Romania’s National Agency for Cadastre and Land Registration (ANCPI) is investigating a cyberattack after a hacker allegedly gained unauthorized access to one of its systems, attempted to extort the agency, and later deleted a land registry database when the demand was not met. The incident temporarily disrupted access to property records, forcing the agency to restore the affected database from backups while investigators worked to determine the full scope of the breach.

 

 

According to information released by Romanian authorities, the attacker did not exploit a previously unknown software vulnerability. Instead, investigators believe the intrusion was carried out using compromised login credentials that provided access to the affected system. Once inside the network, the hacker allegedly contacted the agency and demanded money in exchange for leaving the database intact. Officials have not disclosed how much money was requested or whether any communication took place beyond the initial demand.

After the alleged extortion attempt failed, the attacker deleted the database, temporarily making land registry information unavailable. ANCPI said the affected system contains cadastral and property ownership records used by public institutions, notaries, surveyors, businesses, and property owners. Although the deletion disrupted access to the data, the agency said backup copies allowed administrators to recover the information and restore normal operations without permanent data loss.

Authorities have not said whether the attacker copied or exfiltrated any information before deleting the database. Investigators are currently examining system logs, authentication records, and other digital evidence to determine exactly what actions were performed after the compromised credentials were used. Officials have also not identified the individual responsible for the intrusion or indicated whether the attack was carried out by a lone hacker or a larger criminal group.

The investigation remains ongoing, and Romanian authorities have released a few technical details about the breach while forensic work continues. ANCPI said it has reported the incident to the appropriate authorities and is cooperating with the investigation. The agency is also reviewing its security procedures following the attack, but has not announced whether additional systems were affected or whether any arrests have been made in connection with the incident.

Leave a Reply