PSG BANATSKI DVOR D.O.O. NOVI SAD (SERBIA) Listed by ransomhub Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The PSG BANATSKI DVOR D.O.O. NOVI SAD (SERBIA) Listed by ransomhub Ransomware Group (reported May 28, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target organisations across Europe, using double-extortion tactics that combine system encryption with the theft of internal data. Listings on criminal leak sites have become a routine pressure tool, even when the full scale of any intrusion remains unconfirmed by the organisations involved. Against that backdrop, a Serbian company appeared on a ransomware group's site in late May 2024.
Public records show that PSG BANATSKI DVOR D.O.O. NOVI SAD (SERBIA) was listed by the ransomhub ransomware group on 28 May 2024. The group claims to have exfiltrated internal files totalling 80 GB. The number of people affected is unknown, and the data had not been published at the time of the listing. For employees, partners and anyone whose information may sit inside those systems, the claim itself raises practical questions about exposure and next steps.
Inside the incident
According to the available record, the incident was reported on 28 May 2024. The listing attributes the activity to ransomhub and states that internal files were exfiltrated in a ransomware attack. The claimed data volume is 80 GB. The listing also records 44 visits and notes that the material had not been published. No further technical details—such as the initial access method, the duration of the intrusion, or any confirmation from the company—have been disclosed in the public facts. The number of individuals whose data may be involved remains unknown. All statements about the breach therefore rest on the group's own claim rather than independent verification.
Inside ransomhub
Ransomhub is a ransomware-as-a-service operation that became more visible after the disruption of earlier groups such as ALPHV/BlackCat. Like many of its peers, it typically follows a double-extortion model: encrypting systems while also stealing data and threatening to release it if a ransom is not paid. Affiliates often handle the initial compromise and data theft, then use the group's infrastructure to post victim names on a dedicated leak site. The site serves both as a pressure mechanism and as a public claim of success. In this case the group claims that PSG BANATSKI DVOR D.O.O. NOVI SAD (SERBIA) is a victim and that 80 GB of internal files were taken; those assertions have not been independently confirmed in the available record. Ransomhub has listed organisations in multiple sectors and countries, but specifics of any negotiation or payment related to this particular listing are not part of the public facts.
About PSG BANATSKI DVOR D.O.O. NOVI SAD (SERBIA)
PSG BANATSKI DVOR D.O.O. NOVI SAD is a Serbian limited-liability company based in the Novi Sad area, with a name that references Banatski Dvor. Companies of this type commonly operate in industrial, energy-related or local commercial activities and therefore maintain internal business records, operational documents, employee information and correspondence with suppliers or customers. A ransomware claim against such an organisation is consequential because the data held by mid-sized industrial or commercial firms often includes both operational details and personal information of staff and partners. Even when the exact nature of the business is not elaborated in the breach record, the potential exposure of internal files can affect day-to-day operations, contractual relationships and the privacy of individuals connected to the company.
The information in question
The facts state only that internal files were exfiltrated and that the claimed volume is 80 GB. No more granular list of data types—such as employee records, financial documents, customer lists or technical drawings—has been disclosed. Organisations of this kind typically store personnel files, payroll data, contracts, emails, operational logs and other business documents. Because the precise contents remain unconfirmed, it is not possible to state with certainty which categories of information, if any, left the company's control. The listing itself simply asserts that internal files were taken; readers should treat that assertion as an unverified claim until further evidence appears.
The real-world impact
For individuals whose data may have been among the files, the practical risks include possible misuse of personal details for phishing, identity fraud or social-engineering attempts. Even when names and contact information alone are involved, they can be combined with other publicly available data to craft more convincing scams. For the organisation, the claim can disrupt operations, require forensic investigation and notification efforts, and create uncertainty among employees and business partners. Because the number of people affected is unknown and the data have not been published according to the listing, the immediate public harm is limited to the uncertainty itself; that uncertainty, however, can still generate legitimate concern and administrative cost. No confirmation of encryption, ransom demands or actual data release has been provided in the facts, so the full operational impact remains undisclosed.
Were you affected?
If you have a past or present connection to PSG BANATSKI DVOR D.O.O. NOVI SAD—as an employee, contractor, supplier or customer—treat the listing as a prompt to review your own exposure. Monitor bank and credit accounts for unusual activity, be cautious of unexpected emails or messages that reference the company, and consider changing passwords used on any shared or work-related systems. Keep records of any suspicious contact. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Official confirmation from the company or Serbian authorities would provide clearer guidance; until then, measured personal vigilance is the most practical response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
acquafertil.com.br Listed by ransomhub Ransomware Groupdiazfoodsolutions.es Listed by ransomhub Ransomware Groupmiedemaproduce.com Listed by ransomhub Ransomware Groupwestbornmarket.com Listed by ransomhub Ransomware GroupLatest breaches
Publicly posted by ransomhub — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.