notification. None of these outcomes is guaranteed by a leak-site listing alone; they depend on whether the claimed files are authentic, whether they contain sensitive material, and whether they are ultimately released. Until those points are clarified, the prudent assumption is that exposure cannot be ruled out.
What to do if you're exposed
Anyone who has done business with, worked for, or supplied personal information to Informatika A.D. should monitor account statements and credit reports for unusual activity, enable multi-factor authentication on important accounts, and treat unexpected emails or calls that reference the company with caution. If you receive notification from the firm itself, follow the instructions it provides. As a further check, you can run a free exposure scan of your email address against known breach data sets to see whether your information has already appeared in other publicly documented incidents. Official updates from Informatika A.D. or relevant Serbian authorities remain the most reliable source of confirmation about this specific event.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Lidera Network Listed by worldleaks Ransomware GroupDP Systems Listed by worldleaks Ransomware GroupACRO Automation Systems Listed by worldleaks Ransomware GroupIntegrated Silicon Solution Inc. Listed by worldleaks Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Informatika A.D. Listed by worldleaks Ransomware Group →
Publicly posted by worldleaks — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.