Tuesday, 22 September 2026 The Plausible Post Independent news from around the world, around the clock.

Forensic Report Uncovers Covert Data Export in Balkan Telco AI — Probe Widens Across Borders

An independent forensic analysis released Monday says a content‑filtering AI used by a major regional carrier secretly exported millions of subscribers’ location and metadata to a private data broker. Regulators in three Balkan states and the EU have opened emergency inquiries and the carrier’s shares plunged on the news.

By Sára Simon ·

Outside Adriatik Telecom headquarters in Belgrade on Monday, where employees, reporters and protesters gathered after a forensic report alleged covert data exports.
Outside Adriatik Telecom headquarters in Belgrade on Monday, where employees, reporters and protesters gathered after a forensic report alleged covert data exports.

A months‑old dispute over repeated service outages at Adriatik Telecom escalated into a full‑scale scandal on Monday after Transparence Labs, a Ljubljana‑based digital forensics firm, published a 78‑page analysis saying the carrier’s AI content‑moderation stack contained a covert export module that transmitted location pings and call metadata for an estimated 8.3 million SIMs to a private broker. The broker, identified in the report as Greybridge Analytics (a Sofia‑registered data firm), allegedly received data batches between March and August 2026 in exchange for fee payments totalling approximately €1.9 million (about $2.0 million), the report said.

The revelations follow weeks of local reporting and consumer complaints first prompted by repeated slowdowns on Adriatik’s 4G and 5G networks across Serbia, Croatia and Bosnia from May onward. Transparence Labs says the export mechanism was embedded in a third‑party module supplied by contractor SentryEdge, marketed as an AI‑driven filter called BalkanGuard that promised to prioritise emergency traffic and block spam. The forensics team traced the function to a software commit flagged internally as an "exception handler" that, in practice, rerouted metadata to an external API endpoint.

Adriatik Telecom called the findings "deeply troubling" and said it had suspended all contracts with SentryEdge and cut the suspect API connection overnight. The carrier’s shares fell 27% on the Belgrade and Zagreb trade platforms before trading was suspended; analysts estimate the reputation shock could wipe up to €1.6 billion from the company’s market value. Prosecutors in Belgrade and Zagreb announced joint inquiries and said they had opened a criminal case for unlawful processing of personal data.

They built a surveillance bypass into a product meant to protect users.

Juliette M. Couturier, cybersecurity researcher

Privacy campaigners and regulators reacted sharply. Karl Owen, director of Balkan Privacy Watch, called the report "a worst‑case scenario for regional digital trust," and urged immediate cross‑border cooperation under EU data‑protection rules. "This is not a bug — it's a business model leak. When network providers outsource AI moderating traffic, oversight has to follow the money," he said. The Croatian and Serbian data‑protection authorities confirmed they had issued emergency inspection orders and asked the European Data Protection Board for coordination.

SentryEdge, the Montenegro‑registered developer of BalkanGuard, issued a terse statement denying it knowingly exported subscriber metadata and said it would fully cooperate with investigators. Transparence Labs disagrees: its report includes logs and signed certificates it says link the exports to Greybridge Analytics’ ingestion servers. Antun Marković, a small‑hotel owner in Split whose booking platform reported spikes of unauthorised verification requests during the same period, said customers were already asking for refunds. "We relied on Adriatik for reliable service; now guests ask if their movements were sold," he said.

The fallout reached beyond telecoms. Regional venture funds told The Plausible Post they were pausing further investments in networked AI tools, and several start‑ups providing emergency‑services routing said public trust was collapsing. Hanna Löfgren, senior policy adviser at a Brussels digital‑rights think‑tank, said the case strengthened arguments for an EU‑level mandatory AI incident registry that would force companies to disclose data breaches and automated‑decision failures within hours. "This is exactly the type of cross‑border, algorithmic failure regulators designed emergency reporting for," she said.

Parliamentary oversight committees in Sarajevo, Zagreb and Belgrade have summoned Adriatik executives and the digital ministers for hearings scheduled this week; prosecutors said forensic teams would begin a six‑week audit of servers and code repositories. Rodica Radu, a member of the Croatian parliament’s digital affairs committee, described the episode as a wake‑up call: "If proven, this is an institutional failure — we must rewritte procurement and auditing rules for any AI that touches the network." For millions of users in the Balkans, the episode leaves open the question of who should be trusted with the flows of data that now underpin everyday life.

More news