Romanian Property Registry Wiped by Hackers After Failed Extortion Attempt
The National Agency for Cadastre and Real Estate Publicity (ANCPI) in Romania suffered a devastating cyberattack when hackers, identified as belonging to the group ByteToBreach, deleted its property registry database. The attack followed an unsuccessful extortion attempt where the attackers demanded money in exchange for not erasing the data. ANCPI refused to negotiate with the criminals, leading to the complete destruction of the property registry system. This incident paralyzed a significant portion of the country's real estate market for approximately one week, preventing notaries from registering transactions, citizens and banks from obtaining property certificates, and rendering official applications and websites inoperable. Reports indicate the intruder gained access using valid credentials, navigated the internal network, and ultimately deleted both production systems and backups when their extortion demands were not met. The situation was further exacerbated when employee credentials, internal documents, and information about the agency's IT infrastructure were later found for sale. Fortunately, the Romanian administration is rebuilding the system from scratch using an offline backup copy, which will allow for the recovery of records. This incident is not isolated, as similar attacks have targeted property registries in Poland, Slovakia, Greece, Morocco, Russia, and Ukraine in recent years.
This incident highlights a critical vulnerability in centralized digital infrastructure, particularly for governmental bodies managing sensitive public data. The attackers exploited a common ransomware tactic: data destruction following a failed extortion attempt, underscoring the need for robust, multi-layered cybersecurity defenses that extend beyond mere data encryption to include resilient backup and recovery strategies, including offline and immutable copies. The reliance on valid credentials for initial access suggests potential insider threats or sophisticated phishing campaigns, necessitating continuous security awareness training and stringent access control protocols. The widespread nature of similar attacks across Europe and beyond indicates a systemic challenge, suggesting that property registries and similar large-scale data repositories are increasingly attractive targets for financially motivated cybercriminal groups. Future preparedness will require proactive threat intelligence, regular penetration testing, and potentially a shift towards more decentralized or resilient data management architectures to mitigate the impact of single points of failure.
AI-generated to prompt reflection — not editorial opinion, not advice, not a statement of fact. How this works.