Technology

Romania's Land Registry Goes Dark After Cyberattack

A breach has paralyzed Romania's digital land registry, bringing real estate transactions across the country to a halt. The government insists that ownership data remains undamaged. It is a warning shot that highlights the importance of IT security.

Computers in a server room.

Romania\'s property market has stalled since the country\'s cadastral systems were compromised. Photo: Getty Images

A cyberattack on Romania's cadastral authority, the National Agency for Cadastre and Land Registration (ANCPI), has brought the country's real estate transactions largely to a standstill. Central applications, including the land registry system e-Terra, have been unreachable since 14 July. Online claims that databases had been deleted and backup copies destroyed have circulated widely, but the government states that the ownership data remains intact.

On 14 July, nearly all of ANCPI's IT systems failed, affecting the email infrastructure and, above all, e-Terra, the system used to generate land registry extracts, register ownership changes, record mortgages and process cadastral procedures. The authority initially described the outage as a technical malfunction, before confirming a day later that it had in fact been a cyberattack, one it called the largest technical disruption in its history.

https://twitter.com/ThreatLocker/status/2080045246512083120

Hacker Offers Decryption Help, for a Price

Shortly after the outage, an entity going by the name ByteToBreach began offering data allegedly stolen from ANCPI for sale on several online forums. According to Romanian media reports, ByteToBreach claimed to have obtained personal information, the source code of the e-Terra and RENNS systems, and copies of internal GitLab servers, which store source code, technical documentation and access credentials. For the Romanian cadastral authority, a compromised GitLab server would be especially damaging, since it could give an attacker insight into the architecture of e-Terra and other applications, along with access keys, passwords or configuration data that could enable further attacks elsewhere in the system. Screenshots that circulated online also created the impression that the attacker had begun deleting backup copies.

This gave rise to the misleading headline that Romania's land registry had been deleted. In an interview, the alleged perpetrator said that numerous files had been encrypted, but insisted the central databases themselves had not been altered, only copied. ByteToBreach also denied the reported demand of €10m ($11.40m), though the entity admitted to a financial motive and offered the authority help with decryption in exchange for payment.

Welcome to the comments section of the Štandard daily. Please take note of our guidelines, comments are moderated by us. You can contact the moderators at support@statement.com.

Participate in the discussion

Comments are available to subscribers only. If you'd like to join the discussion, choose a subscription starting at €6.72 per month.

All comments 0

    Register

    Comments are available to registered users only. If you'd like to join the discussion, register here.