Cyberattack in Eastern Europe

Hacker Wipes Entire European Government Database

Hacker, Romania land registry database cyberattack, hacker wipes government property database, Romania, Romania cyberattack, land registry database, government database hack, Database, Cyberattack
Facebook
X
LinkedIn
Reddit
WhatsApp

Following a failed extortion attempt, a hacker has deleted Romania’s entire land registry database. The incident has brought tens of thousands of real estate transactions to a standstill.

Following an unsuccessful extortion attempt, a cybercriminal has wiped the entire database of Romania’s National Agency for Cadastre and Land Registration (ANCPI). The attacker allegedly gained access to the system using valid credentials and stole internal documents, employee data, and central land registry records before destroying the primary data stored on the agency’s servers.

Ad

The massive data loss has brought Romania’s real estate market to a standstill, as property transactions can no longer be documented or verified nationwide. Romania records an average of between 150,000 and 170,000 residential property sales each year. Notary Ana Stan described the immediate impact on day-to-day digital infrastructure:

“I am a notary. Since Tuesday, I have been unable to issue a land registry extract, certify a sale, or register a mortgage.”

Ana Stan, Notary

Ad

Infrastructure Recovery Relies on Offline Backups

ANCPI initially described the widespread system outage on its official website as a routine technical issue. The agency shortly afterward acknowledged that the disruption was the result of a targeted cyberattack.

The agency is now rebuilding its entire government network from the ground up. According to government officials, the institution has physically isolated offline backups of the deleted datasets stored at multiple redundant locations. This security architecture enables the systems to be gradually restored, even though the attacker claimed on the dark web to have also disrupted the backup replication process.

Security Analysts Identify Suspected Attacker

The threat actor operates online under the pseudonym ByteToBreach. Cybersecurity company KELA analyzed the attacker’s infrastructure and identified the suspected operator behind the campaign. According to the analysis, the individual is Zakaria Mahdjoub, who is based in Oran, Algeria.

The attacker’s network has been linked not only to the latest incident in Romania but also to previous intrusions targeting Sweden’s e-government portal and government registries across Eastern Europe, including Slovakia, Ukraine, Poland, and Lithuania.

(ll)

Ad

Artikel zu diesem Thema

Weitere Artikel