logo

How stolen credentials and known vulnerabilities brought Romania's land registry to a standstill

ID: 345e2207-e05f-5083-9469-89fd89f32391

STIX ID: report--345e2207-e05f-5083-9469-89fd89f32391

Feed Name: ThreatLocker Blog

Threat Score
78/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

...
...

On 14 July 2026 Romania's national land registry (ANCPI/e-Terra) suffered a preventable cyberattack that took internal services (including email and the cadastre application) offline, froze property transactions nationwide, and resulted in limited data exfiltration and reported destruction of systems and backups; DNSC attributes the incident to an access broker using leaked credentials and exploitation of known, unpatched vulnerabilities (no zero-day) with stolen artifacts posted for sale by an actor calling itself ByteToBreach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.