A Hacker Stole Romania’s Entire Land Registry Database — Then Deleted It
Key Points
- A hacker breached Romania’s land registry agency, failed to extort payment, and then allegedly deleted the stolen data, including critical land registry records.
- The attack has severely disrupted Romania’s real estate sector, preventing property transactions and access to land records while officials work to restore systems from offline backups.
- IANS Faculty say the incident highlights the need to plan for destructive retaliation after failed extortion attempts, with experts emphasizing strong backups, recovery testing, and business continuity preparedness.
A Hacker Stole Romania’s Entire Land Registry Database — Then Deleted It
Cyber extortion campaigns usually follow a simple playbook: steal data, demand cash, and repeat. But after a hacker breached Romania’s land registry database and failed to secure a payout for the stolen files, the familiar cycle took a destructive turn: the attacker allegedly deleted the data.
The attack began when a threat actor used stolen credentials to gain unauthorized access into Romania’s National Agency for Cadastre and Real Estate Advertising (ANCPI). Shortly after, a hacker using the name ByteToBreach took credit.
“The official government website announced a shutdown of IT systems due to ‘technical problems,’ but this is a bit of an understatement. An offer of assistance was made, but without insistence or pressure,” the attacker wrote in an announcement posted to a hacking forum.
As days passed and the ANCPI’s system was still inaccessible, the institution admitted on July 15 that it was dealing with “the largest technical disruption in the institution’s history.”
When the agency reportedly did not comply with ByteToBreach’s extortion demands, the hacker deleted all the stolen data -- including employee credentials, internal documents, and all land registry data.
Without database access, Romania’s real estate industry has been completely frozen. Notaries cannot record new transactions, citizens cannot obtain land records, and the country’s active property market, which handles at least 150,000 sales annually, has come to a complete standstill.
Romania’s leading cybersecurity agency, the National Cyber Security Directorate (DNSC), stated it had previously warned ANCPI about its poor security hygiene.
In an interview with Romania’s G4Media, DNSC director Dan Cîmpean stated “it wasn’t a very complex attack,” and added that the hacker exploited vulnerabilities that the DNSC had instructed the ANCPI to patch.
Romanian officials stated that they are continuing efforts to restore services, including migrating applications over to a government cloud platform. But the ANCPI also stated that all impacted systems will remain isolated until each security concern has been addressed.
Officials have restored the ANCPI’s website and appear to be rebuilding the entire network from scratch using an offline backup copy of the wiped data.
Big Picture
This incident highlights a broader lesson: organizations should prepare responses for attacks an adversary claims to be conducting, while also accounting for any further damage the attacker could cause with the access already gained.
"We are seeing increasing numbers of extortion-only attacks, where threat actors extort victims, rather than wholesale data encryption seen in ransomware attacks. This is one example where the threat actor took destructive action after negotiations failed.” Jake Williams, IANS Faculty.
The ANCPI has been paralyzed for a week. But very few organizations could endure such a prolonged shutdown without significant business consequences.
"Governments don't go out of business because one process is broken for a few months; citizens typically bear the cost and frustration. But companies are not typically able to go months without serving customers. Immutable backups, and proper restoration testing including speed of recovery are critical.” Guillaume Ross, IANS Faculty.
Extortion only works when victims are operational enough to meet an attacker’s demands. But, organizations should still ensure their business continuity and disaster recovery plans address the possibility that ignored demands could ignite destructive retaliation.
This is a great case study in why organizations must take these threats of access seriously. There are obvious business continuity problems ongoing here and disaster recovery efforts are certainly slower than any recovery time objective (RTO) published in the organization. Leaders should be asking, ‘If this were my org, would we meet our RTOs?’ The answer is probably not.” Jake Williams, IANS Faculty.
Resilience is becoming just as important as prevention. The organizations that recover quickly, and have rehearsed that recovery before a crisis, will often fare far better than those focused solely on keeping attackers out." Lisa Perdelwitz, IANS Faculty.
IANS Faculty Recommendations
- Map out a response for the worst-case scenario: Assume threat actors may delete systems or data if extortion demands fail. Incident response and business continuity plans should address data destruction, as well as encryption and data theft scenarios.
- Test recovery against business objectives: Regularly validate that critical systems can be restored within published recovery time objectives (RTOs). Offline or immutable backups are only effective if organizations can recover fast enough to maintain business operations.
- Treat persistent access claims as credible until proven otherwise: Even when extortion groups claim they still have network access after an incident, investigate and validate those claims before dismissing them. Prioritize credential resets, access reviews and threat hunting to confirm attackers have been fully removed.
- Invest in immutable backups and recovery exercises: Maintain immutable backups for critical systems and routinely test full restoration workflows, including recovery speed, to ensure the organization can quickly resume operations after a destructive attack.
Authors & Contributors
Emily Dempsey, Author - Security Reporter, IANS News
Although reasonable efforts will be made to ensure the completeness and accuracy of the information contained in our News & blog posts, no liability can be accepted by IANS or our Faculty members for the results of any actions taken by individuals or firms in connection with such information, opinions, or advice.