• Sources: Risky Business, Help Net Security, HN discussion
  • Summary: Romania's National Agency for Cadastre and Real Estate Advertising (ANCPI) confirmed a cyberattack on its e-Terra land-registry platform. Reporting states the attacker logged in with valid credentials, mapped internal systems, then wiped systems and backups after the agency refused an extortion demand, and that email servers were also affected. The intrusion became public on 2026-07-14 as data deletion began, and stolen citizen records and source code were offered for sale on 2026-07-15. The country's real-estate market stalled for about a week: official apps and websites went offline, notaries could not record transactions, and citizens could not obtain proof of ownership. ANCPI has begun rebuilding its network from scratch, reportedly aided by an offline backup. Security firm KELA attributes the ByteToBreach account used in the attack to an actor based in Oran, Algeria, also linked to a Sweden e-government breach this year.
  • Comments: HN commenters note the agency appears to have retained an offline copy despite the attacker's claim to have deleted backups, and compare the incident to an earlier attack on Slovakia's land registry.
  • Why it matters: A credential-based intrusion that destroyed a national land registry and its online backups and halted a country's property market for a week is a concrete lesson on offline backup isolation and credential hardening for critical civic infrastructure.
  • Follow-up: Watch for a published post-mortem, confirmation the offline backup restores the registry without data loss, and the scope of the data-for-sale fallout.

send feedback on this story