Romania ANCPI Land Registry Wiped in Credential-Based Cyberattack: Incident Analysis and Mitigation Recommendations

Romania ANCPI Land Registry Wiped in Credential-Based Cyberattack: Incident Analysis and Mitigation Recommendations

Executive Summary

In mid-July 2026, Romania’s National Agency for Cadastre and Real Estate Advertising (ANCPI) suffered a financially motivated double-extortion ransomware attack that halted nationwide digital land-registry operations. DNSC interim technical analysis T66/22.07.2026 describes unauthorized activity against the agency datacenter that culminated in bytetocrypt ransomware on VMware ESXi hosts, deletion of approximately 100 of approximately 1,083 VMs, and underground advertising by ByteToBreach / ByteToBreach33.

ANCPI IT detected the incident at approximately 2026-07-14 05:45 UTC. The DNSC timeline places the first foothold at 2026-07-10 15:23:57 UTC against internet-facing OpenAM/ForgeRock authentication for ePay (T1190), then WebSphere, unpatched GitLab, monitoring/SIEM, then vCenter. The Path B baseline of 2026-07-20 correctly highlighted credential reuse and a destructive wipe, but DNSC shows initial access was Exploit Public-Facing Application via a known OpenAM/ForgeRock CVE chain, with Valid Accounts (T1078) driving escalation into virtualization management. Credential compromise remains central but incomplete without the public-facing exploit foothold.

Official messaging (DNSC, The Record): Oracle Exadata technical/legal cadastral databases are not evidenced as compromised; land-book integrity was preserved. Confirmed exfiltration: credential samples and application code fragments (approximately 2 million OpenDJ userPassword hashes; GitLab source for e-Terra/RENNS/payments/GIS); attempted domain-controller VMDK copy. Actor claims of broader citizen data exceed DNSC confirmation.

Impact: e-Terra, email, and portals froze; the real-estate market stood still. Recovery moved toward the Romanian Government Cloud (STS/Cyberint/DNSC). e-Terra restarted on 2026-08-11; as of 2026-09-13 local reporting, Geoportal, MyEterra, Registrul Proprietarilor, Titluri de proprietate, and Registrul de Transcripțiuni și Inscripțiuni remained unrestored publicly. The attack is characterized as financially motivated, not highly complex, exploiting known weaknesses plus leaked/reused credentials. KELA-reported personal attribution of ByteToBreach to Oran, Algeria has not been verified by Romanian authorities.

This advisory refreshes the July 2026 Path B write-up against DNSC T66 and recovery reporting through mid-September 2026.

Technical Information

Victim: ANCPI. Attack: double-extortion ransomware (bytetocrypt on ESXi) plus VM deletion and leak claims. Actor: ByteToBreach / ByteToBreach33. No verified state or APT attribution.

Key timeline (DNSC):

  • 2026-07-10 — OpenAM foothold; later JSP webshell dec3.jsp.
  • 2026-07-11 — WebSphere JMX/RMI.
  • 2026-07-12 — GitLab CVE-2021-22205; Zabbix Scripts reverse shell; FortiSIEM credential store; Ligolo-ng; Sliver masquerading as auditd.
  • 2026-07-13 — vCenter admin login (~1,083 VMs); ESXi bytetocrypt; ~100 VMs deleted; SCP to 66.163.118.234.
  • 2026-07-14 — detect/notify.
  • 2026-07-22 — DNSC T66.
  • 2026-08-11 — e-Terra restart.
  • 2026-09-13 — other portals still down in public reporting.

DNSC cites CVE-2021-35464 (ForgeRock/OpenAM, CISA KEV) as primary initial access; it also pairs CVE-2024-36401 (NVD: GeoServer—a citation anomaly relative to the OpenAM foothold). GitLab CVE-2021-22205 is in CISA KEV. vCenter 6.0.0 build 5112529 is end-of-life. FortiGate log retention was approximately seven minutes. BitDefender was present on workstations only.

MITRE ATT&CK mappings below are taken from DNSC T66 §8 only; this advisory does not invent additional technique IDs:

Path B correction: lead with the known-CVE public-facing foothold, and keep the credential-reuse and destructive-wipe elements.

Affected Product Versions

No new ANCPI-specific CVE is assigned by this advisory. Named infrastructure in DNSC reporting:

  • OpenAM/ForgeRock (version unpinned); OpenDJ
  • IBM WebSphere
  • GitLab (unpatched at time of compromise)
  • Zabbix 7.4
  • vCenter 6.0.0 build 5112529; ESXi
  • FortiSIEM 7.2; FortiGate 300E
  • Juniper SRX650 / EX9214
  • BitDefender (workstations)
  • Oracle Exadata (not accessed)

Custom tooling names only: bytetocrypt, Sliver, Ligolo-ng, dec3.jsp.

Workaround and Mitigation

  • Patch ForgeRock/OpenAM CVE-2021-35464.
  • Inventory GeoServer separately for CVE-2024-36401 (do not collapse that CVE into the OpenAM foothold).
  • Enforce MFA on privileged paths.
  • Upgrade GitLab past CVE-2021-22205.
  • Prohibit password reuse GitLab → Kerberos → vCenter.
  • Authenticate WebSphere JMX.
  • Least-privilege Zabbix Scripts.
  • No reversible SIEM secrets.
  • Extend WAF log retention well beyond ~7 minutes.
  • Retire end-of-support vCenter.
  • Immutable, restore-tested backups.
  • EDR on servers, not workstations only.
  • KEV aging for IAM/DevOps tooling in TPRM questionnaires.

Indicators of Compromise

No comprehensive public IoC package has been published. Contextual indicators from DNSC reporting only:

  • 66.163.118.234
  • dec3.jsp
  • bytetocrypt
  • Sliver masquerading as auditd
  • Ligolo-ng
  • ByteToBreach / ByteToBreach33

No hashes are published in this advisory. Prefer behavioral detection over inventing hash lists, and validate any future indicators before enforcement.

References

Third-Party Risk Bridge: KEV Aging, Secrets, and Hypervisor Blast Radius

ANCPI shows TPRM is not only confidentiality: a financially motivated IAB-style actor used known CISA KEV weaknesses (ForgeRock/OpenAM, GitLab), monitoring/SIEM, and end-of-support vCenter to freeze property markets while Exadata databases stayed intact. Demand KEV aging, secrets/MFA that block password reuse, log-retention SLAs, hypervisor segmentation, and restore-tested immutable backups.

Book a demo to see how Rescana tracks KEV-aged IAM, GitLab, and virtualization chokepoints in the third-party estate, and whether password-reuse, log-retention, and restore-tested backup evidence is on file before residual availability risk is closed.

Forward this advisory to TPRM, procurement, and NIS2 owners; use the ANCPI path identity → app server → GitLab → monitoring/SIEM → end-of-support vCenter as a questionnaire checklist.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.