Internet

No ransom paid: Hacker deletes Romania’s land registry database

A hacker attack has completely paralyzed the Romanian real estate market. After a failed ransom demand, a blackmailer deleted the country’s entire land registry database. Offline backups now prevent total data loss.

Blackmail leads to data deletion

A cyber attack has severely affected the IT infrastructure of the Romanian Agency for Cadastral and Real Estate Advertising, or ANCPI for short. An attacker gained access to the agency’s systems and demanded a ransom. When the payment failed to materialize, the perpetrator deleted the country’s entire land registry database. The incident has far-reaching consequences for the Romanian real estate market, which has effectively come to a standstill due to the system failure. Notaries are currently unable to certify new property transactions or register mortgages. At the same time, citizens have no way of accessing proof of ownership or detailed land register extracts.

As Risky business reports, the criminal used valid access data to break into the network. After the blackmail failed, he said he not only deleted the active systems, but also manipulated the online backups. He also offered stolen internal documents and employee data for sale on dark web forums.

Perpetrator apparently identified

There is an actor behind the attack who goes by the pseudonym ByteToBreach acts. IT security researchers have now identified the perpetrator as a man from Algeria. The criminal is no stranger and is said to have previously penetrated government networks in other European countries, including Sweden, Poland and Ukraine. The Romanian authority clarified that it has multiple physically separate offline backup copies. This means that the historical land registry data is not permanently lost.

However, recovery takes a lot of time as the entire infrastructure has to be rebuilt from scratch. ANCPI is currently working with external IT security specialists to clean and secure the network. The systems remain isolated for the time being to exclude further risks. Only when all vulnerabilities have been fixed should the services gradually come back online.

Recent Posts

Android 17: Google ends update support for Pixel 6 (Pro)

Google is officially ending software support for the Pixel 6 and Pixel 6 Pro. With…

2 hours ago

Millions of websites at risk: Attackers exploit bug in WordPress

Millions of websites are currently at risk of a successful attack. An error became known…

2 hours ago

Data theft as a service: Microsoft warns about ACR stealer campaigns

Microsoft warns of an increased wave of attacks with the ACR Stealer malware. Accordingly, attackers…

2 hours ago

PayPal takeover: $53 billion from Stripe is probably not enough

Stripe and Advent are offering a massive $53 billion for PayPal, but the payment service…

2 hours ago

Bizarre: North Korea’s Pixel 8 clone is partly superior to the Google original

A newly emerged North Korean clone of the Google Pixel 8 Pro not only looks…

2 hours ago

LibreOffice shoots against Microsoft – Sharp criticism of Office formats

LibreOffice once again sharply criticizes Microsoft Office file formats. The accusation is that users are…

2 hours ago