# Romania PNRR implementation and ANCPI cyberattack

> Live situation record from CLSTR: https://clstr.news/situations/romania-eu-pnrr-funding-implementation
> Updated: 2026-08-11T08:43:35.000Z. Sources: 113. Developments: 17.

Romania has utilized significant tranches of the European Union’s National Recovery and Resilience Plan (PNRR) to fund various modernization projects, including upgrading the national railway fleet, digitalizing the National Anti-Corruption Directorate (DNA), and modernizing hospital infrastructure.

However, these digital goals faced a major setback in July 2026 when the National Agency for Cadastre and Real Estate Publicity (ANCPI) was targeted by a massive ransomware attack. Attributed to a hacker known as ‘ByteToBreach’, the breach involved compromised credentials and outdated servers, leading to the deletion of digital land-registry databases and the suspension of the e-Terra platform. This outage paralyzed the real-estate market, preventing notaries from certifying sales and banks from processing mortgages.

Following the attack, the agency migrated its applications to a government-run cloud. In early August, specialists from the Special Telecommunications Service (STS), the National Cybersecurity Directorate (DNSC), and the firm Cyberint conducted security, functionality, and performance evaluations to remedy identified vulnerabilities. To prevent future incidents, ANCPI planned an investment of approximately €5 million in new IT-security infrastructure.

As of August 11, 2026, the e-Terra application has commenced a phased restart. Initial access is restricted to ANCPI staff, cadastre office personnel, and public notaries to prioritize the processing of approximately 94,000 pending requests accumulated during the outage. On August 12, access expanded to include authorized surveyors, judicial technical experts, and bailiffs. While e-Terra is functional, other platforms like Geoportal and MyEterra remain offline. Authorities have confirmed the integrity of cadastral records, stating there is ‘no evidence of data theft’. Currently, users must use payment orders or cashiers, as card payments are unavailable.

## Claims

- The attacker deleted hundreds of thousands of files, including land‑registry contracts and notarial records. (disputed by 3 sources)
- The central cadastral database remained intact and was not accessed by the attackers. (disputed by 3 sources)
- Approximately 94,000 requests were pending at the time of the incident. (corroborated by 7 sources)
- Access to the application was expanded on August 12 to include authorized cadastral workers, technical-judicial experts, and bailiffs. (corroborated by 7 sources)
- The attack halted property transactions, froze mortgage approvals and prevented notaries from accessing records. (corroborated by 6 sources)
- A ransomware attack on the National Cadastre and Real‑Estate Publicity Agency (ANCPI) began on 14 July 2026 and disabled its systems. (corroborated by 6 sources)
- The government migrated the e‑Terra application to the Government Cloud and is conducting final security, functionality and performance tests. (corroborated by 6 sources)
- On the first day of resumption, August 11, 2026, 24,695 requests were registered. (corroborated by 6 sources)
- Payments in e-Terra can currently only be made via payment order or at the cashier, not by card. (corroborated by 6 sources)
- A hacker using the alias ByteToBreach carried out a ransomware attack on Romania's cadastre system. (corroborated by 5 sources)
- ANCPI confirmed the breach and is cooperating with the National Directorate for Cyber‑Security and KELA to restore services. (corroborated by 5 sources)
- The e-Terra application has resumed activity to recover delays accumulated during its downtime. (corroborated by 5 sources)
- Other ANCPI online platforms, such as Geoportal and MyEterra, will be restored in a subsequent phase. (corroborated by 5 sources)
- Independent testing of the e‑Terra system was performed by STS, DNSC and Cyberint. (corroborated by 4 sources)
- The testing has completed another evaluation round. (corroborated by 4 sources)
- A limited number of technical issues remain to be corrected before the e‑Terra application can be made public. (corroborated by 4 sources)
- Each correction will be validated through a new round of testing. (corroborated by 4 sources)
- Testing is conducted in a controlled environment to avoid post‑release issues. (corroborated by 4 sources)
- ANCPI and the Ministry of Development, Public Works and Administration have met with notaries and cadastral specialists to plan the resumption of e‑Terra operations. (corroborated by 4 sources)
- The e‑Terra system will be reinstated once all tests and technical validations are successfully completed. (corroborated by 4 sources)
- The government will issue a public update on the remediation status by Friday, 7 August 2026. (corroborated by 4 sources)
- The disruption occurred shortly before a VAT increase on new homes effective 1 August 2026, affecting many buyers and developers. (corroborated by 3 sources)
- The Romanian government refused to pay the ransom demanded by the hacker. (corroborated by 3 sources)
- Dan Cimpean, director of the DNSC, said the attacker acts as an “initial‑access broker”. (corroborated by 3 sources)
- ANCPI said its core databases were not destroyed and data had not been permanently lost. (corroborated by 2 sources)
- The breach exploited outdated Windows XP servers and compromised credentials. (corroborated by 2 sources)
- ANCPI allocated only 0.2 % of its budget to cyber‑defence before the attack. (corroborated by 2 sources)
- The attack caused an estimated daily economic loss of €60.75 million. (corroborated by 2 sources)
- The Romanian Senate passed a temporary exemption from the 1 % inheritance‑tax surcharge for cases impacted between 14 July and 30 September 2026. (corroborated by 2 sources)
- Romanian authorities confirmed on 16 July 2026 that the incident was a cyber attack. (single source)
- The National Penitentiary Administration suffered a ransomware attack on the night of 28‑29 July 2026, but essential prison operations continued. (single source)
- The prolonged cadastre outage created liquidity pressure on Romanian real‑estate agencies, with delayed transactions reported by RE/MAX. (single source)
- Latvia provided investigative assistance to Romania regarding the cadastre cyberattack. (single source)
- ANCPI spent a total of 68 million lei on system maintenance in recent years, including a 11.6 million‑lei contract for e‑Terra maintenance. (single source)
- The integrity of the cadastral and land registry records has been confirmed. (single source)

## Timeline

### 2026-08-11: ANCPI e-Terra application resumes activity after cyberattack

Romania's e-Terra cadastre application has resumed operations following a July 14 cyberattack. Access is being restored in stages to professionals, though a backlog of 94,000 requests remains.

23 sources. https://clstr.news/cluster/ancpi-to-restart-e-terra-platform-following-ransomware-attack

### 2026-08-05: ANCPI plans to relaunch Romania's e-Terra cadastral system after technical fixes

Romania's ANCPI says the e‑Terra cadastral system will reopen after independent testing by STS, DNSC and Cyberint corrects remaining technical issues; a public update is due by 7 Aug 2026.

5 sources. https://clstr.news/cluster/ancpi-plans-to-relaunch-romanias-e-terra-cadastral-system-after-technical-fixes

### 2026-08-05: Romanian Land Registry e‑Terra System Disabled by Cyberattack

Romania’s ANCPI e‑Terra system was knocked offline for 22 days due to weak passwords and unpatched software, while a global report finds cybercrime inflicts $10 k average losses per victim and up to $10.5 trn a

2 sources. https://clstr.news/cluster/romanian-land-registry-eterra-system-disabled-by-cyberattack

### 2026-08-03: Romania's ANCPI conducts new security tests on e‑Terra land registry system

Romania's ANCPI says the e‑Terra land‑registry app, offline after a July cyberattack, is undergoing a new round of security, functionality and performance tests by STS, DNSC and Cyberint; the system will be re‑

3 sources. https://clstr.news/cluster/romanias-ancpi-conducts-new-security-tests-on-eterra-land-registry-system

### 2026-07-29: Romania's Cadastre Agency recovers after ransomware attack

Romania's cadastre agency was hit by a ransomware attack on 14 July 2026, costing €60.75 million daily, prompting cloud migration, Senate tax relief, and nationwide cyber‑security measures.

20 sources. https://clstr.news/cluster/romanias-ancpi-ransomware-attack-stalls-realestate-transactions-and-presses-liquidity

### 2026-07-27: Romania’s cadastral system hack freezes property market

ByteToBreach ransomware attack on Romania’s cadastre system deleted files, stopped property deals and mortgages, and left the central database intact; the government refused ransom and recovery efforts areongo‑

14 sources. https://clstr.news/cluster/romanias-ancpi-hit-by-ransomware-attack-e-terra-services-offline

### 2026-07-25: Romania's land registry crippled by cyber attack

A hacker dubbed “ByteToBreach” breached ANCPI on 14 July 2026, deleting Romania’s e‑Terra property database and halting the real‑estate market; authorities say core data survive and are rebuilding the system.

6 sources. https://clstr.news/cluster/romanian-land-registry-erased-in-massive-cyberattack

### 2026-07-23: Romanian land registry hack freezes property market

Algerian‑linked hacker ByteToBreach erased Romania’s digital land‑registry on July 14, halting all property transactions and highlighting insufficient cyber‑security investment.

2 sources. https://clstr.news/cluster/romanian-land-registry-hack-freezes-property-market

### 2026-07-19: Romania's land registry crippled by cyberattack, halting property market

A ransomware‑style hack wiped Romania's land‑registry data, shutting ANCPI's online services for a week and halting property transactions ahead of a VAT increase, while authorities work to restore systems from

14 sources. https://clstr.news/cluster/romanias-cadastre-agency-hit-by-cyber-attack

### 2026-07-18: ANCPI cyberattack leaves cadastral services offline, data safe and recovery underway

ANCPI’s cyberattack shut down cadastral services; databases remain intact via backups, restoration is ongoing, and the outage threatens reduced‑VAT home‑buyer benefits.

21 sources. https://clstr.news/cluster/romanias-ancpi-cyberattack-stalls-property-registrations-threatens-reduced-vat

### 2026-07-15: Romania's cadastre system e‑Terra crippled by massive cyberattack

A major cyberattack disabled Romania's ANCPI e‑Terra system, halting real‑estate transactions and risking loss of reduced 9 % VAT for thousands of buyers; authorities investigate and a hacker claims data theft.

16 sources. https://clstr.news/cluster/romanias-mipe-cyber-attack-disrupts-pnrr-project-database

### 2026-07-13: Romanian interim health minister says NRRP hospitals to be finished by August

Romania's interim health minister Cseke Attila said five NRRP‑funded hospitals will be finished by August, two are in reception, and the Constanța emergency hospital will complete in spring after extra state‑c​

4 sources. https://clstr.news/cluster/romanian-interim-health-minister-says-nrrp-hospitals-to-be-finished-by-august

### 2026-07-09: Romania's Health Ministry allocates 162.5 million lei to PNRR hospital upgrades

Romania's Health Ministry has spent over 162.5 million lei on PNRR‑funded hospital upgrades and signed 35 contract amendments to extend and refine digital and infrastructure projects nationwide.

3 sources. https://clstr.news/cluster/romanias-health-ministry-allocates-1625-million-lei-to-pnrr-hospital-upgrades

### 2026-07-01: Romania's DNA completes €2.5 million PNRR digitalisation project

Romania's National Anti‑Corruption Directorate has finished a €2.5 million PNRR‑funded digitalisation project, upgrading IT hardware and software to modernise operations and boost data exchange with the justice

2 sources. https://clstr.news/cluster/romanias-dna-completes-25-million-pnrr-digitalisation-project

### 2026-06-29: CFR Călători advances Romanian rail modernization with new locomotive and 42 upgraded carriages

CFR Călători readied the modernised LEMA 006 locomotive and 42 upgraded passenger cars, part of a PNRR‑funded programme to modernise 139 Romanian rail vehicles.

2 sources. https://clstr.news/cluster/cfr-cltori-advances-romanian-rail-modernization-with-new-locomotive-and-42-upgraded-carriages

### 2026-06-24: CFR Călători adds 19 modernized locomotives under EU‑funded PNRR program

CFR Călători modernised 19 electric locomotives under the EU‑funded PNRR, spending €67 m on upgrades and €33 m on maintenance, boosting Romania's rail efficiency and heritage branding.

3 sources. https://clstr.news/cluster/cfr-cltori-completes-modernization-of-19-locomotives-under-the-pnrr-program

### 2026-06-23: Romania receives €2.25 billion EU grant under PNRR

Romania got €2.25 billion from the EU as the fourth PNRR payment, covering reforms in health, pensions, digitalisation and infrastructure, raising total receipts to over 60 % of its allocation.

23 sources. https://clstr.news/cluster/eu-approves-additional-528-million-for-moldovas-growth-plan

---
Cite as: Romania PNRR implementation and ANCPI cyberattack. CLSTR, https://clstr.news/situations/romania-eu-pnrr-funding-implementation
