< Back to situation

[REVISION HISTORY]

Romania PNRR rollout and cadastral cyberattack

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-07-26 11:12 UTC → 2026-07-26 23:21 UTC · added removed

In late June 2026 the EU released the fourth €2.251 billion tranche of Romania’s PNRR, bringing total receipts to about €13 billion for reforms in health, pensions, digital administration, forest management, decarbonisation and infrastructure. Key projects include modernising 19 electric locomotives, digitising the anti‑corruption directorate’s case‑management platform and completing five PNRR‑funded hospitals by August. A large‑scale cyber‑attack on the National Agency for Cadastre and Land Registration (ANCPI) began on 14 July 2026, crippling the e‑Terra e‑Terra/e‑Property platform and halting notarial, mortgage and land‑registry services. The attacker used stolen credentials, attacker, using the alias “ByteToBreach”, demanded ransom, and after the extortion failed claimed to have erased system backups, and later deleted the central land‑registry database and source code. Core Authorities confirmed that core legal databases remained intact and offline backups exist. no permanent data loss occurred; the breach exploited outdated Windows XP servers and compromised credentials. By 19 July the outage persisted for nearly a week, persisted, freezing thousands of property transactions just before a VAT increase on new homes (from 9 % to 21 % on 1 August) and a scheduled tax rise on 31 July. A notary confirmed the inability to issue extracts, certify sales or register mortgages. ANCPI’s director, Laurențiu Blaga, emphasized protecting data integrity, while the National Directorate for Cyber Security labeled the attack financially motivated and linked it to known software vulnerabilities. Recovery efforts, Recovery, coordinated by the Special Telecommunications Service and cybersecurity specialists, include involves migrating ANCPI applications to the Romanian government cloud, expected to finish mid‑week, followed by conducting integrity checks before service restoration. No new completion date has been set, and market uncertainty remains high. On rebuilding infrastructure. The migration was expected to finish mid‑week following the 23 July officials identified the hacker as the group “ByteToBreach”, allegedly identification of ByteToBreach (allegedly operating from Algeria. Director Dan Cîmpean described Algeria). The government stresses data‑integrity protection, while the breach as not technically complex and noted that low cybersecurity budget—€305 000 out of the €135 million spent on digitising the cadastre over two decades, only about €305 000 was allocated to cybersecurity despite prior warnings. digitisation—had been previously flagged.

Versions

  1. 2026-07-26 23:21 UTC Romania PNRR rollout and cadastral cyberattack
  2. 2026-07-26 11:12 UTC Romania PNRR rollout and cadastral cyberattack

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.