Hacker wipes European country’s entire land registry database, paralyzing real-estate market. The attack halted all property transactions.
Romania’s national land registry was thrown into chaos after a hacker breached the country’s cadastre agency and, following an apparently unsuccessful extortion attempt, deleted the data they had stolen. The attack on the National Agency for Cadastre and Real Estate Advertising (ANCPI) brought property transactions across the country to a standstill, leaving notaries unable to authenticate sales, issue land registry extracts, or register mortgages.
The attacker first announced the breach on a hacking forum with the message: “[RO] Thy arss shall be spanked, Romania! [ANCPI]”. According to the hacker, the stolen material included personal data belonging to Romanian citizens, information gathered from various databases accessible through ANCPI’s networks, and a copy of the agency’s GitLab servers containing the source code for several of its systems, including Eterra and RENNS. The hacker also claimed to have included a version of their own ransomware program among the stolen files.
ANCPI initially described the disruption as a result of “technical problems.” It later acknowledged that the institution had in fact suffered a cyberattack. The consequences were severe: the agency’s IT systems became inaccessible, effectively paralysing much of Romania’s real-estate transaction infrastructure.
After the extortion attempt apparently failed, the attacker reportedly deleted the data they had obtained. This allegedly included internal documents, employee credentials and, most significantly, the country’s land registry data. The hacker appears to have gained access using valid credentials rather than through an especially sophisticated intrusion technique.
The disruption was immediately felt by notaries throughout Romania. Ana Stan, a notary, described the situation online in stark terms: “I am a notary. Since Tuesday, I cannot issue a land registry extract, I cannot authenticate a sale, I cannot register a mortgage.”
The attacker, operating under the dark-web identity ByteToBreach, reportedly went further by claiming to have begun deleting or compromising backup copies of the stolen data in an effort to make recovery more difficult. The same actor has also been linked to an earlier breach of Sweden’s e-government portal and has since reportedly been identified, or “doxxed,” online.
Despite the scale of the disruption, Romanian officials have managed to restore the ANCPI website and have begun rebuilding the agency’s network from scratch. More importantly, it appears that ANCPI had maintained an offline copy of the land registry data, potentially allowing the institution to recover the information that was deleted during the attack.
The incident has nevertheless triggered significant criticism over ANCPI’s cybersecurity practices and its preparedness for precisely this type of attack. Critics argue that the attacker had considerable opportunities because the agency had not invested sufficiently in protecting its infrastructure.
Romanian financial publication Ziarul Financiar described the incident as the consequence of a model in which cybersecurity is treated as an annex, rather than as a fundamental part of digital infrastructure.
According to reports, ANCPI has spent approximately €135 million ($154 million) on digitalisation over the past 20 years. Only around 0.2% of that investment — approximately €305,000 ($348,000) — was reportedly allocated to cybersecurity.
Romania’s National Cyber Security Directorate (DNSC) has also faced questions about the agency’s preparedness. DNSC said it had previously warned ANCPI about weaknesses in its cybersecurity posture. Its director, Dan Cîmpean, described the attack as relatively unsophisticated and said it could have been prevented. According to DNSC, the attacker exploited “vulnerabilities that we had notified them about quite recently.”
Romania’s interim economy minister, Irineu Darău, likewise argued that ANCPI could have done considerably more to prevent the incident. Speaking to Digi24, he stressed that cybersecurity should be treated as a top priority across government institutions.
“Each institution and the management of each institution must treat cybersecurity as priority zero. You can never reduce the risk of a cyberattack to zero, but I believe that many institutions, including the ANCPI, still have work to do in prevention, in strengthening the security of their own software.”
The timing of the attack has also made the disruption particularly sensitive. The incident occurred during the final weeks in which Romanian buyers could still purchase new homes subject to a 9% VAT rate. From August 1, the VAT rate on new homes was scheduled to increase to 21%, potentially adding further pressure to property transactions already delayed by the cyberattack.
Meanwhile, cybersecurity company KELA has reportedly attributed the ByteToBreach operation to Zakaria Mahdjoub, an individual based in Oran, Algeria. Researchers describe Mahdjoub as a technically skilled cybercriminal allegedly involved in selling sensitive data obtained from airlines, banks and government organisations around the world.
ByteToBreach has also been linked to alleged breaches of government registries elsewhere in Eastern Europe, including Slovakia, Ukraine, Poland and Lithuania.
For Romania, however, the ANCPI incident represents more than another data breach. The attack exposed how dependent essential public services have become on digital infrastructure — and how quickly a failure in that infrastructure can spill over into the real economy. Even if the land registry data can ultimately be recovered from offline backups, the incident has raised uncomfortable questions about why those safeguards were necessary in the first place and whether Romania’s public institutions are investing enough in cybersecurity to protect critical national systems.
