All posts

Hacker wipes Romania's entire land registry database

Manaal KhanJuly 22, 2026 at 8:31 AM5 min read
Hacker wipes Romania's entire land registry database

Key Takeaways

Hacker wipes Romania's entire land registry database
Source: Hacker News: Best
  • A hacker using valid credentials wiped Romania's national land registry database after a failed extortion attempt
  • All real estate transactions in Romania have been frozen for over a week as officials rebuild systems from scratch
  • Security firm KELA identified the attacker as Zakaria Mahdjoub from Algeria, the same hacker who breached Sweden's e-government portal

Romania's entire real estate market ground to a halt after a hacker breached the country's National Agency for Cadastre and Real Estate Advertising (ANCPI), wiped the land registry database, and deleted backups. The attack, which became public on July 14, followed a failed extortion attempt.

For over a week, notaries cannot record property transactions. Citizens cannot obtain proof of ownership or land records. The agency's email servers went down. Officials are now rebuilding the entire network from scratch.

Image (Source: Hacker News: Best)
Image (Source: Hacker News: Best)
Advertisements

How the attacker got in

Sources told Risky Business that the hacker entered using valid credentials. Once inside, they mapped internal systems methodically before executing the wipe. When the extortion demand failed, the attacker deleted both production systems and backups.

A day after the incident became public, stolen ANCPI data appeared for sale on a hacking forum. The dump included employee credentials, internal documents, and detailed information about the agency's IT network architecture.

The agency appears to have had an offline backup copy, which prevented a complete catastrophe. Without it, Romania would have faced months of chaos trying to reconstruct property ownership records for the entire country.

Who is behind the attack?

The stolen data was posted by an account named ByteToBreach. This is not a new player. The same hacker breached Sweden's e-government portal earlier this year and has hit numerous government agencies and companies over the past twelve months.

Image (Source: Hacker News: Best)
Image (Source: Hacker News: Best)

Security firm KELA published a profile on ByteToBreach last December, hinting at an Algerian location. After the ANCPI hack, KELA updated its post and directly identified the hacker as Zakaria Mahdjoub from Oran, Algeria. That disclosure should make Romanian law enforcement's job considerably easier.

A pattern across Eastern Europe

Romania joins a growing list of countries whose land registry systems have been compromised. Poland, Slovakia, Greece, Morocco, Russia, and Ukraine have all suffered similar breaches in the past three years. Land registries are attractive targets: they hold sensitive ownership data, support critical economic activity, and often run on aging infrastructure.

Image (Source: Hacker News: Best)
Image (Source: Hacker News: Best)

Romania had invested heavily in digitizing its land records since 2015, with EU funding support. The cadastre system underpins all real estate transactions, mortgages, inheritance claims, and property tax administration. This attack struck at the heart of that modernization effort.

Advertisements

What this means for critical infrastructure security

The ANCPI breach exposes a fundamental weakness: valid credentials bypass perimeter defenses entirely. The attacker did not need a zero-day exploit or sophisticated malware. They logged in, explored, and destroyed.

Credential theft remains one of the most effective attack vectors. Whether obtained through phishing, purchased from initial access brokers, or harvested from previous breaches, stolen credentials give attackers a clean entry point that looks legitimate to monitoring systems.

Image (Source: Hacker News: Best)
Image (Source: Hacker News: Best)

The backup deletion is equally significant. Many organizations treat backups as their insurance policy against ransomware and destructive attacks. But if an attacker has enough time and access, they can map where backups live and delete them too. Only truly air-gapped or immutable backups survive this scenario.

AI-powered attacks are escalating

The Romania incident comes amid a broader trend of attackers using AI to amplify their operations. The Risky Business podcast recently covered how ransomware groups are leveraging AI to gain more leverage over victims during extortion negotiations. The FulcrumSec group uses simple initial breach techniques, then deploys AI tools to maximize pressure.

In a separate incident, AI platform Hugging Face was breached last week by an autonomous AI agent exploiting vulnerabilities in its data-processing pipeline. When Hugging Face tried to use a frontier AI model to analyze the attack, the model's safety guardrails blocked the analysis, unable to distinguish incident response from offensive operations.

ℹ️

Logicity's Take

For startup founders, this breach is a reminder that credential hygiene matters more than fancy security tools. Multi-factor authentication, privileged access management, and truly isolated backups are non-negotiable. If you are building products that touch government or enterprise infrastructure, assume your customers will demand proof of these controls. The cost of implementing them now is trivial compared to rebuilding your entire system from scratch while your business sits frozen.

Frequently Asked Questions

How did the hacker breach Romania's land registry?

The attacker used valid credentials to log into ANCPI systems, mapped internal infrastructure, and then wiped databases and backups after failing to extort the agency.

Who is ByteToBreach?

ByteToBreach is a known hacker identified by security firm KELA as Zakaria Mahdjoub from Oran, Algeria. The same attacker breached Sweden's e-government portal and multiple other targets in the past year.

How long has Romania's real estate market been frozen?

The attack became public on July 14, and systems have been offline for over a week. Officials are rebuilding the entire network from scratch.

Did Romania lose all its land registry data?

The agency appears to have had an offline backup copy, which is being used to restore the system. Without it, reconstruction would have taken months.

Which countries have had their land registries hacked?

Poland, Slovakia, Greece, Morocco, Russia, Ukraine, and now Romania have all suffered land registry breaches in the past three years.

Also Read
EU may hand US biometric data of 460M citizens for visa-free travel

Another major data security story affecting European citizens and government systems

ℹ️

Need Help Implementing This?

If this story has you rethinking your backup strategy or access controls, start with the basics: audit who has credentials to your critical systems, implement MFA everywhere, and test whether your backups can actually be restored from an isolated environment. Your future self will thank you.

Source: Hacker News: Best

M

Manaal Khan

Tech & Innovation Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.