On December 27, 2023, the Serbian state-owned energy giant Electric Power Industry of Serbia (EPS) appeared on the leak site of the qilin ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the company that produces, supplies, and trades most of the electricity used across Serbia. The leak-site entry does not specify the number of records affected or list exact data types beyond “internal files.”
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Eps.Rs
Get alerted the next time Eps.Rs files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Eps.Rs’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The qilin leak site, mirrored on ransomware.live, publicly listed EPS.RS and stated that data had already been stolen from the utility. The disclosure indicates the files were taken as part of a double-extortion operation in which the attackers both encrypt systems and threaten to publish sensitive material unless a ransom is paid. No ransom amount or negotiation status is shown on the listing. The notification does not quantify how many employee, customer, or partner records may have been included in the exfiltrated material.
Why This Matters for You and Your Family
When a national electricity provider is breached, the consequences reach far beyond corporate networks. EPS holds personal and financial details on employees, contractors, and potentially millions of Serbian households that pay their power bills. If those records surface, identity thieves can combine them with other leaks to build complete profiles. Even if you do not live in Serbia, any shared vendors, international partners, or family members connected to the company could expose your information through supply-chain overlap. The breach therefore creates a concrete risk that your address, payment history, or government ID numbers could be traded on criminal forums.
Doxxing and Identity-Chain Implications
Internal files from an energy utility often contain spreadsheets that link employee names, corporate email addresses, phone numbers, and sometimes home addresses. Attackers routinely chain this information with credential leaks from other breaches. A single exposed work email can unlock personal accounts that reuse the same password, leading to full account takeover. Once attackers control an email or phone number, they can reset banking credentials, request new government documents, or impersonate you to family members. Children’s gaming accounts are especially vulnerable in these chains because kids often use a parent’s email or phone for recovery, turning one corporate breach into household-wide exposure.