Tue 21 Jul 2026 / 00:28 ET
Kernel
Security 3 min read

Romania moves land registry to government cloud after cyberattack

ANCPI says core cadastral and legal records were not compromised, but a weeklong outage has frozen property transactions across Romania.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

Romania moves land registry to government cloud after cyberattack
img: The Record

Romania’s land registry authority is rebuilding its digital systems after a cyberattack knocked out the platform used to record property sales, mortgages and cadastral filings across the country.

The National Agency for Cadastre and Land Registration, or ANCPI, said Monday that its core technical and legal databases were not compromised. Those records contain the basics that make a property market function: boundaries, maps, ownership data and mortgage information.

That does not mean the incident was harmless. ANCPI said services have been offline for nearly a week, leaving notaries, lawyers, cadastral specialists, agency staff and homebuyers unable to complete the digital steps required for property transactions. In a registry system that runs fully online, taking the platform down means the paper workaround is mostly fantasy.

ANCPI said it has started moving its applications into Romania’s government cloud. The agency expects that migration to finish Wednesday, after which officials will check system integrity before bringing services back in stages.

“The primary objective is to protect data integrity and eliminate all identified vulnerabilities,” ANCPI said. The agency said affected systems will stay isolated until all identified security weaknesses are addressed.

What went down

ANCPI first disclosed the incident last Tuesday, calling it the most serious technical incident in the institution’s history. The agency said the attack disabled its central IT infrastructure, including e-Terra, the nationwide cadastral and land registry platform.

The outage also disrupted online land registry services, official email and applications used by outside professionals and ANCPI employees. According to ANCPI, authorities cannot register new property transactions, process pending requests or issue land registry extracts needed for home sales and mortgage registrations while the systems remain unavailable.

The timing adds pressure. Local media reports said the disruption comes shortly before Romania is set to raise value-added tax on new homes to 21% from 9%, delaying deals that some buyers and developers had hoped to finish before the higher rate applies.

Known bugs, leaked credentials

Dan Cimpean, director of Romania’s National Directorate for Cyber Security, told G4Media that the attack appeared to be financially motivated. He said the attackers used known software vulnerabilities that authorities had recently warned organizations to patch, along with previously leaked credentials.

“It wasn’t a very complex attack,” Cimpean told G4Media. He said investigators had not found evidence so far that personal data or land registry certificates were stolen. He also said the attackers allegedly exfiltrated a limited amount of information, including user credentials and application source code.

A threat actor using the name ByteToBreach claimed responsibility last week and advertised what it described as stolen ANCPI data on an underground forum, including internal databases and source code for e-Terra.

Cimpean said Romanian authorities believe ByteToBreach is an initial access broker, a criminal seller of entry into compromised systems, rather than a state-backed hacking group. He said investigators suspect the actor is based in Algeria.

Cybersecurity firm Kela has attributed the ByteToBreach persona to Zakaria Mahdjoub, whom it described as an alleged cybercriminal in Oran, Algeria, and a seller of stolen government, banking and airline data. Romanian authorities have not confirmed Kela’s attribution.

In an interview conducted over Signal by Euronews Romania, a person claiming to be the hacker apologized to Romanians and IT workers. Asked whether citizens should worry about stolen data, the person said: “I don't sell this data to just anyone.” Recorded Future News said it could not independently verify the person’s identity or the claim.

This story draws on original reporting from The Record.

More Security/

view all ↗