Analysis

Hackers Wiped Romania's Land Registry

NB NeoBit team Jun 15, 2026 10 min read
Hackers Wiped Romania's Land Registry

In mid July 2026, Romania's National Agency for Cadastre and Land Registration (ANCPI) became the target of a serious cyberattack. The attack took place around 14 July and was discovered a day later, around 15 July. The agency's services were unavailable for almost a week, and the consequence was the halting of practically all real estate transactions in the country. Notaries could not certify sales or mortgages, surveyors and lawyers were left without access to their applications, and land registry extracts could not be issued. For many entrepreneurs and citizens, this meant frozen deals at the worst possible moment.

Source

According to The Record (Recorded Future News) and Cybernews. Analysis and recommendations by NeoBit.

What exactly happened

The target was the e-Terra platform, the central system of Romania's cadastre and land registry, but also the agency's broader IT infrastructure: email systems and applications intended for notaries, lawyers and surveyors. Reports also mention the RENNS system and the internal GitLab, that is, the source code of the applications. In other words, this was a compromise of the core of digital government, not just one isolated service.

The timeline is instructive precisely because it is not spectacular. The attacker operated under the persona "ByteToBreach", a financially motivated initial access broker. The security firm KELA attributes that alias to Zakaria Mahdjoub from Oran, Algeria. Access to the system was secured through a combination of two banal but deadly weaknesses: leaked or stolen credentials and known, unpatched vulnerabilities that the responsible institutions had warned should be patched shortly before the attack. The director of ANCPI himself, Dan Cimpean, openly admitted that the attack "was not very sophisticated".

After gaining entry, the attacker carried out network reconnaissance, moved through the systems and attempted extortion. When the extortion failed, he claimed that he had destroyed the systems and the backups and that he had deployed his own ransomware. According to his claims, user passwords, application source code and internal databases were stolen. It is important to emphasize what, according to ANCPI and The Record, was not compromised: no personal data of citizens was stolen, nor were any land registry extracts. In other words, the ownership records of properties remained intact, which is the key difference between an unpleasant outage and a national catastrophe.

Recovery started from an offline copy of the data. ANCPI announced a migration to the government cloud and keeping the systems in isolation while the vulnerabilities are being patched. Additional pressure was created by a deadline: an announced increase in VAT on new properties from 9% to 21%, which is why a large number of buyers were rushing to close deals precisely while the systems were down.

Why this matters for us in BiH and the region

It is easy to write this off as a Romanian problem, but that would be a dangerous mistake. The weaknesses that took down ANCPI are not exotic; they are the everyday reality of public administration and the private sector in Bosnia and Herzegovina and across the region. Cadastres, civil registry offices, utility companies, banks, accounting services and ordinary mid sized firms share the same risk profile: employees use passwords that have already leaked somewhere, multi factor authentication (MFA) is not enabled or is not mandatory, critical systems remain without security patches for months or years, and backups are either nonexistent or connected to the same network that an attacker can wipe.

The message is sobering: to bring you down, you do not need a state actor or a zero day attack. A financially motivated individual, one stolen password and a patching failure you were warned about yourself are enough. If an institution the size of Romania's cadastre can stay offline for a week, the same fate threatens every company that delays basic measures. Digitalization without security only multiplies the attack surface.

Five lessons (and how to protect yourself)

1. An offline backup following the 3-2-1 rule literally saved Romania

The most important fact of the entire story: ANCPI recovered from an offline copy of the data. The attacker claimed that he had destroyed the systems and the backups, but the existence of a separate, offline copy meant the difference between recovery and permanent loss. The 3-2-1 rule (three copies of the data, on two different media, with one copy off site and separated from the network) is no longer a recommendation but a condition for survival. See how to set up backup for companies and why the 3-2-1 strategy is the foundation of ransomware resilience.

2. Leaked passwords are the entry door, and mandatory MFA is the lock

The attack began with stolen credentials. Billions of passwords circulate on forums and marketplaces, and if your employees reuse the same passwords, it is only a matter of time before one of them opens the door. Mandatory multi factor authentication on all access points stops the vast majority of such attacks even when the password is known to the attacker. Strengthen your email security and pay particular attention to Active Directory protection, because the domain controller is the most common target of lateral movement.

3. Patching vulnerabilities and regular resilience testing

The vulnerabilities that were exploited were known, and a warning already existed for them. Systematic patch management, short deadlines for critical vulnerabilities and regular penetration testing reveal the holes before an attacker discovers them. Testing from the attacker's perspective is the only honest way to find out how resilient you really are, instead of learning it from the headlines.

4. 24/7 monitoring that catches reconnaissance and lateral movement

Between the first entry and the extortion attempt, time passed during which the attacker moved through the network. Had someone been monitoring that traffic in real time, the incident could have been stopped before it escalated. Continuous SOC monitoring detects unusual logins, reconnaissance and lateral movement while they are still in an early phase, when the damage is minimal.

5. A rehearsed incident response plan

Romania had the plan and the discipline to recover from an offline copy, isolate the systems and migrate to the government cloud. Your company needs an equally clear protocol: who calls whom, how the systems are isolated and how operations are restored. If you suspect you have been compromised, it is important to immediately report the attack, while stable infrastructure management ensures that the response is fast and controlled rather than improvised.

Our solution

NeoBit combines 24/7 SOC monitoring, backup and disaster recovery and penetration testing, so that your company does not end up as a headline. Request a free assessment.

Frequently asked questions

Were citizens' personal data and land registry extracts stolen?

According to ANCPI and The Record, citizens' personal data and land registry extracts were not stolen. The attacker obtained user passwords, application source code and internal databases, but the ownership records of properties remained intact.

How did the attacker get into the system in the first place?

Through a combination of leaked or stolen passwords and known unpatched vulnerabilities for which a warning already existed. The agency's director himself admitted that the attack was not technically very sophisticated, which makes it an all the more dangerous lesson.

What saved Romania's cadastre from permanent loss?

An offline backup of the data. Although the attacker claimed that he had destroyed the systems and the backups, recovery was possible precisely because a separate copy existed beyond the attacker's reach.

Can an attack like this happen to a company or institution in BiH?

Yes. The same weaknesses (reused and leaked passwords, a lack of mandatory MFA, unpatched systems and poor backups) are widespread in the region's public administration and private sector. Basic protective measures and regular testing drastically reduce the risk.

Under attack? WhatsApp