Bosnia and Herzegovina Mine Action Center Data Breach

Alleged

Ransomware claim involving Bosnia and Herzegovina Mine Action Center

Published: Sep 9, 2026 Emperador
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Bosnia and Herzegovina Mine Action Center
Industry
Government & Defense
Threat Actor
Emperador
Date of Incident
Sep 9, 2026

Executive Summary

The Bosnia and Herzegovina Mine Action Center (BHMAC), the national body responsible for coordinating humanitarian demining operations and mine risk education, was listed on the emperador ransomware group’s leak site on September 9, 2026. SOCRadar’s Dark Web Monitoring service identified this listing. BHMAC, a government and defense organization, operates within Bosnia and Herzegovina. The targeting of BHMAC aligns with emperador’s pattern of targeting public sector entities, which often hold sensitive information or are critical for national operations, making them attractive targets for ransomware attacks. Emperor ransomware has demonstrated a broad disregard for specific target industries, as evidenced by its victim list over the preceding 60 days. During this period, the group claimed 13 victims across Government & Defense, Manufacturing, and Energy & Utilities sectors, with victims located in Brazil, the United States, and India. Notable previous governmental targets include the Judicial Branch of the Province of Jujuy, Prefeitura Municipal de Arcos, City Government of Baguio, and BAYMER. The inclusion of BHMAC reinforces this pattern of targeting public sector organizations globally.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed a significant exposure related to the bhmac[.]org domain, with 17 classified records identified in the queried sample. Of these, thirteen records consisted of employee credentials on internal organizational systems, and an additional three were corporate credentials associated with third-party services. This indicates a substantial credential exposure within the organization. Further examination of the compromised infrastructure shows that the mail server, mail.bhmac[.]org, contained seven records, including multiple distinct corporate usernames. The organization’s primary domain, which hosts an NTLM/Forms authentication endpoint, accounted for five additional records. The exposure extended to a partner humanitarian organization’s identity portal and Serbia’s national e-ID system, both accessed using BHMAC organizational credentials. This pattern suggests a potential workstation compromise among employees who possess cross-organizational access. The detected credential exposures have timestamps ranging from February 2024 up to September 9, 2026, the same day the listing appeared on the ransomware leak site. Notably, credential records continued to be logged in August and September 2026, indicating no apparent rotation or mitigation efforts over a period of two and a half years. While this stealer-log data does not confirm that emperador specifically utilized these credentials for an intrusion, the combination of compromised mail infrastructure, an NTLM authentication endpoint, access to partner organizations, and credentials remaining current through the listing date presents a strong pre-intrusion foothold. Such footholds are commonly exploited by targeted ransomware campaigns against government institutions. Therefore, immediate credential rotation and an audit of mail server access are highly recommended, irrespective of whether a direct link to emperador’s activities is definitively established.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.