Romania’s land registry agency said Monday that a cyberattack that took out the country’s digital registry systems last week had not compromised its technical and legal databases — the core records containing cadastral information such as property boundaries, maps, as well as legal information including ownership and mortgages.
The National Agency for Cadastre and Land Registration (ANCPI) said it is continuing efforts to restore services that have been offline for nearly a week, bringing real estate transactions across the country to a standstill.
According to its statement, the agency has begun migrating its applications to the Romanian government cloud, a process expected to finish on Wednesday, after which authorities will verify the integrity of the systems before gradually restoring services.
“The primary objective is to protect data integrity and eliminate all identified vulnerabilities,” ANCPI said, adding that affected systems must remain isolated until every identified security weakness has been addressed.
The agency disclosed last Tuesday that it had suffered what it described as “the most serious technical incident in the institution’s history” after a cyberattack disabled its central IT infrastructure, including the nationwide e-Terra cadastral and land registry platform.
The outage disrupted online land registry services, official email systems, and applications used by notaries, lawyers, cadastral specialists, and ANCPI employees, preventing authorities from registering new property transactions or processing existing requests.
Dan Cimpean, director of Romania’s National Directorate for Cyber Security (DNSC), told Romanian outlet G4Media that the attack appeared to be financially motivated and was carried out by exploiting known software vulnerabilities that authorities had recently warned organizations to patch, together with previously leaked credentials.
“It wasn’t a very complex attack,” Cimpean said, adding that investigators had so far found no evidence that personal data or land registry certificates had been stolen, although the attackers had allegedly exfiltrated a limited amount of information, including user credentials and application source code.
A threat actor using the name ByteToBreach claimed responsibility for the attack last week, advertising what it said was stolen ANCPI data for sale on an underground forum, including internal databases and source code for the e-Terra system.
Cimpean said Romanian authorities believe ByteToBreach is an initial access broker that targets poorly protected systems for financial gain rather than a state-backed hacking group. He said investigators suspect the threat actor is based in Algeria.
Israel-based cybersecurity firm Kela has attributed the ByteToBreach persona to Zakaria Mahdjoub, an alleged cybercriminal based in Oran, Algeria, who it describes as a prolific seller of stolen government, banking, and airline data. Romanian authorities have not verified those claims.
In an interview with Euronews Romania conducted over the Signal messaging app, a person claiming to be the hacker apologized to Romanians and IT professionals for the intrusion and, when asked whether citizens should be concerned about stolen data, replied: “I don’t sell this data to just anyone.” Recorded Future News could not independently verify the identity of the individual or the claim.
According to local media reports, the disruption comes just weeks before Romania will raise the value-added tax on new homes to 21% from 9%, reportedly delaying transactions that many buyers and developers had hoped to complete before the higher tax takes effect.
Because the country’s cadastral and land registry system is fully digital, authorities cannot register new property transactions, process existing applications, or issue land registry extracts required for home sales and mortgage registrations, ANCPI said.
Recorded Future
Intelligence Cloud.
