RO EN
← Back to Blog Romania Land Registry Hit by Major Ransomware Attack

Romania Land Registry Hit by Major Ransomware Attack

Published on: 30.07.2026  ·  Views: 237

Inside Romania's Worst Cyberattack: How Ransomware Paralyzed the National Land Registry


On Tuesday, July 14, 2026, before most Romanians had even checked their morning email, the system that records ownership of nearly every piece of property in the country quietly collapsed. What officials first described as a "technical incident" turned out to be a full-blown ransomware attack that knocked out the entire digital infrastructure of Romania's National Agency for Cadastre and Land Registration (ANCPI). Two weeks later, thousands of real-estate transactions remain frozen, notaries can't authenticate deeds, and the country is grappling with what authorities have called the most severe technical incident in the agency's history.

What Actually Happened

It began early on Tuesday, July 14, 2026. ANCPI's IT systems suddenly went offline — including the agency's official email addresses. The initial statement was cautious: a "major technical incident," with no further detail offered.

By the next day, Wednesday, July 15, the tone shifted. ANCPI publicly confirmed it was dealing with a cyberattack — the most extensive technical outage in the agency's history — while insisting that the data it manages remained secure, at least at that point.

Reality proved more complicated. Around the same time, a threat actor going by ByteToBreach surfaced on a cybercrime forum specializing in stolen-data trading, publicly claiming access to databases containing information on Romanian citizens and to a copy of the agency's GitLab servers — effectively the source code for the e-Terra and RENNS applications. The attacker also claimed to have deployed ransomware and deleted the system's backup copies.

It wasn't until July 27 that the Romanian government officially confirmed the exact nature of the attack in a press statement: a ransomware attack that encrypted and partially wiped the virtualization infrastructure hosting ANCPI's applications. The one piece of good news, according to authorities, is that the central cadastral database — the record of property ownership and real estate rights — appears untouched, with no evidence so far that attackers accessed it.


Timeline of an Unprecedented Shutdown

By the time of this report, the outage has already stretched past two weeks — an eternity for a system that notaries, banks, real-estate developers, and ordinary citizens rely on daily just to sell an apartment or register an inheritance.


Technical Details: What Was Actually Compromised

Based on officially confirmed information and press reporting, the technical picture looks like this:


A detail worth flagging for any security professional: even if the central database appears untouched so far, the fact that attackers managed to encrypt and delete virtualization infrastructure points to a deep, system-level compromise — not a quickly-contained phishing incident.


Impact on Citizens and the Real-Estate Market

"The land registry system is down" might sound abstract from the outside. In practice, the effects were immediate and painful:


For an ordinary citizen trying to sell an inherited apartment or close on a mortgage, the shutdown meant weeks of uncertainty, missed deadlines, and in many cases direct financial losses — contractual penalties, extra interest charges, withdrawn purchase offers.


"One citizen waiting to sell an apartment inherited from their parents reportedly lost the buyer, who couldn't wait any longer for the land registry extract to be issued." — a scenario echoed across multiple local reports as a typical consequence of the shutdown.
"A cybersecurity specialist might sum it up plainly: when critical infrastructure is fully digitized with no working fallback plan, a single point of failure can bring an entire country's transactions to a standstill." — an illustrative observation typical of expert commentary on the incident.

Official Reactions

The official response visibly shifted from downplaying the incident to transparency forced by the facts.

ANCPI moved from the cautious label of "major technical incident" to publicly acknowledging the cyberattack, while consistently maintaining that the central database remained unaffected.

DNSC, Romania's National Cybersecurity Directorate, became directly involved in the technical investigation under procedures applicable to public institutions, coordinating the isolation of affected infrastructure to prevent further spread.

The Romanian government, in its July 27 statement, publicly took ownership of the central coordination of the institutional response, acknowledging it could not yet provide a firm restoration date — precisely to avoid "making promises that technical conditions might force us to postpone."

Authorities are advising anyone who used the ePay.ancpi.ro payment platform to change their password, especially if reused elsewhere, and warning against phone calls or emails requesting personal or financial data — no state institution ever requests such information through these channels.

According to press reports, the attack was part of a broader wave of cyber incidents that hit several Romanian public systems in the same period, including the Ghișeul.ro payment platform and a ministry procurement application.


What Does This Attack Mean for Romania? (GDPR / NIS2 Analysis)

Beyond the immediate disruption, the ANCPI incident raises structural questions about Romania's regulatory framework.

From a GDPR perspective: ANCPI manages sensitive personal data — names, addresses, national ID numbers, property records, and indirectly, citizens' financial situations. Even though the agency maintains the central database wasn't compromised, an attacker publicly claiming to hold such data triggers clear theoretical obligations:


From a NIS2 perspective: The NIS2 Directive, transposed into national law, classifies public authorities managing critical infrastructure — and a national land registry clearly qualifies — as essential entities, subject to heightened obligations around:


The fact that virtualization infrastructure could be partially encrypted and deleted, and that the system remained unavailable for over two weeks, suggests that backup and recovery plans did not perform at the level expected of an essential entity under NIS2. It's precisely the scenario the directive aims to prevent through resilience and testing requirements.

The analytical takeaway: this incident isn't just a story about a successful attack. It's a nationwide stress test of how Romania actually implements its own legal obligations around data protection and cyber resilience — and judging by the length of the outage, the test exposed real vulnerabilities, not just theoretical ones.


Conclusion

The ANCPI cyberattack isn't just a technical headline for cybersecurity specialists. It's the story of thousands of ordinary people — buyers, sellers, heirs, entrepreneurs — suddenly blocked by an invisible but essential system. It's also a painful lesson about the cost of digitization without a matching resilience strategy: when an entire institution's workflow depends on a single IT system with no functioning fallback, one successful attack can paralyze an entire country for weeks. Romania now has, in black and white, a case study in what happens without a robust cyber-resilience plan — and how expensive, in time and public trust, every day of downtime turns out to be.


What do you think — are Romania's public institutions prepared enough for attacks like this? Share this article if you find it relevant — the more people understand what's at stake, the greater the pressure for real transparency and investment in cybersecurity.


Share: Facebook LinkedIn