Hacker wipes European country’s entire land registry database, paralyzing real-estate market
One security firm has already doxxed the crook behind the cyberattack.

Image by Cybernews.
- A hacker deleted Romania's entire land registry database after a failed extortion attempt, paralyzing the real-estate market
- The attack halted all property transactions, preventing notaries from authenticating sales or registering mortgages nationwide
- It appears, though, that Romania's cadastre agency has had an offline copy of the wiped data
Hackers can get very angry when they don’t get their way. That’s what happened in Romania when a crook wiped the country’s entire land registry database after an unsuccessful extortion attempt.
First, the hacker breached Romania’s cadastre agency, the National Agency for Cadastre and Real Estate Advertising (ANCPI), posting on a hacking forum: “[RO] Thy arss shall be spanked, Romania! [ANCPI]”
“In addition to the data of Romanian citizens, from various databases collected through ANCPI networks, there is also a copy of the GitLab servers containing the source code of all their systems, such as Eterra, RENNS, as well as a version of my little ransomware program,” the announcement continued.
“The official government website announced a shutdown of IT systems due to ‘technical problems,’ but this is a bit of an understatement. An offer of assistance was made, but without insistence or pressure.”
Has your password leaked?
Indeed, the ANCPI initially claimed technical issues but had to admit it was facing a cyberattack. Today, no one can really access the institution’s systems.
And since the extortion didn’t work, the hacker – who seems to have entered the database using valid credentials – deleted all data they had stolen, including internal documents, employee credentials, and, of course, land registry data.
The hack has brought Romania’s entire real-estate market to a standstill, Risky Business points out.
Notaries cannot record new transactions while citizens can’t obtain proof of ownership or detailed land records. And Romania is no small fish: on average, between 150,000 and 170,000 residential real estate units are sold annually across the country.
The hacker whose dark web account is called ByteToBreach and who also breached Sweden's e-government portal earlier this year, has been doxxed.
One notary, Ana Stan, said online: “I am a notary. Since Tuesday, I cannot issue a land registry extract, I cannot authenticate a sale, I cannot register a mortgage.”
On the dark web, the hacker also boasted to have begun backup copies of stolen data in an attempt to prevent it from being restored.
However, Romanian officials have managed to at least restore the ANCPI’s website and post a message saying they were rebuilding the agency’s entire network from scratch. It appears that the agency has an offline copy of the wiped data.
“Contrary to some information appearing in the public space, at the time of the incident, the ANCPI had several locations designated for storing backup copies, a measure that ensures redundancy and the possibility of data restoration in the event of cybersecurity incidents,” the press release says.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Moreover, the hacker whose dark web account is called ByteToBreach and who also breached Sweden's e-government portal earlier this year, has been doxxed.
Cybersecurity firm KELA now says that the actor behind the ByteToBreach campaign is likely operated by Zakaria Mahdjoub, an individual based in Oran, Algeria.
Researchers call him a “technically skilled cybercriminal selling sensitive global data from airlines, banks, and governments.”
ByteToBreach might also have been behind breaches of government registries in Eastern Europe, including Slovakia, Ukraine, Poland, and Lithuania.