< Back to all clusters
[TECHNOLOGY] · Romania · 6 sources

started · updated

Romania's land registry crippled by cyber attack

On 14 July 2026 a hacker using the alias “ByteToBreach” breached the National Agency for Cadastre and Real Estate Publicity (ANCPI) by exploiting compromised credentials and outdated Windows XP servers. The attacker issued a deletion command that erased the entire e‑Terra property database and disabled the agency’s email system.

The outage halted Romania’s real‑estate market: notaries could not issue ownership certificates, register mortgages or finalize sales contracts, and banks were unable to process mortgage loans. The disruption came just days before a scheduled VAT increase on new homes that was to take effect on 1 August 2026, magnifying economic pressure on buyers and developers.

Romanian authorities confirmed on 16 July 2026 that the incident was a cyber attack. ANCPI said its core databases were not destroyed and that data had not been permanently lost. The government has begun rebuilding the affected infrastructure, migrating applications to a government‑run cloud and verifying data integrity, while the stolen data were offered for sale on dark‑web forums.

Despite multi‑billion‑lei cybersecurity budgets allocated to the national intelligence service (SRI) and other agencies, the attack succeeded using simple credential theft, highlighting lingering vulnerabilities in critical state IT systems.

Entities

ByteToBreach · National Agency for Cadastre and Real Estate Publicity (ANCPI) · National Agency for Cadastre and Real Estate Registration (ANCPI) · Romania · Romanian Government

Claims

What the coverage asserts, and how many sources carry each claim.