Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

Jump to content

2026 ANCPI hack

From Wikipedia, the free encyclopedia
2026 ANCPI hack
Date14 July 2026
Location
TypeCyberattack
ThemeRansomware attack disrupting ANCPI's IT infrastructure
OutcomeDatabase systems wiped and IT services disrupted. Data offered for sale, while surviving backups enabled restoration.

On 14 July 2026, Romania’s National Agency for Cadastre and Land Registration [ro] (ANCPI) was hit by a cyberattack. The attack disrupted ANCPI's IT infrastructure, including its cadastre and land-registration systems.[1] ANCPI applications, such as emails, and e-Terra, the cadastre application, were frozen, and the stolen information was put on sale on an undisclosed hacking forum.[2]

This attack is considered to be "the most serious technical incident in the institution's history."[3]

Attack

[edit]

After the attacker gained access using valid credentials, the e-Terra platform became unavailable, preventing employees from completing mortgage registrations, building-permit applications, and cadastral reception requests.[4] The attacker demanded payment after gaining access to ANCPI's systems, but the agency refused. The attacker subsequently wiped the production systems and backups. Stolen data, including internal documents, employee credentials and source code, was then offered for sale on a hacking forum.[1]

The attacker also posted a message on the forum mocking ANCPI: "Thy arss shall be spanked, Romania! [ANCPI]".[5]

Although the hacker claimed to have deleted the backups, officials announced that the network was being rebuilt and that an offline copy appeared to have survived.[6]

Aftermath

[edit]

The hacker group was identified to be ByteToBreach.[2][7][8] In a later interview, the hacker who claimed responsibility for the attack apologized for the problems caused by the incident. He said that he had exploited a vulnerability known since 2021 and stated that the stolen data "wouldn't be sold to just anyone". He also denied that he had demanded a €10 million ransom, saying that such matters were discussed only between the relevant parties.[9] The group has targeted organizations in numerous countries. The most targeted countries are the United States and India, followed by Italy, Spain and Russia. Other victims have been identified across Europe, including several CIS countries, as well as Asia, Africa and Latin America.[10]

The leak revealed details of ANCPI's Active Directory environment, including the use of antiquated operating systems such as Windows XP, Windows 7 and Windows Server 2003. It also revealed at least 69 Group Policy Objects, including policies named "DISABLE WINDOWS FIREWALL" and "MIGRARE - ADD ADMINS", as well as misuse of Active Directory permissions.[2]

A subsequent technical analysis reconstructed the attack as involving multiple known vulnerabilities. The attacker first exploited CVE-2021-35464, a remote code execution vulnerability affecting OpenAM, and subsequently exploited CVE-2024-36401, another remote code execution vulnerability in GeoServer. Both vulnerabilities had publicly available patches before the incident. CybrOps reported that the latter vulnerability was likely used for lateral movement within the infrastructure. The National Directorate for Cyber Security [ro] (DNSC) characterized the attack as not complex, citing the exploitation of known, unpatched vulnerabilities and compromised credentials.[11]

A legal debate subsequently emerged over whether the cyberattack could constitute force majeure under Article 1351 of the Romanian Civil Code. The issue affected buyers, sellers, developers and other participants in the real estate market, as the unavailability of the central land registry prevented or delayed real estate transactions, mortgage financing and cadastral procedures. The disruption also created difficulties for developers whose building permits and urbanism certificates were subject to statutory deadlines.[12]

References

[edit]
  1. 1 2 Salem, Julia (5 August 2026). "The Attacker's First Target Was the Backups: Inside Romania's Land Registry Wipe". Eon. Retrieved 20 September 2026.
  2. 1 2 3 ThreatLocker Special Projects Engineering Team (21 July 2026). "How stolen credentials and known vulnerabilities brought Romania's land registry to a standstill". ThreatLocker. Retrieved 20 September 2026.
  3. ↑ Chiriac, Marian (21 July 2026). "Land Registry Cyberattack Exposes Holes in Romania's Digital Defences". Balkan Insight. Retrieved 20 September 2026.
  4. ↑ Schoenherr și Asociații (7 August 2026). "Atacul cibernetic asupra ANCPI: cine plătește factura pieței imobiliare blocate?". HotNews.ro. Retrieved 20 September 2026.
  5. ↑ Radauskas, Gintaras (21 July 2026). "Hacker wipes European country's entire land registry database, paralyzing real-estate market". Cybernews. Retrieved 20 September 2026.
  6. ↑ Cimpanu, Catalin (20 July 2026). "Risky Bulletin: Hacker wipes Romania's entire land registry database". Risky Business. Retrieved 20 September 2026.
  7. ↑ "Investigație: Atacul cibernetic care a blocat o lună piața imobiliară din România a fost anticipat de existența pe internet a mii de parole de notari, avocați, ingineri și funcționari publici". HotNews.ro. 18 August 2026. Retrieved 21 September 2026.
  8. ↑ "Romania ANCPI Land Registry Wiped in Credential-Based Cyberattack: Incident Analysis and Mitigation Recommendations". Rescana. Retrieved 21 September 2026.
  9. ↑ "Hackerul care susține că a spart serverele Agenției pentru Cadastru, despre datele furate: „Nu le vând chiar oricui"". HotNews.ro. 17 July 2026. Retrieved 21 September 2026.
  10. ↑ "Dark Web Profile: ByteToBreach". SOCRadar. 26 November 2025. Retrieved 21 September 2026.
  11. ↑ "Atacul ANCPI arată ruptura dintre conformitate și reziliență: cum ajunge securitatea de importanță națională să existe mai ales pe hârtie". CybrOps. Retrieved 24 September 2026.
  12. ↑ "Romania: The cyberattack on ANCPI: force majeure or mere technical disruption? What it means for the real estate market". Schönherr. 10 August 2026. Retrieved 24 September 2026.