On July 14, 2026, Romania's land registry stopped working.
The Romanian cadastre application, known as e-Terra, went offline. So did internal email. Within days the country's real-estate market had frozen as notaries could not authenticate sales or register mortgages, and citizens could not pull proof of ownership. Romania's ANCPI Land Registry first called it a technical incident.
It was a cyberattack.
The attack was remarkably ordinary. Romania's National Cyber Security Directorate (DNSC) has said the attack was not complex and could have been prevented. Known, unpatched vulnerabilities that had recently flagged to ANCPI according to the DNSC, combined with credentials that had leaked and been posted online. There was no zero-day, and the attacker did not need a bypass. The environment had already supplied the credentials, the known vulnerabilities, and, according to leaked configuration data, a Group Policy named "DISABLE WINDOWS FIREWALL."
The accounts split on what happened to the data:
- Production systems and reachable backups were reportedly wiped, according to sources cited by Risky Business.
- DNSC confirms some data was exfiltrated, in limited volume, including samples of user credentials and fragments of application code.
- ANCPI says its authoritative technical and legal databases were not affected.
- Recovery reportedly depended on backups the agency kept out of the attacker's reach.
The accounts differ on what was taken and what was destroyed. Taken together, they point to known weaknesses, exposed credentials, and recovery systems the attacker could reportedly reach.
What we know so far
Reporting on a live incident arrives at different confidence levels. Here is the split.
Confirmed timeline:
- July 14. e-Terra and other ANCPI applications, including email, go offline. ANCPI calls it a major technical failure.
- July 15. Stolen ANCPI data is offered for sale on a hacking forum. Threat-intel firm KELA identifies the breach claim.
- July 16. The event is confirmed as a cyberattack. Separately, Romania's Ministry of Investments and European Projects (MIPE) confirms one of its procurement applications was also hit. Two public institutions went down in three days.
- July 17. Romanian outlet Public Record details the forum listing, including claimed citizen data and a claimed copy of ANCPI's GitLab source code. KELA updates its actor profile.
- July 20. ANCPI states that, per verifications so far, its technical and legal databases were not affected, and that migration of its applications to Romania's Government Cloud, coordinated by the Special Telecommunications Service (STS), has begun and should finish July 22. Services will return in stages after validation. ANCPI also warns that claims circulating publicly about the attack are not coming from official sources.
The official technical account:
In his interview with G4Media, DNSC head Dan Cîmpean called the attack financially motivated, with no sign of a state actor. He described ByteToBreach as an initial access broker active since roughly mid-2025. The actor gets into poorly protected systems, then offers to help clean up the chaos it created, for a fee. He was explicit that this is not how a ransomware group operates.
DNSC drew a narrower line on the data. It is certain that some categories were exfiltrated, in limited volume, and that the actor published credential samples and application-code fragments. It has not detected theft of citizens' personal data or land-book certificates.
The reported account:
Sources cited by Risky Business describe the destructive sequence: valid-credential access, internal reconnaissance, and the wiping of systems and backups after extortion failed, with stolen employee credentials, internal documents, and network details put up for sale.
It is the strongest account of that phase, and it rests on unnamed sources. Treat it as reporting, not forensics.
The actor's claims:
On the forums, ByteToBreach claimed to have taken citizen data and a full copy of ANCPI's GitLab source code, to have deployed ransomware, and to have deleted backups. He also reportedly claimed to have used a known vulnerability dating to 2021. DNSC has confirmed that known vulnerabilities were exploited, but not that one specifically. Those are the words of someone posting stolen data to make a sale.
Initial access was valid credentials and known vulnerabilities, not a zero-day
The official account makes the failure harder to excuse.
DNSC's description is a combination of unpatched known vulnerabilities plus credentials that had leaked and been posted online. That matters because the attacker did not have to build anything. Both halves of the entry were already sitting in public or semi-public space, and the vulnerabilities had reportedly been flagged to the agency. Nothing about that required a breakthrough.
KELA found one possible source for the credentials, but not enough evidence to call it the entry point. It identified infostealer-harvested credentials that may have belonged to ANCPI administrators but could not confirm they were still valid or used in the attack.
Mapped to MITRE ATT&CK, the confirmed part of the entry is short: Valid Accounts (T1078), used alongside exploitation of a known, unpatched vulnerability. There was no novel exploit chain to catch. Detection tuned to zero-day behavior and bespoke malware had little to work with, because the raw materials were a legitimate login and a bug that should already have been patched.
Identity and patching are boring right up until they decide the outcome. You do not need a bypass if you can log in to a system that was already flagged as weak.
The leak was a map of the environment
The leaked dataset handed outsiders a map of ANCPI’s Active Directory environment. It amounts to a reconnaissance dump, the kind that lets someone plan a route to domain control without touching the network again.
What it exposed:
- Windows XP, Windows 7, and Windows Server 2003, still present in the environment in 2026.
- At least 69 Group Policy Objects, including ones named "DISABLE WINDOWS FIREWALL" and "MIGRARE - ADD ADMINS."
- Dangerous Active Directory permissions (GenericAll, WriteDacl, WriteOwner), the exact relationships BloodHound exists to surface.
- Employee personal data and at least one encoded password.
This is an exposed configuration, not a reconstructed attack path. The GPO names show the policies existed, but they do not prove the attacker used them. However, that configuration could make privilege escalation much easier than it should be.
End-of-life systems with no modern mitigations, firewall-disabling policies, and permissive access-control edges are the conditions under which that combination can create several plausible routes toward domain admin using built-in tools.
We do not know which route the attacker took because the environment offered plenty.
Why deleting systems is often easier than encrypting them
According to sources cited by Risky Business, the attack turned destructive after extortion failed. Systems and backups were wiped rather than held for ransom. That fits DNSC's read of the actor as an access broker rather than a ransomware crew.
The difference is motive. Encryption keeps the data as leverage while deletion throws the leverage away to maximize damage. An actor focused on access and extortion does not need a mature encryption operation to cause serious damage.
None of it needs custom malware because with enough privilege, Windows supplies the tools. PowerShell, WMIC, PsExec, and the native backup and volume-shadow utilities can disable services, delete snapshots, drop databases, and remove virtual machines at scale. The same tools administrators use every day.
The exact tooling used at ANCPI has not been disclosed, and the actor claimed ransomware. Native utilities are capable of the reported outcome, but that is not the same as knowing which ones ran. If the wiping is confirmed, it maps to Data Destruction (T1485) and Inhibit System Recovery (T1490), the second being the delete-the-backups step. ANCPI's reported saving grace was a backup that step could not reach.
Why this attack became a national problem
Land registry systems sit under a whole category of civic and economic activity. When they go down, the failure does not stay technical. Property transactions stop, mortgage registration stops, legal verification of ownership stops, and dependent government services stop.
ANCPI recorded more than 51,000 property sales nationwide in June 2026 alone. A multi-day outage of the authoritative registry is much more than an IT inconvenience. It is a nationwide freeze on a working market, which is how DNSC described the impact.
It also flips the usual priorities. Security tends to optimize for confidentiality, for keeping data secret. This incident is a reminder that availability and integrity weigh just as much. A registry whose data is intact and confidential but unreachable still halts the economy that depends on it.
Underneath sits the real issue of assumed trust and reach. The breadth of the outage suggests one foothold reached a lot of systems. Romanian security firm BlackBullet reads that as weak internal segmentation, which is a reasonable inference rather than a confirmed cause.
Either way, the principle holds. In an environment built on assumed trust, a single compromised account inherits far more than it should. That is the condition Zero Trust exists to break. One compromised endpoint shouldn't be a launch point for the whole estate.
The attack path, by confidence level
Not every stage is equally well established. Sorted by how well each is supported:
Confirmed or officially acknowledged: The outage; exploitation of known, previously flagged vulnerabilities alongside leaked credentials (DNSC); limited data exfiltration, plus the publication of credential samples and application-code fragments (DNSC); exposed technical artifacts including obsolete systems and dangerous AD configuration (KELA).
Reported by sources: Valid-credential access, internal reconnaissance, and the wiping of systems and backups after a failed extortion attempt (Risky Business, unnamed sources); employee credentials and internal documents offered for sale.
Plausible but unconfirmed: Infostealer logs as the specific credential source; privilege escalation through the exposed ACL relationships; native remote-administration tooling for lateral movement and destruction; a flat internal network; domain-admin-level access.
Regardless of the exact path, defenders should watch for:
- Anomalous logins, impossible travel, and authentication from unfamiliar devices
- Unpatched internet-facing systems matching recent security advisories
- Bulk directory enumeration and BloodHound-style collection behavior
- Changes to high-value GPOs, privileged groups, and directory ACLs
- Unusual SMB, RDP, WinRM, admin-share, or remote-service activity
- Mass file operations, backup or snapshot deletion, service shutdowns, and virtual machine removal
How ThreatLocker could have interrupted the attack
While the exact toolchain is unclear, the controls that would have made it much harder are not.
Known vulnerabilities the agency had already been warned about were part of the attacker’s initial access. ThreatLocker Patch Management uses hash-based detection to find unpatched software, including portable applications traditional tools miss.
If the exploited software was supported and the relevant update was available, patching would have removed that half of the entry. The end-of-life systems in this environment are a separate problem. Patch management cannot support unsupported operating systems.
Prevent execution
Application Allowlisting answers one question: should this run? Infostealers, loaders, and unapproved tools do not execute if they were never permitted. The source of the ANCPI credentials remains unconfirmed, but this is one common route by which credentials end up for sale, and one that Allowlisting closes.
Restrict what trusted software can do
Allowlisting decides whether something runs. Ringfencing decides what it may do once it does, limiting which files, registry keys, network resources, and applications a trusted tool can touch, and stopping tools like PowerShell from launching unauthorized processes or reaching the internet. A compromised application constrained by policy cannot simply become the attacker’s platform.
Reduce standing admin rights
Privileged Access Management replaces broad local administrator rights with application-specific, policy-governed elevation, without administrator credentials being entered on the endpoint. A stolen credential should not come with permanent administrator rights.
Limit lateral movement
Zero Trust Endpoint Firewall enforces device-level rules by device, IP, port, and policy, and can restrict SMB, RDP, WinRM, and administrative shares to approved paths. In an environment whose Group Policy included one named “DISABLE WINDOWS FIREWALL,” host-level firewall policy draws the line between one compromised host and a domain-wide walk.
Reduce blast radius
Together, these controls make it far harder for one compromised account to become domain-wide access, and for production and recovery systems to share the same fate. That last part still depends on backups being genuinely separated. Reportedly, a backup copy outside the attacker’s reach is what kept recovery possible here.
The attack was ordinary, but the impact wasn't.
This is not a story about a brilliant adversary. By the national cyber authority's own account, the attack was preventable. Known vulnerabilities that had already been flagged, plus leaked credentials, used by an access broker rather than an elite crew.
The lesson is not that credential theft beats traditional defenses. It is that known weaknesses, exposed credentials, too much internal reach, and reachable backups turned a routine intrusion into a national outage.
Every one of those is fixable before an intrusion becomes an outage. Patch what you have been warned about. Stop unapproved software from running. Limit what trusted software can do. Remove standing admin rights. Restrict lateral movement. Keep recovery data genuinely out of reach. None of these are exotic.
These are basic controls against a basic attack.
Detection asks whether you can see the attacker in time. Controls decide whether it matters if you cannot.



