Executive Summary
On July 14, 2026, the National Agency for Cadastre and Real Estate Advertising (ANCPI) of Romania suffered a critical cyberattack that resulted in the complete wiping of the country's land registry database. The attacker, identified as ByteToBreach, gained access using valid credentials, conducted internal reconnaissance, and subsequently destroyed both systems and backups after a failed extortion attempt. This incident brought Romania's real-estate market to a halt, disabling official applications, websites, and email servers, and preventing notaries and citizens from accessing essential land records. Stolen data, including employee credentials and internal documents, was posted for sale on a hacking forum. The agency has since begun rebuilding its network, reportedly aided by an offline backup. Attribution points to a threat actor with a history of targeting government agencies, with possible ties to Algeria. This report provides a detailed technical analysis, timeline, threat activity assessment, and prioritized mitigation recommendations based solely on confirmed evidence from the primary source.
Technical Information
The attack on ANCPI demonstrates a sophisticated, multi-stage intrusion leveraging valid credentials for initial access. According to the primary source, the attacker entered the agency's network using legitimate credentials, a method categorized under MITRE ATT&CK technique T1078 (Valid Accounts) [https://news.risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database/]. This approach bypasses many traditional perimeter defenses and highlights the importance of robust credential management and monitoring.
Once inside, the attacker mapped internal systems, consistent with T1087 (Account Discovery) and T1082 (System Information Discovery). This phase likely involved enumerating user accounts, network shares, and critical infrastructure to identify high-value targets and backup locations. The evidence for this activity is based on direct statements from sources cited in the article, with a medium confidence level due to the lack of granular technical detail.
The most destructive phase involved the wiping of both production systems and backups, aligning with T1485 (Data Destruction) and T1490 (Inhibit System Recovery). The attacker’s actions rendered the land registry database and associated services inoperable, causing a nationwide disruption in real-estate transactions and public record access. The agency’s email servers were also taken offline, further impeding recovery and communication.
Prior to the destructive actions, the attacker attempted to extort the agency, threatening further damage if demands were not met. While the specific extortion method is not detailed, this behavior is consistent with T1657 (Data Manipulation for Impact) and potentially T1486 (Data Encrypted for Impact), though there is no explicit evidence of ransomware deployment in this case.
Data exfiltration was confirmed when stolen information, including employee credentials, internal documents, and IT network details, was posted for sale on a known hacking forum. This aligns with T1567 (Exfiltration Over Web Service) and T1589 (Gather Victim Identity Information). The rapid posting of data suggests the attacker had premeditated plans for monetization and public exposure.
No specific malware, implants, or automated tools were identified in the reporting. The attack appears to have relied on manual actions facilitated by credentialed access, increasing the difficulty of detection by traditional endpoint security solutions.
Attribution efforts, led by security firm KELA, identified the attacker as ByteToBreach, a threat actor with a documented history of targeting government agencies and high-profile organizations. KELA further attributed the individual to a person from Oran, Algeria, though this identification is based on forum activity and open-source intelligence, and should be considered medium confidence.
The incident is part of a broader pattern of attacks against land registry agencies in Europe and beyond, with similar breaches reported in Poland, Slovakia, Greece, Morocco, Russia, and Ukraine over the past three years. This sector-specific targeting underscores the need for heightened vigilance and sector-wide information sharing.
Affected Versions & Timeline
The attack targeted the entire production environment of the National Agency for Cadastre and Real Estate Advertising (ANCPI), including its land registry database, official applications, websites, and email servers. There is no evidence that specific software versions or products were exploited; rather, the breach was facilitated by the use of valid credentials.
The timeline of the incident is as follows: On July 14, 2026, the attacker began deleting data, making the incident public as services went offline. By July 15, stolen data was posted for sale on a hacking forum. The agency’s website and email servers remained offline for at least a week, with officials subsequently announcing a full network rebuild. The presence of an offline backup enabled partial recovery, preventing a longer-term national crisis.
Threat Activity
The threat actor, ByteToBreach, is known for targeting government agencies and e-government portals, with previous attacks including the breach of Sweden’s e-government portal earlier in 2026. The attacker’s modus operandi involves credential-based access, internal reconnaissance, data exfiltration, extortion, and destructive actions if demands are not met. The posting of stolen data on public forums serves both as a monetization strategy and a means of reputational damage.
Attribution to is based on reporting by KELA, which previously profiled the actor and updated its assessment following the ANCPI breach. While this attribution is plausible, it is not independently corroborated in the primary source and should be treated with caution.
The attack on ANCPI fits a broader pattern of land registry agency breaches across Europe and neighboring regions, indicating a sustained campaign against critical government infrastructure. The use of valid credentials and manual attack techniques suggests a focus on exploiting weak authentication and insufficient monitoring rather than software vulnerabilities.
Mitigation & Workarounds
The following mitigation strategies are prioritized by severity:
Critical: Immediate review and reset of all privileged and administrative credentials within the affected environment is essential. Implement multi-factor authentication (MFA) for all remote and privileged access to prevent unauthorized use of valid credentials.
High: Conduct a comprehensive audit of access logs and privileged account activity to identify potential lateral movement or persistence mechanisms. Isolate and rebuild affected systems from known-good backups, ensuring that offline backups are maintained and regularly tested for integrity.
Medium: Enhance monitoring for anomalous account activity, including unusual login times, geographic anomalies, and mass data access or deletion events. Establish incident response playbooks for credential-based attacks and destructive actions.
Low: Provide security awareness training to staff on phishing, credential theft, and social engineering tactics. Participate in sector-wide information sharing initiatives to stay informed of emerging threats and attack patterns.
Indicators of Compromise
No public indicators of compromise were available at the time of writing. Organizations are advised to validate any future indicators before enforcement.
References
Risky Business News, "Hacker wipes Romania's entire land registry database," 20 Jul 2026. https://news.risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database/
About Rescana
Rescana provides a Third-Party Risk Management (TPRM) platform designed to help organizations identify, assess, and monitor risks in their digital supply chain. Our platform enables continuous monitoring of vendor security posture, supports rapid incident response, and facilitates compliance with sector-specific regulatory requirements. For more information or to discuss how our capabilities can support your organization’s risk management strategy, please contact us at info@rescana.com.



