Forgot your password?
typodupeerror
Security Databases

Hacker Wipes Romania's Entire Land Registry Database (cybernews.com) 51

A hacker reportedly wiped Romania's entire land registry database after a failed extortion attempt, halting property transactions across the country and preventing notaries from issuing land extracts, authenticating sales, or registering mortgages. "On the dark web, the hacker also boasted to have begun backup copies of stolen data in an attempt to prevent it from being restored," reports Cybernews. "However, Romanian officials have managed to at least restore the ANCPI's website and post a message saying they were rebuilding the agency's entire network from scratch. It appears that the agency has an offline copy of the wiped data." From the report: First, the hacker breached Romania's cadastre agency, the National Agency for Cadastre and Real Estate Advertising (ANCPI), posting on a hacking forum: "[RO] Thy arss shall be spanked, Romania! [ANCPI]." "In addition to the data of Romanian citizens, from various databases collected through ANCPI networks, there is also a copy of the GitLab servers containing the source code of all their systems, such as Eterra, RENNS, as well as a version of my little ransomware program," the announcement continued.

"The official government website announced a shutdown of IT systems due to 'technical problems,' but this is a bit of an understatement. An offer of assistance was made, but without insistence or pressure." Indeed, the ANCPI initially claimed technical issues but had to admit it was facing a cyberattack. Today, no one can really access the institution's systems. And since the extortion didn't work, the hacker -- who seems to have entered the database using valid credentials -- deleted all data they had stolen, including internal documents, employee credentials, and, of course, land registry data.

Hacker Wipes Romania's Entire Land Registry Database

Comments Filter:
  • by Valgrus Thunderaxe ( 8769977 ) on Monday July 20, 2026 @01:11PM (#66248006)
    100% guarantee. They hate Romania.
    • by rpetre ( 818018 ) on Tuesday July 21, 2026 @05:18AM (#66249152)
      It was sheer incompetence from the authorities. Unpatched CVEs from 2021, wide open internal network, extremely poor admin passwords, the whole shebang. We're lucky it was essentially a lone script kiddie that did a smash and grab looking for the AD (he's allegedly Algerian and he's been doing similar kinds of hacks before). If it truly were the Russians, they could have done MUCH, MUCH worse. From leaking the database and exposing hidden properties of various politicians, to silently modifying or corrupting data. Of course the authorities went through all the possible bad takes. From denying it even happened, to blaming shadow organizations (like your post does), to getting mad at the press for trying to contact the hacker. Now they are pivoting into "after all no sensitive data was lost and we're migrating it to new infra so no harm no foul".
  • by GeekWithAKnife ( 2717871 ) on Monday July 20, 2026 @01:32PM (#66248042)
    When faced with the "cost" of such an outcome how much does mitigation worth to you?

    Friendly word to business owners and senior managers; if you haven't tested your ransomwate recovery mechanism and proved it works just assume there is none.

    ...and no I don't know the details but I can tell you it was preventable.
    • The cost of mitigation isn't that large even. Way back when, I helped build a backup for a system holding critical data that had a far greater transaction volume than the typical cadastre ever will. The system was pretty basic and cheap to build and operate, basically a daily incremental backup written on immutable media, along with a printout of each transaction. This was before ransomware was even a thing, though hacking was already a concern and part of the reason the customer wanted this system (the
    • Tape is great!

      Have the tape drive backup program just watching for changed files from a group of programs, and if there's changes, it needs a password to start copying to the tape library or drive (whatever). The tape drive or library is either offsite or in building (but safe from anything that could get onto the companies network), and as soon as that ransomware screen pops up, kick the power button on the power strip (or yank the power cable to the computer).

      If it's accessible online, connected to the '

  • by Hentes ( 2461350 ) on Monday July 20, 2026 @01:54PM (#66248066)

    The Slovakian land registry also got hacked 2 years ago. I wonder if they are using the same software.

    • Pretty sure no, Romanian software is made by a group of local companies. And those companies have a bad reputation, being linked [hotnews.ro] to a fugitive [wikipedia.org].

  • Kafka (Score:2, Troll)

    by toxonix ( 1793960 )

    Someone call Land Surveyor K. There's now an entire country to survey. His training may finally be useful.

  • Sounds like they werent as tough as they thought. Everytime the DMV dicks around a citizen, I always wonder who among the crowd "possess certain skills" and get tired of it. I'm glad someone got a point back for their side.

  • If they were smart then they would have simply sold land to people on a legit looking website and changed the ownership database. If you are morally bankrupt then you should at least avoid being intellectually bankrupt.

  • Just saying .. an off-site backup is very good for such data!

  • It would totally be worth it to see Jared and Ivanka's billion dollar land scam get wiped out.
  • "It appears that the agency has an offline copy of the wiped data"

    Well, like, duh. Had they not, they should all be immediately fired. And never work in IT again.

  • “Israel-based cybersecurity firm Kela has attributed the ByteToBreach persona to Zakaria Mahdjoub [therecord.media], an alleged cybercriminal based in Oran, Algeria, who it describes as a prolific seller of stolen government, banking, and airline data. Romanian authorities have not verified those claims.”

    ‘In an interview with Euronews Romania conducted over the Signal messaging app, a person claiming to be the hacker apologized to Romanians and IT professionals for the intrusion and, when asked whether c
  • I don't know how the country of Romania is treating this as... but in my opinion, an attack that affects their entire population will be treated as an act of war. These hackers, if convicted by their court, will have only the death sentence. Any country they're hiding at, including those that don't have diplomatic relation to Romania, will be asked for a extradition. What I don't know (I have absolutely no clue) is how the extradition request gets done given the severe consequences. If a country rejects the

The first version always gets thrown away.

Working...