Dear Sir or Madam,
At Hit d.d. Nova Gorica, we highly value your trust, which is why we want to keep you transparently informed about the developments regarding the cybersecurity incident involving our information systems, as well as the potential impact of the incident on your personal data.
According to findings to date, unauthorized access to certain data occurred as part of the cyber incident. As the investigation and analysis of the incident are still ongoing, we will duly inform you of any new significant findings.
What Happened
On August 25, 2026, we detected a cybersecurity incident that resulted in unauthorized access to the information systems of HIT d.d. Nova Gorica company.
What This Means for You
Based on findings to date, there is a possibility that certain personal data was accessible to an unauthorized third party due to the incident. This could present a risk that the data might be used for attempted fraud, impersonation, phishing, or other forms of personal data misuse.
Since personal data includes information that can be used to establish believable contact with you, there is a possibility that you may receive messages that initially appear to have been sent by HIT d.d. Nova Gorica.
How to Recognize and Prevent Potential Fraud
In the event that you receive fraudulent messages, which may also contain your personal data (e.g., first name, last name, address, etc.), never take the presence of such data as proof of the message’s or call’s authenticity.
Trust only official notifications from HIT d.d. Nova Gorica company and seek verified information through the company’s official communication channels. With due caution and a prompt response, you can effectively prevent most frauds, even in the event that your data has been disclosed.
The HIT d.d. Nova Gorica company will never ask you via SMS, email, or telephone call to provide your password, one-time security code, or other confidential information, to confirm a transaction that you did not initiate yourself, or to log into your account via an unknown or provided web link.
The HIT d.d. Nova Gorica company communicates with you via the official company website www.hit.si, through the official websites of individual business units, and via official email accounts with the domain “@hit.si”.
We recommend that you exercise extra caution in the future regarding all incoming messages. If you suspect in any way that messages are not authentic or contain incomplete information, verify their authenticity directly with the sender. In any case, we advise you to take the following steps:
- Change all your passwords, choosing strong passwords;
- Do not open links or attachments in suspicious messages;
- Do not enter any data based on such messages;
- Do not make payments based on requests received through such messages;
- Do not reply to suspicious messages, do not forward them to others, and delete them immediately;
- Do not use contact details or links provided within the message itself to verify its authenticity;
- Visit the website www.staysafeonline.org to familiarize yourself with other protective measures you can take.
To verify the authenticity of a message, we are at your disposal at info@hit.si.
What We Have Done
Immediately upon detecting the incident, we implemented measures to contain, mitigate, and gradually resolve the attack, as well as to provide additional protection for our information systems and data.
We have involved law enforcement authorities and external cybersecurity experts in the investigation to assist in determining the circumstances, nature, and scope of the incident. We are implementing additional technical, organizational, and other security measures to further protect data and prevent similar incidents in the future.
At the same time, we are monitoring potential attempts at data misuse or fraud related to the incident. In the event of significant new findings or circumstances, we will take appropriate action and notify you further as necessary.
We have restored our business operations following the cyberattack. Individual delays or performance limitations in certain systems may still occur, as during the restoration process we place particular priority on the security and integrity of our information systems and the protection of your data.
Additional Information and Contact Details
Information regarding the security event is available and will be regularly updated on our website.
For any questions regarding this notice, we are available at the email address kibernetski.incident@hit.si.
In case of questions regarding the protection of your personal data, you may also contact the Data Protection Officer (DPO) at dpo@hit.si.
We are aware that such an incident may cause you concern and inconvenience. We sincerely apologize for the situation and thank you for your understanding and trust.
Sincerely, HIT d.d. Nova Gorica