Ransomware victim disclosure
← All victimsMinistarstvo poljoprivrede, šumarstva i ribarstva
Claimed by Barracuda · listed 6 hours ago
Status timeline
- ListedOct 9, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileMinistarstvo poljoprivrede, šumarstva i ribarstva (Ministry of Agriculture, Forestry and Fisheries) is the Croatian government agency responsible for agricultural policy, forestry management, and fisheries oversight.
- Industry
- Government – Agriculture
Attack summary
Severity: critical — Confirmed exfiltration of personally identifiable information (PII) at large scale from a government ministry, including photos and phone numbers of Croatian residents, combined with sensitive agricultural and contractual records. Government data compromise at this scale constitutes critical severity.Barracuda claims to have exfiltrated complete database dumps and documents from the Ministry's main file server, including agricultural registration records and personal data of Croatian residents (names, phone numbers, photos) and details of agricultural activities, along with Ministry contracts and confidential documents.
Data the group says was taken
AI dossier — extracted from the leak post- agricultural registration records
- personal data (names, surnames, phone numbers, photos)
- agricultural activity details
- Ministry contracts
- confidential government documents
What the group claims
We have complete database dumps from the Ministry of Agriculture and all documents from its main file server. They contain information about residents of Croatia, including agricultural registration records and personal data such as phone numbers, surnames, first names, and photos, as well as details about each resident’s agricultural activities. We also have Ministry of Agriculture contracts and other confidential documents. Recently, the authorities claimed that no data breach had occurred. It’s unfortunate that this was a lie. https://mps.hr | Status: selling | $50,000
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

