A major cyberattack has disrupted Romania’s real estate sector after hackers targeted the National Agency for Cadastre and Real Estate Advertising (ANCPI), wiping the country’s land registry database following an unsuccessful extortion attempt. According to reports, the attacker first breached the agency’s systems and later published a message on a hacking forum claiming access to sensitive information stored within ANCPI’s networks. The post alleged that the stolen data included information belonging to Romanian citizens, copies of GitLab servers containing the source code of systems such as Eterra and RENNS, and even a version of the attacker’s own ransomware program. Although ANCPI initially described the outage as a technical issue, the agency later confirmed that it had experienced a cyberattack. Reports indicate that the attacker gained access using valid credentials and, after the extortion attempt failed, deleted the stolen data, including internal documents, employee credentials, and land registry records.
The incident has severely affected Romania’s property market, preventing notaries from registering new transactions and leaving citizens unable to obtain proof of property ownership or access detailed land records. Romania records approximately 150,000 to 170,000 residential property sales each year, making the disruption significant for both businesses and individuals. One Romanian notary, Ana Stan, stated that since the systems became unavailable she could not issue land registry extracts, authenticate property sales, or register mortgages. The attacker, operating under the dark web alias ByteToBreach, also claimed to have started deleting backup copies of the stolen information in an effort to prevent data restoration. Despite the damage, Romanian authorities have restored ANCPI’s public website and announced that they are rebuilding the agency’s network from the ground up. Officials also stated that the agency maintained multiple offline backup locations, allowing the restoration of critical data despite the attack. ANCPI said these backup systems had been established to provide redundancy and ensure data recovery in the event of cybersecurity incidents.
The cyberattack has also sparked criticism over ANCPI’s cybersecurity practices and investment strategy. According to local reports, the agency has invested approximately €135 million in digitalization over the past two decades, but only around 0.2 percent of that amount, approximately €305,000, was reportedly allocated to cybersecurity. Romanian media described the incident as the result of treating cyber defense as a secondary priority rather than an essential component of digital transformation. Romania’s National Cyber Security Directorate (DNSC) stated that it had previously warned ANCPI about weaknesses in its cybersecurity posture and had recently notified the agency about vulnerabilities that were later exploited during the attack. DNSC Director Dan Cîmpean reportedly said the attack was not technically advanced and could have been prevented if the identified security issues had been addressed. Interim Economy Minister Irineu Darău also emphasized that every public institution should treat cybersecurity as a top priority, stating that while cyber risks can never be eliminated completely, stronger preventive measures and better software security could significantly reduce the likelihood of such incidents.
The timing of the attack has added further pressure on Romanian authorities, as it occurred during the final weeks in which home purchases qualify for a 9 percent value added tax before the rate increases to 21 percent on August 1. The disruption has therefore affected both government services and ongoing property transactions across the country. Meanwhile, cybersecurity company KELA reported that the individual believed to be operating the ByteToBreach campaign is likely Zakaria Mahdjoub, who is based in Oran, Algeria. Researchers described the threat actor as a technically skilled cybercriminal involved in selling sensitive information obtained from airlines, banks, and government organizations. The same actor has also been linked to an earlier breach involving Sweden’s e government portal and is suspected of participating in attacks targeting government registries in several Eastern European countries, including Slovakia, Ukraine, Poland, and Lithuania.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.