The facts are public and sourced. The parallel drawn between them is our opinion.
In the same summer, two institutions in Romania were hit by cyberattacks. One runs the country’s land registry — ANCPI. The other is a bank — Techventures Bank, formerly Banca Comercială Feroviară. I am not writing here about who was hit harder. I am writing about something less visible and more important: the reflex. What you do in the first hours and, above all, what you tell the person on the outside.
We are not comparing severity. We are comparing the reflex.
A cyberattack can happen to anyone. There is no invulnerable infrastructure, and being the victim of an attack is not, in itself, a disgrace. What differs — and what says almost everything about an organisation — is what it does immediately after. Here, the two incidents revealed two different cultures.
The bank took the short, uncomfortable route. It notified the authority — DNSC — the same day and asked for support with mitigation and investigation. Its public posture was, in essence: we were hit, we are investigating, we are asking for help. Four days later, an extortion group claimed the attack — an attackers’ allegation, not officially confirmed, which nonetheless does not change the essential point: the bank did not pretend nothing had happened.
At the land registry, the public message was different. The official position was that the data it manages is safe and was not compromised. A phrase meant to reassure. The problem is what the very authority investigating the case was saying in parallel: the head of DNSC stated publicly that certain categories of data were exfiltrated — “but not a very large quantity” — and that the attack could have been prevented, through known vulnerabilities, previously flagged, combined with credentials exposed online.
I am not commenting on how sensitive the data taken out of the system is; the investigation will decide that. I am commenting on the tension between “was not compromised” and “certain categories of data were exfiltrated”. Those are two messages that do not sit easily in the same sentence. And when reassurance contradicts what can be seen, the reassurance itself becomes the problem.
Why they react differently
Not because one side employs good people and the other bad ones. Because the two answer to different accountability structures.
A bank is a regulated entity. It answers to the central bank (BNR), to the DORA and NIS2 framework, to depositors, to a market that can punish it tomorrow morning. In that world, downplaying an incident is expensive and quickly penalised — honest reporting is not a virtue, it is survival. The regulatory framework makes lying costly.
A monopoly public registry answers, in practice, mostly to itself and to its supervising ministry. It has no competitor its customers can leave for, and no depositor pulling out their money. The legal obligation exists — the state is just as subject to GDPR and to notifying ANSPDCP as anyone — but the pressure that turns obligation into reflex is far weaker. And when you answer, in essence, to yourself, it is easier to hand yourself a gentle diagnosis.
Who pays for the difference
Not the institution. The citizen. And of all of them, the most exposed is the elderly.
You can change a password. A compromised card is reissued. But the land-registry number, the details on a title deed, the information in the cadastre — you cannot “reset” them. They stay there, exposed, no matter how many reassuring statements appear. And a seventy-year-old who does not follow security forums and gets no alerts on their phone has no way of learning that their data was exposed. They cannot defend against a risk no one tells them about. “The data was not compromised” is not, for them, information. It is a closed door.
Cyber hygiene is, in the end, care for the citizen
That is the whole discussion. Cyber hygiene is not about technology; it is about care for the person who entrusted you with their data. Isolated backups, phishing-resistant MFA, a rehearsed response plan — they all reduce to a single question: when the thing you do not want to happen finally happens, will you protect the citizen or the institution’s image?
Good systems do not assume good people. They assume rules that make lies expensive and the truth cheap. The bank had the framework that pushes it toward the right reflex. The state, toward its own citizen, ought to impose that reflex on itself — precisely because no one else compels it to.
At Braincap we work with exactly the organisations for which this day is a certainty, not a hypothesis: security audit, incident response planning, penetration testing. Not so you are never hit — no serious person promises that — but so you know, within minutes, what to say and what to do when you are. Get in touch.
The facts come from the public communications of the institutions and of DNSC, and from the press that relayed them — the details, with sources, are in the articles on ANCPI and Techventures Bank. The parallel between the two reflexes is our opinion. The attribution claim in the bank’s case belongs to an extortion group and is not officially confirmed.
Frequently asked questions
What obliges an organisation in Romania to report a cyber incident?
Several frameworks, cumulatively. GDPR requires notifying the supervisory authority (ANSPDCP) within 72 hours of becoming aware of a personal-data breach that poses a risk to individuals, plus informing affected people when the risk is high. NIS2 adds reporting of significant incidents to DNSC. For banks, DORA and Romanian central-bank (BNR) supervision raise the bar: operational resilience, reporting and tested recovery. The baseline obligation applies to the state and to a private company alike.
Then why does a bank disclose while a state body tends to reassure?
Not because one side has better people. Because they answer to different accountability structures. A bank answers to the central bank, to the DORA/NIS2 framework, to depositors, and to a market that can punish it immediately — there, downplaying an incident is expensive. A monopoly public registry answers, in practice, mostly to itself and its supervising ministry, where the pressure that turns a legal obligation into a reflex is far weaker.
Why is the elderly citizen the most exposed?
Because some data cannot be "reset". You change a password; a compromised card is reissued — but a land-registry number, the details on a title deed or in the cadastre, stay exposed no matter how many reassuring statements are issued. And someone who does not follow security forums and gets no phone alerts has no way of learning their data was exposed, so cannot defend against a risk no one tells them about.