Hacker Deletes Entire Romanian Real Estate Registry

A severe cyberattack has wiped out Romania’s entire electronic cadastre and property register, paralyzing the nation’s real estate market for more than a week, according to reports by Risky Business and local media. The threat actor, operating under the alias ByteToBreach in DarkWeb forums, targeted the National Agency for Cadastre and Land Registration (ANCPI), initially demanding a ransom before erasing the databases entirely after the extortion attempt failed.

How the ANCPI Cyberattack Paralyzed Romania’s Real Estate Market

Without access to the digital cadastre and land register, notaries cannot register new property transactions, and citizens are unable to secure ownership certificates or other vital documents, according to industry reports. The disruption hits the market during a high-volume period, as Romania typically records between 150,000 and 170,000 residential property sales annually, according to Risky Business figures. The incident also coincides with the final days before a tax threshold shift, as the tax rate on residential purchases is scheduled to rise from 9 percent to 21 percent on August 1.

Government Response and Cybersecurity Criticisms

The official government website initially downplayed the severity of the incident by announcing a suspension of IT systems due to “technical problems,” before ANCPI later acknowledged the cyberattack. Local publication Ziarul Financiar criticized the response, describing the event as the result of a model where cybersecurity is treated as something secondary. Meanwhile, the National Directorate for Cybersecurity (DNSC) stated that it had previously warned ANCPI regarding weak cyber hygiene. Over the past 20 years, out of a significant sum spent on digitizing the cadastre, only a tiny fraction was invested in cybersecurity, according to public reports.

Identity of the Threat Actor Behind ByteToBreach

The hacker responsible for the breach is known in the DarkWeb as ByteToBreach, according to Israeli cybersecurity firm KELA, which identified the individual behind the account as Zakaria Maxdjub, residing in Oran, Algeria. KELA described the suspect as an experienced cybercriminal who sells sensitive global data from airlines, banks, and governments. The threat actor claimed in a hacker forum post to hold data collected from various databases through ANCPI networks, alongside a copy of GitLab servers containing source code for systems such as E-terra and RENNS. Security analysts suggest the same actor has targeted government registries in Slovakia, Ukraine, Poland, and Lithuania.

Data Recovery and Mitigation Efforts

Despite the total deletion of the active databases, ANCPI holds backups and has begun the gradual, phased restoration of maps and registers, according to official updates.

Frequently Asked Questions

>

What systems were affected by the cyberattack in Romania?

According to ANCPI and cybersecurity reports, the attack targeted the National Agency for Cadastre and Land Registration, wiping out databases including property registries and source code from servers containing systems like E-terra and RENNS.

Who is accused of carrying out the attack?

Israeli cybersecurity firm KELA identified the operator behind the DarkWeb alias ByteToBreach as Zakaria Maxdjub, based in Oran, Algeria.

Are the deleted property records lost forever?

No. According to official updates, ANCPI possesses backup copies of the deleted data and is currently working on restoring the cadastral maps and registers in a phased process.

Support independent and investigative journalism by exploring more reports or contributing to our ongoing coverage.

Leave a Comment