Skip to content
Tech News
← Back to articles

Hacker wipes Romania's land registry database

read original more articles
Why This Matters

The hacking of Romania's land registry database highlights the increasing sophistication and impact of cyberattacks on critical national infrastructure, disrupting essential services and exposing sensitive data. It underscores the urgent need for improved cybersecurity measures across government agencies to protect vital systems from similar threats in the future.

Key Takeaways

In other news: Graykey maker sues former employee for leaking exploit; Hugging Face was hacked using AI; unauth RCE finally found in WordPress.

This newsletter is brought to you by Thinkst , the makers of the much-loved Thinkst Canary . You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed . You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here .

A hacker has breached Romania's cadastre agency and wiped the country's entire land registry database following a failed extortion attempt.

The hack has brought Romania's entire real-estate market to a standstill as official apps and websites have been offline for a week. Notaries can't record new transactions while citizens can't obtain proof of ownership or detailed land records.

Email servers at the National Agency for Cadastre and Real Estate Advertising (Agenția Națională de Cadastru și Publicitate Imobiliară, or ANCPI) were also down as part of the incident.

Sources told Risky Business that the hacker entered using valid credentials, mapped internal systems, and wiped systems and backups after failing to extort the agency.

The incident became public on July 14 as the hacker started deleting data. A day later, some of ANCPI's stolen data was put up for sale on a known hacking forum. The posted data included employee credentials, internal documents, and details on the agency's IT network.

Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.

The stolen data was posted online by an account with the name ByteToBreach, a known hacker who also breached Sweden's e-government portal this year, and many other government agencies and high-profile companies over the past year.

Security firm KELA published a profile on ByteToBreach last December and hinted they might be located in Algeria, but since the ANCPI hack has updated the post and outright doxxed the hacker as Zakaria Mahdjoub, an individual from Oran, Algeria.

... continue reading