Romania’s Land Registry Vanishes: How One Hacker Halted a Nation’s Property Market

A hacker using valid credentials erased Romania's full land registry in July 2026, halting property deals nationwide. The attacker, identified as ByteToBreach, later apologized but offered the data for sale. Recovery efforts continue as officials rebuild systems from scratch. This incident highlights persistent vulnerabilities in government databases.
Romania’s Land Registry Vanishes: How One Hacker Halted a Nation’s Property Market
Written by Sara Donnelly

Romania woke up to a real estate market in free fall last week. Its entire national land registry system sat offline. Property deals froze. Notaries stared at blank screens. Citizens seeking proof of ownership found only error messages.

The culprit? A single intruder who slipped in with legitimate credentials. He mapped the networks at the National Agency for Cadastre and Real Estate Advertising, known as ANCPI. Then he erased the core database. Backups too. Or so he claimed.

But the story runs deeper than one wiped server. It exposes cracks in how governments guard foundational records. And it fits a pattern now repeating across Europe.

The disruption began July 14, 2026. ANCPI first described it as a major technical incident. Hours later the agency confirmed a cyber attack. Its flagship e-Terra platform remained unreachable for days. Email systems went dark alongside it. Risky Business first detailed how the attacker gained entry through valid credentials, conducted reconnaissance, and then triggered the deletions after an extortion bid failed.

Real estate transactions ground to a halt. Without access to cadastral data, buyers could not verify titles. Sellers could not transfer ownership. The backlog threatened to stretch for weeks. Officials later announced they would rebuild the entire network from scratch. They pointed to an offline copy that might spare the country from months of chaos.

The perpetrator surfaced on a well-known hacking forum under the handle ByteToBreach. He posted samples of stolen material the next day. Employee credentials. Internal documents. Maps of the agency’s IT layout. News4Hackers reported the actor also advertised citizen information, copies of internal databases, and even snapshots from ANCPI’s GitLab servers containing source code. He threw in a version of his own ransomware for good measure.

Security researchers had tracked ByteToBreach for months. The firm KELA published a profile on him in December 2025. It suggested ties to Algeria. After the Romania breach KELA updated its analysis and identified the individual as Zakaria Mahdjoub from Oran. The same operator hit Sweden’s e-government portal earlier this year along with dozens of other government bodies and companies.

His methods follow a familiar script. Exploit weaknesses in cloud setups or corporate perimeters. Reuse credentials harvested through phishing or infostealer malware. Probe for misconfigurations. Sometimes brute force. In this case the entry point traced back to a vulnerability known since 2021.

Then came the twist. The hacker issued an apology. In messages obtained by Romanian outlet Euronews he told citizens and the ANCPI IT team he regretted the disruption. “Îmi pare rău pentru problemele pe care le-am cauzat pentru cetățeni și pentru echipa IT care lucrează acum din greu la ANCPI,” he wrote. He insisted he does not sell the data to just anyone. “Nu vând aceste date chiar oricui.” He dismissed rumors of a 10 million euro ransom demand. “Oricărui om întreg la minte i-ar fi rușine să ceară un astfel de preț,” he added. These things get discussed only between relevant parties.

Yet the data appeared for sale anyway. Screenshots shared by the actor served as proof of access. KELA noted that ByteToBreach’s past claims often checked out. This time the agency pushed back hard. ANCPI stated repeatedly that no citizen data had been compromised. Its systems held firm on that line even as investigators from the Romanian National Cyber Security Directorate, or DNSC, dug in.

DNSC director Dan Cîmpean characterized the attacker as financially motivated rather than state-sponsored. He described ByteToBreach as an access broker skilled in initial entry and data theft. Officials urged organizations not to pay ransoms. Such payments risk feeding wallets tied to EU sanctions lists.

Romania now joins a growing list. Poland. Slovakia. Greece. Morocco. Russia. Ukraine. Each saw its land or property registry targeted in the past three years. The motives differ. Some attackers sought cash. Others aimed to sow confusion. The common thread remains the same. These databases sit at the heart of economic activity. Disrupt them and entire sectors seize up.

Analysts see a wider shift. Public sector organizations face rising pressure. Projections from years past warned that most governments would encounter ransomware or extortion attempts by now. The forecast has proven accurate. Slovakia’s registry went dark after a ransomware strike in 2025. Greek cadastral systems suffered similar hits. Lithuania reported the download of more than 600,000 real estate records in May 2026.

Romania’s case stands out for its scale and its simplicity. No sophisticated zero-day chain. No nation-state malware. Just stolen or guessed credentials and the nerve to pull the trigger on deletion. The intruder embedded his ransomware inside the environment before leaving. That detail sent a chill through security teams watching from afar.

Rebuilding will test ANCPI’s resilience. The agency has restored its public website with a notice about the rebuild. Services remain limited. Teams work under tight security conditions. One senior partner at cybersecurity firm Veridio offered a blunt assessment. Systems that grow dependent on digital platforms need strong contingency plans. Reliability hangs in the balance.

The apology adds another layer. Hackers rarely express remorse in public. This one claimed respect for the IT staff now scrambling to recover. He framed his actions in financial terms yet denied seeking an outsized payout. Whether the statements reflect genuine regret or an attempt to soften his image remains unclear. The data still circulates on underground markets.

Investigations continue. Romanian authorities work with international partners to trace the actor. Mahdjoub’s location in Algeria complicates extradition. Past breaches linked to him produced verifiable leaks. That track record lends weight to current claims even if ANCPI disputes them.

For the real estate industry the incident delivers a harsh lesson. Paper records vanished years ago. Digital systems now hold the keys to ownership. When those systems fail the economy feels it immediately. Notaries cannot certify deals. Banks hesitate to issue mortgages. Courts lose reference points for disputes.

Broader questions linger about backup strategies. The hacker boasted of destroying offsite copies. ANCPI’s ability to fall back on an offline version prevented total collapse. Many governments still rely on aging infrastructure that mixes legacy databases with newer cloud elements. That mix creates blind spots.

ByteToBreach’s tactics highlight the human factor too. Credential theft remains the easiest door to open. Phishing campaigns. Compromised contractors. Reused passwords across systems. Once inside, lateral movement often meets little resistance. Romania’s networks apparently allowed broad mapping before the wipe began.

European officials have taken notice. Discussions about shared threat intelligence have gained urgency. Some countries now audit their cadastral platforms with fresh eyes. The risk extends beyond Eastern Europe. Any nation that digitizes core property records without matching defenses invites the same outcome.

So far no evidence points to state involvement. DNSC’s assessment aligns with that view. Financial gain drove the attack. The sale of data on hacking forums follows a predictable path. Buyers might include identity thieves, rival brokers, or even foreign intelligence shopping for open-source information.

The ANCPI rebuild will take time. Full restoration of e-Terra could stretch beyond initial estimates. In the interim citizens turn to manual processes that recall an earlier era. Paper forms. In-person visits. Long lines. The contrast with modern expectations could hardly be sharper.

One detail stands out amid the technical reports. The hacker said he respects the IT employees working overtime. That rare acknowledgment humanizes a story otherwise filled with cold code and deleted records. It does not undo the damage. But it hints at the strange mix of bravado and reflection sometimes found in underground communities.

Romania has faced cyber challenges before. This episode feels different. It struck at the foundation of private property itself. In a country still shaped by post-communist reforms, land records carry extra weight. Their sudden absence rattled confidence at multiple levels.

Security firms continue to monitor the leaked material. Any confirmed dumps could reveal more about ANCPI’s internal architecture. That information might help defenders elsewhere. It could also aid the next attacker looking for similar weaknesses.

For now the agency focuses on recovery. Investigators chase leads on the intruder. The real estate market waits for systems to return. And ByteToBreach moves on to the next target. The cycle repeats. Each breach teaches new lessons. Whether governments absorb them fast enough will determine who holds the advantage in coming years.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us