Cybersecurity breach: Bosnian passports on the black market
The Bosnian-Herzegovinian passport is virtually impossible to forge. To this day, no legitimate forgeries of this passport were found. Passports issued by Bosnia and Herzegovina (BiH) meet the standards of the International Civil Aviation Organization (ICAO).
So how can it happen that an unsuspecting, innocent individual, travelling with his family, finds himself being stopped at the border and told that there is an Interpol warrant for his arrest, upon handing over his passport? The following question may answer the previous: how can it happen that a concerningly large amount of BiH passports have been found on the black market?
In 2022, Anton* was stopped and searched by the Border Police of the Republic of Serbia during a rafting trip, after his passport was checked and came back flagged with an Interpol warrant. As it happens, Anton has been a victim of identity theft by a notorious criminal clan member from Montenegro – Dimitrije*, who has managed to obtain an ID and several personal documents in the name of Anton. Dimitrije has leveraged Anton’s identity to such an extent that the Interpol has issued an arrest warrant for Anton as a murder suspect. As one may imagine, Anton described his experience crossing the border as a nightmare ever since. But this case has opened a bigger question: How was Dimitrije able to get his hands on the identity of Anton, a BiH citizen, who wields documents virtually impossible to forge?
In 2025, an ethical hacker from Bosnia and Herzegovina has conducted an investigation into the dark web. She has reported that she has encountered a large volume of BiH passports being sold, confirming that she has managed to verify the authenticity of some of them, further claiming that these were not simply edited images or poor forgeries, but legitimate, valid documents, belonging to unsuspecting citizens of BiH. She elaborated her suspicion towards potential vectors of attack through which such sensitive personal information may be obtained, listing hacked databases, insider threat, poor handling of documentation and documentation scans by hotels and tourist agencies.
It is worth noting that BiH has lacked authentic services offering cybersecurity and defense, as well as incident response for infrastructure and systems hosting such sensitive data so far. With the cyber defense industry being underdeveloped in BiH, institutions face limited options. Furthermore, despite having a strategy for the establishment of Cyber Emergency Response Teams - CERTs, BiH still lacks implementation in this area and is the only country in the region without a functional CERT. Therefore, the institutions have found themselves in a difficult position with few solutions available. A 2025 analysis by cloud security firm Kloudle ranked BiH as the most cyber-vulnerable country in Europe. With the landscape constantly changing and cyber threats being more sophisticated than ever before and rapidly evolving, BiH is more vulnerable than ever before.
The public paradox is clear: a document virtually impossible to forge, yet accessible enough to criminals that it has become one of the most traded travel documents on the dark web. The answer lies not in the document itself, but in the pipeline behind it. Personal data is handled by over 160 legal bodies in the process of issuing a single passport - municipal registries, police agencies, entity-level ministries, border services - before it ever reaches the hands of airlines, hotels, and travel agencies processing it again on the other end. Each handoff is a potential point of failure. It is not the passport that is vulnerable. It is everything around it.
The legal situation, however, is not as tragic. The law on protection of personal information of BiH has been amended to be GDPR-compliant in 2025, however it is yet to be enforced, as there have still not been any recorded legal actions against bodies experiencing personal data leaks.
Being a country that has introduced biometric passports to allow visa-free travel to the Schengen Area, BiH travel documents are now amongst the most valuable on the black market. It is imperative that the entire pipeline for handling sensitive personal information - both public institutions and private companies - be secured by advanced cyber defense services. With GDPR fines now reaching up to 70 000 BAM for the Directors/CEOs of enterprises and institutions experiencing leaks and up to 40 million BAM for the legal bodies that have experienced critical personal information leaks, the pressure is at a high.
Lawmakers, institutions, and companies should take steps to protect themselves and the systems they use for handling personal data with advanced cyber defense. With mounting pressure, legislative and in cyberspace, noting the recent detection of the PRC-linked UNC2814 “Gallium”, it has never been more important to stress - cyber resilience is not optional, it is obligatory.
*The real names of individuals are not disclosed in this article, the names Anton and Dimitrije used in their place do not refer to any individual but are used for simpler understanding of the article by readers.
[ Direct Line ]
Talk to Our Security Operations Team
If this briefing is relevant to your environment, our team can assess your exposure and show you how Outis defends critical infrastructure.




