Tech

Romania land registry chaos as hacker wipes database following failed extortion

The breach, attributed to Zakaria Mahdjoub, has halted property transactions and exposed internal credentials, marking the latest in a series of attacks on European land registries.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Hacker News · original
Tech
No image available
National Agency for Cadastre and Real Estate Advertising rebuilds network from scratch

Romania’s real-estate market has ground to a halt after hackers breached the National Agency for Cadastre and Real Estate Advertising (ANCPI) and deleted the country’s entire land registry database. The incident, which began on 14 July, was triggered by a failed extortion attempt and has prevented notaries from recording transactions while leaving citizens unable to access ownership records.

The attacker, identified by security firm KELA as Zakaria Mahdjoub from Oran, Algeria, utilised valid credentials to map the agency’s internal systems before wiping data and backups. Stolen information, including employee credentials and internal documents, was subsequently posted for sale on a hacking forum by the account ByteToBreach, which has been linked to previous breaches of high-profile entities including Sweden’s e-government portal.

Official applications and websites remained offline for a week, disrupting critical administrative functions. In response, ANCPI has restored its website and announced it is rebuilding its entire network infrastructure from scratch. The agency confirmed it is utilising an offline copy of the data for recovery, suggesting that despite the attacker’s claims of destroying backups, a secure offline reserve was available to mitigate total data loss.

This event places Romania in the company of Poland, Slovakia, Greece, Morocco, Russia, and Ukraine, all of which have seen their land registry agencies targeted by cyberattacks over the past three years. The breach highlights the growing vulnerability of critical national infrastructure to sophisticated ransomware and data theft campaigns.

While the immediate impact is a standstill in property transactions, the exposure of internal network details and employee credentials poses long-term security risks for the agency. Law enforcement efforts are now focused on the identified suspect, with the public disclosure of Mahdjoub’s identity expected to assist investigations into the breach and the broader activities of the ByteToBreach group.

Continue reading

More from Tech

Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers
Read next: Developer Antirez releases native MiniMax H3 inference engine for Apple Silicon