Cybersecurity & Government IT

A Hacker Wiped Romania's Entire Land Registry — Inside the Attack That Froze a National Real-Estate Market

Romania's national cadastre agency was breached and its land-registry database wiped following a failed extortion attempt — a textbook example of why single points of truth in government IT are such dangerous targets.

The attack unfolded quietly before it became a crisis. The hacker gained access through legitimate-looking login credentials — a reminder that a stolen password is often a full invitation to an organisation's backend. Once inside, the attacker spent time mapping the network before any data was touched, the calm phase of a ransomware-style extortion attempt. When the agency did not comply, the attacker's fallback was simple and brutal: delete everything, including the backups.

Why does erasing a land registry stop a country's economy? Because the cadastre is the single authoritative record of who owns what. Notaries cannot record sales, citizens cannot prove ownership, and property transactions of every size grind to a halt. Restoring the website was the easy part; the agency is now rebuilding its entire network from scratch. Officials appear to have an offline copy of the registry, which has kept the situation from becoming catastrophic — but the episode exposes how fragile a single national database can be.

Worryingly, this is no longer an isolated pattern. Romania joins Poland, Slovakia, Greece, Morocco, Russia and Ukraine among countries whose land-registry agencies have been compromised in the past three years. As governments digitise physical records, those records become a single, high-value target — and credential theft, not sophisticated malware, remains the easiest door to walk through.