Hacker wipes European country’s entire land registry database, paralyzing real-estate market
One security firm has already doxxed the crook behind the cyberattack.

Image by Cybernews.
- A hacker deleted Romania's entire land registry database after a failed extortion attempt, paralyzing the real-estate market
- The attack halted all property transactions, preventing notaries from authenticating sales or registering mortgages nationwide
- It appears, though, that Romania's cadastre agency has had an offline copy of the wiped data
- Critics still point out that the perpetrator of the cyberattack had ample openings since the ANCPI hasn’t actually been investing much in cybersecurity.
Hackers can get very angry when they don’t get their way. That’s what happened in Romania when a crook wiped the country’s entire land registry database after an unsuccessful extortion attempt. Poor cyber hygiene didn't help, either.
First, the hacker breached Romania’s cadastre agency, the National Agency for Cadastre and Real Estate Advertising (ANCPI), posting on a hacking forum: “[RO] Thy arss shall be spanked, Romania! [ANCPI]”
“In addition to the data of Romanian citizens, from various databases collected through ANCPI networks, there is also a copy of the GitLab servers containing the source code of all their systems, such as Eterra, RENNS, as well as a version of my little ransomware program,” the announcement continued.
Real-estate market stands still
“The official government website announced a shutdown of IT systems due to ‘technical problems,’ but this is a bit of an understatement. An offer of assistance was made, but without insistence or pressure.”
Has your password leaked?
Indeed, the ANCPI initially claimed technical issues but had to admit it was facing a cyberattack. Today, no one can really access the institution’s systems.
And since the extortion didn’t work, the hacker – who seems to have entered the database using valid credentials – deleted all data they had stolen, including internal documents, employee credentials, and, of course, land registry data.
The hack has brought Romania’s entire real-estate market to a standstill, Risky Business points out.
Notaries cannot record new transactions while citizens can’t obtain proof of ownership or detailed land records. And Romania is no small fish: on average, between 150,000 and 170,000 residential real estate units are sold annually across the country.
The hacker whose dark web account is called ByteToBreach and who also breached Sweden's e-government portal earlier this year, has been doxxed.
One notary, Ana Stan, said online: “I am a notary. Since Tuesday, I cannot issue a land registry extract, I cannot authenticate a sale, I cannot register a mortgage.”
On the dark web, the hacker also boasted to have begun backup copies of stolen data in an attempt to prevent it from being restored.
However, Romanian officials have managed to at least restore the ANCPI’s website and post a message saying they were rebuilding the agency’s entire network from scratch. It appears that the agency has an offline copy of the wiped data.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
“Contrary to some information appearing in the public space, at the time of the incident, the ANCPI had several locations designated for storing backup copies, a measure that ensures redundancy and the possibility of data restoration in the event of cybersecurity incidents,” the press release says.
Attack could have been prevented
Still, the ANCPI’s alleged passivity in reacting to the breach has been quite heavily criticized in Romania.
Critics point out that the perpetrator of the cyberattack had ample openings since the ANCPI hasn’t actually been investing much in cybersecurity. A local outlet, Ziarul Financiar, even called the incident “the result of a model in which cyber defense is treated as an annex.”
The institution has reportedly spent €135 million ($154 million) on digitalization in the last 20 years, but only 0.2% of that amount, some €305,000 ($348,000, has been allocated to cybersecurity.
Romania’s dedicated cybersecurity body, the National Cyber Security Directorate (DNSC), also said it had warned the ANCPI about the issues with its poor cybersecurity hygiene.
You can never reduce the risk of a cyberattack to zero butI believe that many institutions, including the ANCPI, still have work to do in prevention, in strengthening the security of their own software,Irineu Darău
The agency’s director Dan Cîmpean even claimed that the cyberattack against the ANCPI wasn’t too complex and could definitely have been prevented. Plus, the DNSC explained, the hacker exploited “vulnerabilities that we had notified them about quite recently.”
Finally, Romania’s interim economy minister, Irineu Darău, told Digi24 that the ANCPI could have carried out much more intensive prevention work to prevent such attacks.
The conversation on this topic is live. Join in the discussion.
“Each institution and the management of each institution must treat cybersecurity as priority zero. You can never reduce the risk of a cyberattack to zero butI believe that many institutions, including the ANCPI, still have work to do in prevention, in strengthening the security of their own software,” said Darău.
For the government, timing is pretty sensitive. The cyberattack hit the ANCPI precisely in the last weeks when homes can still be purchased with a 9% VAT. The tax for new homes increases to 21% from August 1st onwards.
Hacker now named
At least the hacker whose dark web account is called ByteToBreach and who also breached Sweden's e-government portal earlier this year, has been doxxed.
Cybersecurity firm KELA now says that the actor behind the ByteToBreach campaign is likely operated by Zakaria Mahdjoub, an individual based in Oran, Algeria.
Researchers call him a “technically skilled cybercriminal selling sensitive global data from airlines, banks, and governments.”
ByteToBreach might also have been behind breaches of government registries in Eastern Europe, including Slovakia, Ukraine, Poland, and Lithuania.