Claims of a Croatian clinic data leak are unverified. What that means for you
If you have an account with this organisation, here’s what is being claimed, and what it would mean for you.
A group posted claims that it leaked records from a Croatian clinic for the blind. No clinic or official body has confirmed any breach. If you are worried this involves you, here is what is actually known and what is useful to do.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
A group calling itself INF GRUPA posted on underground forums that it held about 9,400 patient records from an unnamed Croatian clinic for the blind. A tracker listing dated 24 August 2026, and later Croatian news reports, repeated that post — including claimed details such as names, phone numbers, addresses, national identification numbers, diagnoses, medications, clinical notes and medical documents.
Watch this company
Get alerted the next time this company files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about this company’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr.
None of that has been confirmed. No clinic has announced a breach. Croatia’s privacy regulator has not verified a leak. There is no official filing. Every public report traces back to the group’s own message, not to an independent review of any files.
Headlines describe a leak. The evidence is a claim.
If you saw this story and felt a jolt — especially if you or someone close to you uses a specialist eye clinic — that reaction is understandable. Coverage has led with a round number, a medical setting and a list of intimate data types. That is how the posts were written, and how they were copied from site to site.
What most of that coverage does not sit with is simpler: nobody outside the people who wrote the post has shown that the records are real, that they came from a Croatian clinic, or that 9,400 patients are involved. Some “breach” lists republish underground claims without checking the files. Repeating a number does not verify it.
So the honest read for you is not “your file is out,” and it is not “you are in the clear.” It is that this specific incident has not been established. Treating an unverified forum post as a claimed medical breach helps the people who posted it more than it helps you.
What to actually expect
- You should not expect a letter or email from a clinic or from Croatian authorities about this particular claim, because no organisation has confirmed it.
- You may get messages, calls or ads that mention a “medical leak” or “clinic records” and urge you to click, pay or hand over more information. Those are typical tag-alongs to news like this. They are not proof you were involved.
- More articles will likely recycle the same 9,400 figure and the same forum posts. That repetition is not new confirmation.
- There is no public check that can tell you whether your name was in the alleged files. A clean result would not mean you were absent; a hit on a random website would not mean the files are genuine.
What you can and cannot fix
If these files later turn out to be real, they cannot be pulled back. Medical notes, diagnoses and national identification numbers do not become private again once they have been copied. Nobody can honestly promise to remove that kind of material from the internet.
Right now, though, it has not been shown that any of that left a clinic. What you can still do is limit how much a future leak — this claim, or any other — can be stitched onto the rest of your life.
- Ignore and delete unsolicited contacts that cite this story. Do not send copies of your ID, health records or payment details to anyone who reaches out first.
- If you are a patient at a particular clinic and you want a direct answer, ask that clinic whether it has issued any breach notice. That is the only place an official yes or no could come from. Silence in the news is not a notice, and a forum post is not a notice either.
- Cut back what people-search and directory sites publish about you — old addresses, relatives, phone numbers, employers. A bare clinic record is harder to use against you if it cannot be joined to a public profile that already maps your household. Those directory listings, unlike stolen medical files, can often actually be taken down.
- Watch for real notices from a clinic, insurer or government body you already know. Those will not arrive as a surprise link in a chat message.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Flock Safety CEO address posts: what is confirmed and whether it affects you
In late August 2026, posts on X claimed to share Flock Safety CEO Garrett Langley’s home address aft…
Eastlink data breach August 2026: what the customer emails actually mean
Eastlink emailed some current and former customers on 28 August 2026 about accounts that may have be…
Kindol vintage shop leak: 136,464 customers and 109,311 home addresses taken
Treasure Factory confirmed on 28 August 2026 that a phishing email let an attacker into a staff acco…