Bigcenters.rs appeared on the Werewolves ransomware leak site on May 18, 2023, claiming that the Serbian shopping-mall operator suffered a ransomware attack in which internal files were exfiltrated. The listing does not disclose the number of people affected or the exact data stolen, only that the company’s internal documents are now held by the attackers.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch bigcenters.rs
Get alerted the next time bigcenters.rs files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about bigcenters.rs’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The Werewolves leak page states that Bigcenters.rs was hit by a ransomware attack and that internal files were successfully exfiltrated. No sample data is shown, no ransom amount is published, and the victim count remains unknown. The disclosure simply lists the company alongside the note that its data is now in the group’s possession. Public reporting on Werewolves indicates the actors follow a double-extortion model: they first encrypt systems and then threaten to publish stolen files if payment is not made.
Why This Matters for You and Your Family
When a retailer or property operator loses control of internal files, the information often includes customer records, supplier contracts, employee payroll data, and contact details. Even though the exact contents are not public, any exposure of names, addresses, phone numbers, or email addresses tied to a shopping center can be used for phishing, identity theft, or targeted scams against shoppers and staff. If you or your family have shopped at or worked with any of the more than 1,000 stores inside Bigcenters facilities, your information could be among the records now held by criminals. The breach therefore carries direct consequences for ordinary people rather than abstract corporate risk.
Doxxing and Identity-Chain Risks
Stolen internal files frequently contain spreadsheets that link personal details to usernames, loyalty-program IDs, or even children’s activity registrations. Attackers can combine this data with information from other breaches to build complete identity chains. A single leaked email or phone number from the Bigcenters.rs incident can unlock additional accounts, including gaming profiles that children use. Once those gaming accounts are taken over, attackers gain photos, chat logs, and location data that further expand the doxxing chain. The result is a cascading exposure that can affect every member of a household long after the original breach is forgotten.