Hacker Wipes Romania's Entire Land Registry Database After Failed Extortion

Original: Hacker wipes Romania's land registry database

Why This Matters

Nation-state and criminal attacks on land registry infrastructure highlight critical vulnerabilities in government data systems globally.

A hacker breached Romania's ANCPI cadastre agency, wiped its entire land registry database and backups after a failed extortion attempt. The incident, which became public on July 14, 2026, halted Romania's real-estate market for over a week, taking official apps, websites, and email servers offline.

A hacker identified by security firm KELA as Zakaria Mahdjoub, from Oran, Algeria, breached Romania's National Agency for Cadastre and Real Estate Advertising (ANCPI) using valid credentials. After mapping internal systems and failing to extort the agency, the attacker wiped both primary systems and backups. The incident became public on July 14, 2026, when data deletion began. A day later, stolen data — including employee credentials, internal documents, and IT network details — was posted for sale on a hacking forum under the account ByteToBreach, a threat actor also linked to a breach of Sweden's e-government portal earlier in 2026. The attack brought Romania's real-estate market to a standstill: notaries could not record new transactions, and citizens were unable to obtain proof of ownership or land records. ANCPI's email servers were also taken offline. Officials subsequently restored their website and announced they are rebuilding the agency's entire network from scratch. Despite the attacker's claims of deleting all backups, ANCPI appears to have retained an offline copy. Romania joins Poland, Slovakia, Greece, Morocco, Russia, and Ukraine as countries whose land registry agencies have been hacked in the past three years.

Source

news.risky.biz — Read original →