Scams in BiH: an early warning
Over the past several weeks, Bosnia and Herzegovina has seen a convergence of public warnings that, taken together, describe a threat environment that has moved beyond opportunistic fraud. The Federal Administration of Police (FUP) issued an emergency alert documenting a significant rise in organized online attacks - AI-generated voice calls, spoofed emails, business email compromise operations, ransomware, and SMS phishing campaigns impersonating banks, government agencies, and courier services. Separately, IDDEEA, the state agency responsible for identity documents and data exchange, publicly clarified that it does not send payment links to citizens, after its name, visual identity, and institutional branding were used without authorization in a sustained smishing campaign. SIPA traced the incoming messages to international numbers with Filipino country codes. A second wave followed after the first warning, with adjusted content and new domains.
BH Telecom confirmed that a significant portion of the attacks were distributed through RCS and iMessage channels, not traditional SMS, which current telecom infrastructure in BiH is not equipped to filter.
The financial and personal harm to citizens is real and documented. But the full picture extends beyond what these warnings individually describe.
What phishing at scale actually requires
Organized phishing and smishing campaigns do not emerge from nothing. To convincingly impersonate a state agency, replicating its name, tone, and the administrative contexts that prompt citizens to act without hesitation, attackers require prior familiarity with how that institution communicates and what citizens expect from it. To sustain a campaign across two documented waves, adapting domains and content each time a warning is issued, requires coordination and resources that go beyond casual criminal opportunism.
The attackers in this case also held a substantial database of active Bosnian phone numbers. Any response to a message, even a reply of "0" or "1", confirms that a number is active, making it more valuable for future campaigns or for sale to other actors.
In cybersecurity practice, large-scale credential harvesting campaigns against a defined national population frequently serve a secondary purpose. Credentials and personal data collected through phishing are aggregated, tested against other systems, and traded on closed markets. The smishing attack that a citizen receives on their phone and the intrusion that follows into an organizational system may be separated by considerable time and appear entirely unrelated.
The visible attack and the consequential attack are often not the same event.
Why the conditions in BiH matter
Bosnia and Herzegovina is currently the only country in Europe without an operational national CERT, a Computer Emergency Response Team with the authority and capacity to coordinate responses to cyber incidents at a national level. This gap exists not because of a lack of awareness but because of unresolved administrative and political obstacles that have persisted for years.
Beyond the absence of a CERT, digital security standards across institutions remain inconsistent. The domain architecture of public administration is fragmented, with different agencies operating under different domains, making it genuinely difficult for citizens to distinguish a legitimate government website from a fraudulent one with a near-identical address. Telecom operators currently lack effective mechanisms for filtering the specific channels through which a significant portion of recent attacks have been distributed.
Organizations across the country, in both the public and private sector, frequently operate without continuous security monitoring, without tested incident response procedures, and without clear visibility into whether any part of their environment has already been accessed by an unauthorized party. In this context, a well-resourced attacker does not need to force entry. They can work with what is already accessible.
The broader threat picture
Bosnia and Herzegovina may not appear, at first glance, to be a high-value target in the global threat landscape. But the country hosts critical infrastructure, including energy systems, financial institutions, telecommunications networks, and public administration that is increasingly reliant on digital services, that is operationally significant both domestically and within the wider regional context.
State-sponsored actors, organized criminal groups, and hybrid threat actors all operate with a logic of reconnaissance before action. Campaigns that map a population's behavioral responses, harvest credentials at scale, and identify organizations with low or no detection capability are not always ends in themselves. They are frequently the preparation phase for operations that follow later and cause considerably more damage, to organizations, to infrastructure, and to the continuity of services that people and institutions depend on.
The current wave of attacks generates intelligence for whoever is conducting it: which credentials are valid, which organizations do not detect or respond to intrusions, and where the paths that lead deeper into sensitive environments might be found.
What this moment calls for
Four separate institutions, FUP, IDDEEA, SIPA, and BH Telecom, issued public warnings within a matter of weeks, each describing a different dimension of the same underlying problem. That level of convergence reflects a threat environment that warrants a proportionate response.
For organizations that hold sensitive data, operate infrastructure, or provide services that matter to the functioning of this country, the relevant question is not whether they are being probed in some form. The relevant question is whether they have the visibility to know, and the capability to respond, when that probing moves from the perimeter toward something more serious.
Cyber resilience is not optional.
[ Direct Line ]
Talk to Our Security Operations Team
If this briefing is relevant to your environment, our team can assess your exposure and show you how Outis defends critical infrastructure.




