Romania’s National Agency for Cadastre and Real Estate Registration (ANCPI) has been effectively offline for over two weeks.
As we are used to the affected parties almost always minimizing the attacks, and the attackers conflating the amount of damage they inflicted, what was announced on 14 July as a major technical incident was later confirmed as a cyberattack. Taking place on 14 July, the attack left the e-Terra application dark ever since, and with it, the entire country’s ability to issue various registrations, land registry or notary updates, or even authenticate property transactions.
ANCPI then called it the most serious technical incident in the institution’s history. Now, this is the one statement in this whole affair that nobody will ever dispute.
What we know so far
The attacker Loic Matrier, who operates under the pseudonym ByteToBreach, infiltrated using valid credentials, possibly posted on internet hacking forums, mapped the internal network, attempted to extort the agency, and when that did not go to plan, the attacker started deleting systems and backups on the way out.
Dan Cîmpean, director of the National Cyber Security Directorate, described it as financially motivated and said it “wasn’t a very complex attack,” exploiting known software vulnerabilities and previously leaked credentials. He also stated that exfiltration was limited to user credentials and application source code, with no evidence of stolen personal data or land registry certificates.
I agree with the fact that it is not a complex attack. We later found out that several of the websites had the username “admin” with the password being “password”. We don’t even need to mention 2FA because, of course, there was none. And what was later found out and discussed were the old Windows versions, policies to disable firewalls and various security processes that might’ve ‘hampered’ their computers with various vulnerability alerts that needed to be silenced.

Feels bad to say, but this felt pretty much like a Romanian thing, just like how, if we can generalize a bit and make fun of ourselves, a lot of Romanians ask for various car sensors to be silenced or completely removed, instead of fixing the actual problem that the sensor alerted them to.
Back to the attack. Not that we should take everyone’s word as 100% truthful, but the attacker’s version is a bit different. ByteToBreach advertised much more: internal databases, citizen data, internal documents, employee credentials, and the entire source code for the e-Terra and RENNS systems on underground forums, with screenshots attached. Then, reassuringly, as every Romanian citizen started saying under their breath (thank god) (sarcasm), they told a journalist: “I don’t sell this data to just anyone.”
ANCPI’s version is, of course, also different. On July 15, the agency stated that data administered through its IT systems “has not been compromised.” On July 20, it clarified that the attacker did not manage to wipe all backups because backups are stored in several locations. This statement needs to be waited on to see if it aged like milk or fine wine.
There we go, now we have three accounts of one major incident. Only time will settle this, hopefully.
But wait, it was not just ANCPI
Two days later, on July 16, the Ministry of Investments and European Projects confirmed that its “Achiziții Beneficiari Privați” application had also been compromised. I feel almost bad writing on this blog about defense-in-depth, zero-trust security, while most likely that application contains passwords like “qwerty123, password”.
Two confirmed attacks on Romanian public institutions in three days. No attribution has been published for the second one.
The deadline nobody wants to discuss
The transition window that lets qualifying buyers complete a purchase at 9 percent VAT instead of the current standard rate closes on July 31. Buyers who signed pre-contracts and paid their advance before August 2025 needed to finalise before that date. Finalising means notarial authentication. Notarial authentication requires a land registry extract. Land registry extracts have not been issued since July 14.
Recovery estimates, for their part, have slipped three times. July 20, then July 22 for the government cloud migration, then Prime Minister Bolojan’s July 23 statement that activity would resume “in the course of next week.” That week is now ending. It all depends on whether they actually have a reasonably fresh backup, however, all assumptions point to the worst-case scenario.
Further analysis is in progress
I want to see the incident report before drawing harder conclusions about the intrusion chain, and I would like a straight answer on which specific systems held the surviving backups and how they were isolated. It’s not as if a software project that cost millions of taxpayers’ money should mean demanding more explanations.
Sources:
– [Help Net Security – Romania’s land registry hit by cyber attack, data allegedly for sale]
– [The Record — Romania races to restore land registry after cyberattack disrupts property market]
– [Risky Bulletin — Hacker wipes Romania’s entire land registry database]
– [BlackBullet — Two Confirmed Attacks in Three Days]
– [Balkan Insight — Land Registry Cyberattack Exposes Holes in Romania’s Digital Defences]
Photo by Towfiqu barbhuiya on Unsplash
