How a Single Hacker Wiped Romania’s 20‑Year Land Registry Project with Just 0.2% Security Funding

After spending 7.1 billion lei over two decades on digitising Romania’s land‑registry system, the government allocated only 160 k lei (0.2%) to security, allowing a lone hacker to steal backups, delete the database and halt all property transactions nationwide within 24 hours.

ITPUB
ITPUB
ITPUB
How a Single Hacker Wiped Romania’s 20‑Year Land Registry Project with Just 0.2% Security Funding

1. 24 Hours: From a Minor Glitch to the Worst Incident

On July 14, the entire ANCPI system was breached in a single attack. The hacker exfiltrated the full GitLab backup and the source code of the core e‑Terra system, posted them for sale on the dark web, and then deleted the production database, instantly nullifying all property transactions.

"Thy arss shall be spanked, Romania!"

Initially, ANCPI announced on Facebook that a "technical issue" would be resolved by the weekend, labeling it a "small technical incident". By Day 2, the hacker’s dark‑web post forced ANCPI to admit it was "the most severe technical incident in the agency’s history".

2. €15 k per Year: A Paper‑Thin Security Wall

French media Ziarul Financiar calculated that ANCPI’s digitalisation budget over 20 years totals 7.1 billion lei, yet only 160 k lei (≈ €30.5 k) was spent on cybersecurity – about €1.5 k per year.

"This was not a complex attack… it could have been prevented."

The DNSC director noted that the attackers used only known vulnerabilities, no zero‑day exploits, no APT tools, and credentials leaked long ago. ANCPI had ignored patch warnings and had not changed the compromised passwords.

3. No State‑Level APT, Just a Dark‑Web Data Broker

Initial speculation blamed a Russian APT, but DNSC identified the attacker as ByteToBreach, real name Zakaria Mahdjoub, an Algerian “initial access broker” who trades stolen data on the dark web. He had no sophisticated tools or strategic motives; he simply scanned for unsecured servers, broke in, and listed the data for sale.

4. Nationwide Paralysis: Buyers Left Without Deeds

ANCPI is the hub for all Romanian property transactions. The breach halted the entire market, coinciding with a planned VAT increase on new homes from 9 % to 21% on August 1, a period that would have seen a surge in notarisation work.

"We have been waiting three days. Clients signed contracts, paid deposits, banks approved loans, and we are missing only the land‑registry extract. Without that paper nothing can proceed."

On July 20, ANCPI claimed that offline backups existed, data had not been lost, and that migration to a government cloud was underway, with security agencies to verify integrity before gradual restoration.

5. Where Is Your Property Title?

The incident shows that a minimally resourced attacker can cripple a nation’s core infrastructure. With only a few leaked passwords and unpatched vulnerabilities, the breach penetrated a system that had received 0.2 % of its IT budget for security, far below the 5‑10 % typical for mature institutions.

Globally, the lesson is clear: any country moving critical records to digital platforms must ask whether its security budget is sufficient.

Data sources: The Record, Cybernews, Romania Insider, Ziarul Financiar, G4Media, DNSC official statements (July 2026).

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

data breachcybersecuritybudgetgovernmentRomanialand registry
ITPUB
Written by

ITPUB

Official ITPUB account sharing technical insights, community news, and exciting events.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.