IRONVALD
27 000 000 cyber-attacks in Bosnia and Herzegovina only in January 2026

#CYBERATTACK #CYBER #HEALTHCARE #RANSOMWARE

27 000 000 cyber-attacks in Bosnia and Herzegovina only in January 2026

According to recent reporting, estimates indicate that Bosnia and Herzegovina has been struck by roughly 27 million cyber-attacks only in January 2026. While the number may seem alarming and somewhat hard to believe, it is important to understand what this number represents.

Most often, offensive cyber operations do not consist of a single attack, but of continuous, automated system access attempts. Each one of these access attempts could become a devastating cyber-attack if not stopped and have catastrophic consequences for the target, paving the way for deeper penetrating and more elaborate intrusions.

Due to the fact that Bosnia and Herzegovina has no existing Cyber Emergency Response Teams (CERTs), it is difficult to estimate the exact number and nature of these attacks, as well as inflicted damage and losses. It is worth noting, however, that the United Nations Development Programme (UNDP) is working towards establishing the nation’s first CERTs, however, cyber capacities in BiH are still at a low.

According to reports from the Cyber Security Excellence Centre (CSEC), Bosnia and Herzegovina mostly suffers Distributed Denial-of-Service (DDoS) attacks. These attacks seek to disrupt a server or a service by flooding it with internet traffic at a rate higher than it can receive, making it unavailable to legitimate users.

The second most prevalent type of attacks in BiH are ransomware attacks - a type of attack targeting systems containing large volumes of sensitive information. The attackers often steal this information, leaving the server either wiped or encrypted, demanding a ransom to restore data, while leveraging the data owner with threats of publishing this information on the internet. One such attack targeted the Integrated Health Information System (IZIS) of the Republic of Srpska (RS), one of BiH’s two entities, paralyzing the healthcare in RS for 17 days.

It is clear that with rapid advancement of technologies, such attacks become more frequent and more sophisticated. Without adequate protection, institutions risk more downtime in systems that cannot fail. It is a matter of responsible governance to maintain data sovereignty and everyday life continuity. It is time for decision-makers to take the step towards greater cyber-defense capacities.

[ Direct Line ]

Talk to Our Security Operations Team

If this briefing is relevant to your environment, our team can assess your exposure and show you how Outis defends critical infrastructure.

[ Book Now ][ Explore the Platform ]

[ Related Briefings ]

Why Critical Infrastructure in Bosnia and Herzegovina Isn't Mapped, and What That Actually Means 

Why Critical Infrastructure in Bosnia and Herzegovina Isn't Mapped, and What That Actually Means 

2026.08.26

Why incident response fails industrial networks

Why incident response fails industrial networks

2026.06.02

Scams in BiH: an early warning

Scams in BiH: an early warning

2026.05.21

[ Back to News ]