Skip to content
Braincap
← All articles

The ANCPI cyberattack: the facts, in brief

Illustration of an information system taken down by a cyberattack

In July 2026, a cyberattack took Romania’s national cadastre and land registry system offline. Below are the facts as confirmed by the institutions and reported by the press — kept clearly separate from the attacker’s unconfirmed claims. The situation was still developing at the time of publication (22 July 2026).

Timeline

  • On Tuesday, 14 July 2026, the IT systems of ANCPI (the National Agency for Cadastre and Real Estate Publicity) became non-functional. The agency first described it as a “major technical incident”, then confirmed it was a cyberattack.
  • The national cadastre and land registry system was unavailable for roughly three days in the first phase, and the e-Terra application remained down for several more days afterwards.

Affected systems

  • According to ANCPI, all of the agency’s IT systems were affected, including its e-mail addresses.
  • The most visible impact was the outage of e-Terra — the application used by citizens, notaries, lawyers, surveyors, banks and public authorities for property-related operations.

What the authorities stated

ANCPI:

  • The data it manages is safe and was not compromised; backup copies exist and the database is being restored from them.
  • Services return in phases, by priority; applications are being migrated to the government cloud, to be verified by the competent institutions.
  • A criminal investigation is under way; DNSC, the SRI (intelligence service) and the STS (special telecommunications service) are involved.

DNSC — director Dan Cîmpean:

  • The attack was not highly complex and could have been prevented.
  • The attackers exploited known technical vulnerabilities that the authorities had been notified about recently, combined with credentials (passwords) exposed online.
  • “We have not detected, so far, any stolen personal data or land registry certificates.”
  • The attackers published samples of user credentials and fragments of ANCPI application code; certain categories of data were exfiltrated, “but not a very large amount”.
  • The incident appears financially motivated, with no indication so far of a state actor.

What the attacker claims (unconfirmed)

  • An attacker using the handle ByteToBreach put data up for sale on a cybercrime forum.
  • They claim to hold databases of Romanian citizens’ information and a copy of the GitLab servers (source code for applications such as e-Terra and RENNS), to have deployed ransomware, and to have started deleting backups.
  • The Israeli security firm Kela describes the presumed author as a technically experienced criminal previously involved in selling sensitive data from airlines, banks and public institutions in several countries.
  • These claims have not been publicly confirmed by ANCPI or the authorities and contradict the official position, according to which the managed data was not compromised.

Context

  • According to Ziarul Financiar, ANCPI had signed two cybersecurity framework agreements with the firm About IT SRL — roughly 950,000 lei (2019) and about 1.5 million lei (2023), around 2.5 million lei in total.

The entry vectors, according to DNSC

The entry points described publicly by DNSC were already-known, already-notified vulnerabilities plus credentials exposed online — two categories of risk that are reduced by applying security updates promptly and by rigorous password and access hygiene. This is the observation of the authority investigating the incident, not a conclusion of the investigation, which was still under way at the time of publication.

Sources