Romania's Land Registry Goes Dark After Cyberattack

A breach has paralyzed Romania's digital land registry, bringing real estate transactions across the country to a halt. The government insists that ownership data remains undamaged. It is a warning shot that highlights the importance of IT security.

Computers in a server room.

Romania\'s property market has stalled since the country\'s cadastral systems were compromised. Photo: Getty Images

A cyberattack on Romania's cadastral authority, the National Agency for Cadastre and Land Registration (ANCPI), has brought the country's real estate transactions largely to a standstill. Central applications, including the land registry system e-Terra, have been unreachable since 14 July. Online claims that databases had been deleted and backup copies destroyed have circulated widely, but the government states that the ownership data remains intact.

On 14 July, nearly all of ANCPI's IT systems failed, affecting the email infrastructure and, above all, e-Terra, the system used to generate land registry extracts, register ownership changes, record mortgages and process cadastral procedures. The authority initially described the outage as a technical malfunction, before confirming a day later that it had in fact been a cyberattack, one it called the largest technical disruption in its history.

https://twitter.com/ThreatLocker/status/2080045246512083120

Hacker Offers Decryption Help, for a Price

Shortly after the outage, an entity going by the name ByteToBreach began offering data allegedly stolen from ANCPI for sale on several online forums. According to Romanian media reports, ByteToBreach claimed to have obtained personal information, the source code of the e-Terra and RENNS systems, and copies of internal GitLab servers, which store source code, technical documentation and access credentials. For the Romanian cadastral authority, a compromised GitLab server would be especially damaging, since it could give an attacker insight into the architecture of e-Terra and other applications, along with access keys, passwords or configuration data that could enable further attacks elsewhere in the system. Screenshots that circulated online also created the impression that the attacker had begun deleting backup copies.

This gave rise to the misleading headline that Romania's land registry had been deleted. In an interview, the alleged perpetrator said that numerous files had been encrypted, but insisted the central databases themselves had not been altered, only copied. ByteToBreach also denied the reported demand of €10m ($11.40m), though the entity admitted to a financial motive and offered the authority help with decryption in exchange for payment.

The Official Account of the Breach

ANCPI and the Romanian government maintain that, based on checks carried out so far, the technical and legal land registry databases have not been damaged. Acting Prime Minister Ilie Bolojan said on 23 July that experts had found no evidence of impairment to the ownership data. The special telecommunications service (STS), the domestic intelligence service (SRI) and the National Cybersecurity Directorate (DNSC) are all involved in the investigation.

Romania has therefore not lost its land registry data, or at least not entirely. What failed instead was the access infrastructure through which authorities, notaries, banks and citizens reach that data and process new transactions. For those handling legal transactions, this distinction offers little comfort, since the system remains just as unreachable either way. A register that is intact but cannot be securely queried or updated is, in practice, useless.

AI Was Going to Replace Us, But Then Came the Invoice

You might be interested AI Was Going to Replace Us, But Then Came the Invoice

A Long-Known Flaw Opened the Door

So far, what is known about the technical method rests largely on statements from ByteToBreach and from the DNSC. ByteToBreach maintains that no unknown security vulnerability was involved. Initial access is said to have come through a simple, long-known weakness in the systems, with further movement achieved by exploiting software misconfigurations and poorly separated subnetworks.

This technique is known as pivoting, whereby an attacker uses one compromised system as a launching point to reach further into a network. Careful segmentation of subnetworks is meant to stop an intruder who has breached a single system from spreading across an entire infrastructure. In Romania's case, that separation failed.

DNSC head Dan Cimpean described ByteToBreach as a financially motivated actor, likely of Algerian origin, who specializes in initial access, data theft and extortion. Whether the actor is a lone individual or part of a group remains unclear, though ByteToBreach claims to be acting alone. There is, so far, no evidence pointing to a state-directed operation.

Frozen Registry, Frozen Deals

Without current land registry extracts, notaries cannot notarize property sales. Banks cannot fully secure mortgages, ownership transfers cannot be recorded, and cadastral applications cannot be processed. Even procedures already under way have been left on hold.

The outage could not have come at a worse time for the market. The reduced VAT rate of 9% for certain new apartments is set to expire on 1 August and rise to 21%, and buyers and developers who had hoped to finalize contracts by 31 July were unable to complete the necessary steps in time. Several parties in Romania are therefore calling for the deadline for the reduced VAT rate to be extended. Prime Minister Bolojan has backed the idea, arguing that those affected should not be financially penalized for the failure of a state system.

Prime Minister Ilie Bolojan has called for the reduced VAT rate to be extended for buyers caught out by the outage. Photo: Fabian Sommer/dpa/picture alliance via Getty Images

A Cautious Path Back Online

The compromised applications are now being migrated to Romania's government cloud, where they will be checked for vulnerabilities, malware and data integrity. A premature restart could hand the attacker renewed access or reactivate manipulated components, so services are being brought back online only gradually, following a full security review.

According to the latest government statements, migration of the application that accesses the land registry database was in its final phase as of 23 July, after which STS and other relevant agencies were to review the new infrastructure. Bolojan expects ANCPI to resume operations gradually over the coming week, though there is not yet a binding date for the full restoration of all services.

The Fragility Behind Digital Government

The case illustrates just how exposed an administration becomes when its central legal processes depend on a handful of digital systems. The land registry is the state's guarantee of ownership, credit and investment, so even though the entries themselves appear to have survived intact, the attack showed that the access layer alone, once it fails, can be enough to block an entire market. Digitalization offers real advantages over paper-based systems, but just as paper records demand rigorous safeguards, from separately stored copies to fire protection, IT security allows no room for negligence either.

What matters, then, is not only maintaining regular backup copies stored separately from the live system, but also closing identified security vulnerabilities promptly. Properly segmented networks are just as essential a safeguard as robust procedures for restoring compromised data quickly. Romania, fortunately, appears not to have lost its land registry, but it did lose the ability to work with its own data for over a week. That warning shot deserves to be heeded across the rest of Europe as well.

WhatsApp Tackles Its Phone Number Problem with Usernames

You might be interested WhatsApp Tackles Its Phone Number Problem with Usernames