Cybersecurity & Government IT
A Hacker Wiped Romania's Entire Land Registry — Inside the Attack That Froze a National Real-Estate Market
Romania's national cadastre agency was breached and its land-registry database wiped following a failed extortion attempt — a textbook example of why single points of truth in government IT are such dangerous targets.
- The breach targeted Romania's National Agency for Cadastre and Real Estate Advertising (ANCPI), whose apps and websites have been offline for a week, stalling the entire real-estate market.
- The attacker entered using valid, likely-stolen credentials, mapped the internal network, then deleted systems and backups after the agency refused to pay.
- Stolen employee credentials, internal documents and IT-network details appeared for sale on a known hacking forum under the handle "ByteToBreach," already linked to Sweden's e-government breach this year.
The attack unfolded quietly before it became a crisis. The hacker gained access through legitimate-looking login credentials — a reminder that a stolen password is often a full invitation to an organisation's backend. Once inside, the attacker spent time mapping the network before any data was touched, the calm phase of a ransomware-style extortion attempt. When the agency did not comply, the attacker's fallback was simple and brutal: delete everything, including the backups.
Why does erasing a land registry stop a country's economy? Because the cadastre is the single authoritative record of who owns what. Notaries cannot record sales, citizens cannot prove ownership, and property transactions of every size grind to a halt. Restoring the website was the easy part; the agency is now rebuilding its entire network from scratch. Officials appear to have an offline copy of the registry, which has kept the situation from becoming catastrophic — but the episode exposes how fragile a single national database can be.
Worryingly, this is no longer an isolated pattern. Romania joins Poland, Slovakia, Greece, Morocco, Russia and Ukraine among countries whose land-registry agencies have been compromised in the past three years. As governments digitise physical records, those records become a single, high-value target — and credential theft, not sophisticated malware, remains the easiest door to walk through.