Skip to content

Romania’s Cadastral Database Completely Deleted Following Failed Extortion Attempt

In a nutshell: An identified hacker deleted the Romanian cadastral database in retaliation for a failed extortion attempt, blocking all real estate transactions nationwide.

A cybercriminal has completely destroyed the central land registry database of Romania’s ANCPI authority following a failed extortion attempt. The attack has paralysed the entire real estate market and reveals critical vulnerabilities in the security of state infrastructure.

Romania’s National Agency for Cadastre and Real Estate Advertising (ANCPI) has become the target of a destructive cyberattack. The attacker gained access to the systems using valid credentials, stole internal documents and employee data, and subsequently deleted the complete land registry data on the primary servers. Romania records between 150,000 and 170,000 real estate sales annually — none of which can now be documented or legally verified. Notary Ana Stan described the immediate impact: “Since Tuesday, I cannot issue a land registry extract, certify a sale, or register a mortgage.”

The attacker, operating under the pseudonym ByteToBreach, demanded ransom. After the failed extortion attempt, he destroyed the data. Initially, ANCPI declared the outage a technical issue, but later admitted to the targeted attack. The authority is currently launching a complete rebuild of its IT infrastructure. According to government officials, the institution maintains physically isolated offline backups at multiple redundant locations. The attacker claimed in the dark web that he also sabotaged the backup process — a claim that security experts doubt. Gradual system recovery has been initiated.

Cybersecurity company KELA identified the alleged operator as Zakaria Mahdjoub, resident of Oran, Algeria. ByteToBreach is credited with a series of attacks on government systems: Sweden’s e-government portal and state registers in Slovakia, Ukraine, Poland, and Lithuania. The scope of this campaign suggests systematic vulnerabilities in authentication and access control across European government networks.

For CISOs, the incident demonstrates critical risks: compromise via valid credentials reveals deficiencies in identity verification and privileged access management (PAM). The destructive action following a failed ransom attempt underscores that even unsuccessful cyber extortion can result in total data loss. Confidence in supposedly secure offline backups is relativized by the attacker’s claim of their sabotage — a reminder of the need to secure backup integrity through cryptographic verification and regular testing.


Source: www.it-daily.net · Published 21 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: