How to Report Cybercrime and Online Fraud in Serbia (2026)

Scammed or hacked in Serbia? Who to call (112, police 192), how to report to the High-Tech Crime service and the National CERT, and how to try to get your money back.
Serbia is a sovereign country and is not a member of the European Union, so EU rules like GDPR and EU payment-protection regulations do not automatically apply here. If you are scammed or hacked in Serbia, you report to the Serbian police's High-Tech Crime service, and a separate national CERT, central bank and data protection commissioner each cover a different part of the problem. This guide shows you exactly who to contact, how to preserve evidence, and how to try to get your money back. Act fast: the sooner you tell your bank, the better your odds.
Primary sources: MUP: Ministry of Interior of Serbia · National CERT of Serbia (RATEL) · National Bank of Serbia · Commissioner for Information of Public Importance and Personal Data Protection
On this page
First: stop the loss
- Contact your bank or card issuer immediately. If you sent money or shared card details, call the number on your card or statement, report the fraud, and ask them to stop or recall the payment and freeze the account. For card payments, ask about a chargeback. Our chargeback guide explains how.
- Stop all contact with the scammer. Never send more money to "release" or "verify" funds, and never install remote-access software a caller asks for. That is the scam. Block the number, email and account.
- Secure your accounts by changing passwords, signing out other devices and turning on two-step verification. If you clicked a link, see what to do after clicking a phishing link.
- Keep evidence: emails, texts, payment references, names, numbers and account details.
Who to report to
- Emergency or a crime in progress: call 112.
- Fraud and cybercrime: report to the Service for Combating High-Tech Crime (SBPOK), part of the Ministry of Interior (MUP), at any police station or by email to [email protected]. Ask for a reference number for any bank claim.
- A cyber attack, hacking or phishing attempt: report to the National CERT, operated by RATEL, Serbia's telecommunications regulator, through the form at cert.rs or by email to [email protected].
- Bank-impersonation scams and phishing warnings: the National Bank of Serbia (NBS) publishes public warnings about SMS and phishing scams; report suspicious messages to your bank too.
- A personal-data breach or privacy concern: the Poverenik, at [email protected].
Reporting does not by itself return your money, but it creates an official record and feeds local intelligence. Report even if you did not lose money, because the information still helps stop the next victim.
Getting your money back
Serbia uses the Serbian dinar (RSD). As Serbia is not an EU member state, the EU's mandatory payment-protection rules do not apply here, so your options rest on your bank's own policies and Serbian consumer-protection law. Speed is everything.
| How you paid | What to do |
|---|---|
| Bank transfer | Call your bank within minutes to try to stop or recall the payment. Ask whether it will reimburse you, and claim. |
| Debit or credit card | Ask your card issuer for a chargeback and dispute the transaction in writing. Card payments carry the strongest protection. |
| Crypto, cash app or gift cards | Rarely recoverable. Report to the platform and the police at once, and beware "recovery agents" who contact you, that is usually a second scam. |
Do not assume an automatic refund on any payment method. Report to SBPOK, claim from your bank, and escalate a refused claim through its complaints process.
Scams that hit Serbia
SBPOK and the National CERT have warned repeatedly about:
- Fake government-agency phishing emails, impersonating MUP or the public prosecutor's office to pressure recipients into clicking a link or handing over personal details.
- SMS "free prize" phishing, messages claiming you have won a prize or package and asking you to enter card details to "confirm delivery" or pay a small fee.
- Bank-impersonation phishing, mimicking real bank alerts to steal online-banking credentials. See how this messaging is built in our explainer on how phishing works and how to stop it.
The law and your data
Computer offences in Serbia, including unauthorised access to a protected computer, fall under Article 302 of the Krivični zakonik (Criminal Code), punishable by a fine or up to six months' imprisonment, rising for aggravating circumstances. Because Serbia is not an EU member state, GDPR does not apply directly here. Your data is instead protected under Serbia's own Law on Personal Data Protection, enforced by the Poverenik, and breaches must be notified without undue delay rather than under the EU's fixed 72-hour rule.
FAQ
Does GDPR protect me if I am scammed in Serbia?
Not directly. Serbia is not an EU member state, so GDPR does not automatically apply. Serbia's own Law on Personal Data Protection covers your data instead, enforced by the Poverenik.
My email or social media was hacked. Who do I tell?
Secure the account first: change the password, sign out other devices and turn on two-step verification. Report the incident to the National CERT, and to SBPOK if money, identity or business communications were affected.
I only got a suspicious message and lost nothing. Should I still report?
Yes. Reporting phishing emails and scam texts to the National CERT or your bank helps authorities track offenders and warn others, even without a financial loss.
Sources: MUP: Ministry of Interior of Serbia · National CERT of Serbia (RATEL) · National Bank of Serbia · Poverenik
If you have been targeted, you are not alone. See our country-by-country cybercrime help hub for step-by-step reporting and recovery guides.