ctipilot.ch

ANCPI Romania cadastre cyberattack

incident · incident:ancpi-romania-cyberattack-2026-07 contradicted

Multi-day outage of Romania's national cadastre/land-registry systems (e-Terra, RENNS, institutional email) beginning 14 July 2026, confirmed by ANCPI as a cyberattack. ByteToBreach claims citizen-data theft, a copied GitLab source-code server, ransomware deployment and backup deletion; ANCPI disputes any data compromise. Still unresolved as of 17 July 2026 (Help Net Security, Public Record, KELA).

Coverage timeline
6
first 2026-07-19 → last 2026-08-05
Peak priority
high
3 high · 3 notable
Sources cited
20
17 hosts
Sections touched
3
active-threats, updates, weekly-sector-patterns
Co-occurring entities
2
see Related entities below
ATT&CK techniques
11
pinned v19.2 · see below
2026-07-196 appearances2026-08-05

ATT&CK techniques

11 techniques observed across 6 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×3

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated · 2026-07-21/ancpi-romania-cadastre-databases-not-affected-update · 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

T1190Exploit Public-Facing Application×3

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · 2026-07-19/weekly-w29-ch-eu-public-sector-ci-incidents · 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

T1199Trusted Relationship×2

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-26/weekly-w30-ch-eu-public-sector-third-party-incidents · 2026-07-19/weekly-w29-ch-eu-public-sector-ci-incidents · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×3

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated · 2026-07-21/ancpi-romania-cadastre-databases-not-affected-update · 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×3

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated · 2026-07-21/ancpi-romania-cadastre-databases-not-affected-update · 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×3

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated · 2026-07-21/ancpi-romania-cadastre-databases-not-affected-update · 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Credential Access TA0006

T1110Brute Force×1

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Evidence: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated · ATT&CK page ↗

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-26/weekly-w30-ch-eu-public-sector-third-party-incidents · ATT&CK page ↗

Impact TA0040

T1485Data Destruction×2

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Evidence: 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated · 2026-07-21/ancpi-romania-cadastre-databases-not-affected-update · ATT&CK page ↗

T1486Data Encrypted for Impact×5

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · 2026-07-26/weekly-w30-ch-eu-public-sector-third-party-incidents · 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated · 2026-07-19/weekly-w29-ch-eu-public-sector-ci-incidents · 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

T1490Inhibit System Recovery×3

Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.

Evidence: 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated · 2026-07-21/ancpi-romania-cadastre-databases-not-affected-update · 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

Story timeline

  1. 2026-08-05ByteToBreach hits Hungary's State Treasury after Romania's land registry — the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle
    active-threatsThe actor who wiped Romania's cadastre reaches a second EU government body through legacy WebLogic
  2. 2026-07-26Swiss and European public-sector bodies carried the week's home-region incident load — and nearly every one was reached through a third party, a shared platform or a fiduciary, then followed by a disclosure that had to be walked back
    weekly-sector-patternsSwiss public-sector breaches and Romania's land registry share a shape — third-party access, and a 'not affected' claim the leak later contradicted
  3. 2026-07-26ANCPI Romania — DNSC interim report confirms vCenter-to-ESXi ransomware and exfiltration of ~2 million ePayment user records
    updatesRomania's DNSC supersedes the 'databases not affected' line: the cadastre attack took the virtualization plane and two million payment records
  4. 2026-07-21ANCPI (Romania cadastre): agency says core databases were NOT compromised, contradicting ByteToBreach's destruction claim; Gov Cloud migration to complete 22 July
    updatesRomania's cadastre authority disputes the attacker's database-wipe claim as it moves e-Terra to Government Cloud
  5. 2026-07-19Swiss and European public-sector, utility and transport organisations carried the week's home-region incident load — a land registry offline for days, two Swiss utilities/foundations hit through third parties, an EU transit ransomware and a EUR 1.7M telco enforcement
    weekly-sector-patternsW29 home-region incidents — ANCPI Romania offline for days, IWB Basel and Geneva's IFAGE breached, Metro Mondego ransomware, Wind Tre fined EUR 1.7M
  6. 2026-07-19Romania's national cadastre agency ANCPI hit by a multi-day cyberattack; ByteToBreach claims citizen-data and e-Terra source-code theft plus ransomware
    active-threatsRomanian land-registry authority ANCPI down for days after a cyberattack; data-leak operator ByteToBreach claims theft and ransomware

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed to

related to

Where this entity is cited

  • active-threats2
  • weekly-sector-patterns2
  • updates2

Source distribution

  • go4it.ro2 (10%)
  • news.risky.biz2 (10%)
  • telex.hu2 (10%)
  • 20min.ch1 (5%)
  • autismuslink.ch1 (5%)
  • campeaoprovincias.pt1 (5%)
  • digi24.ro1 (5%)
  • garanteprivacy.it1 (5%)
  • other9 (45%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (20)

Entries about ANCPI Romania cadastre cyberattack (6)

2026-08-05 · view entry permalink →

HIGHNATOB2

ByteToBreach hits Hungary's State Treasury after Romania's land registry — the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle

Hungarian outlet Telex.hu reports that the Magyar Államkincstár — Hungary's State Treasury — was breached in late July 2026, with the intrusion confirmed by Treasury officials to Hungarian journalists over the weekend of 2026-08-01/02, and specifically affecting its Agricultural and Rural Development Office (MVH) (Telex.hu, 2026-08-03). Risky Bulletin frames the significance plainly: the same actor who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system (Risky Bulletin, 2026-08-05). That is the part which matters beyond Hungary — this is one financially-motivated operator, assessed by KELA as likely an individual, reaching two national government bodies of two EU member states inside roughly a month (KELA, 2026-07-17).

The reported entry point is the transferable part, and it is not a novel technique. Per cybersecurity experts Telex.hu consulted, who reviewed screenshots the attacker leaked, access came through an unpatched Oracle WebLogic Server, with the outlet linking to Oracle's October 2017 Critical Patch Update (Telex.hu, 2026-08-03). No source names a specific CVE, so none is recorded in this entry's metadata and none should be inferred from the patch-cycle reference. What the reporting does support is the shape: a public application server carrying fixes that shipped roughly nine years ago, still reachable, still in service at a national treasury.

From that foothold the attacker escalated to domain-administrator rights — Telex.hu's sources state the attackers obtained the highest-level administrative privileges in practically every critical system — and the same reporting puts the reach at 116 virtual machines and 229 TB of data, with ransomware encrypting files on employee workstations (Telex.hu, 2026-08-03). Those scope figures derive from the experts' reading of attacker-supplied screenshots rather than from an official statement, and should be held as a claim under review. Treasury officials state that customer and citizen data was not affected. On origin the two accounts diverge: Telex.hu reports the Treasury's own experts attributing the attack to Russian servers, while ByteToBreach disputes that characterisation, denies making a ransom demand and describes the motive as financial. Neither account is independently confirmed. Hungary's National Cybersecurity Institute is investigating and the affected servers were disconnected on discovery.

Triage: exploitation of a legacy application server looks in telemetry like the application server's own service account doing something new — a Java process spawning a command interpreter, outbound connections from a host that should only receive them, or an authentication from the server's account to a system it has never touched. On a host that has run unchanged for years, a first-of-its-kind child process or destination is a stronger signal than it would be anywhere else, precisely because the baseline is so static.

The same hacker who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system.

Risky Bulletin (Risky Business Media) 2026-08-05

A támadók gyakorlatilag minden kritikus rendszerben megszerezték a legmagasabb szintű rendszergazdai jogosultságokat

Telex.hu 2026-08-03

Builds on: 2026-07-26/weekly-w30-ch-eu-public-sector-third-party-incidents · 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated

incident05 Aug 04:12Zmulti-sourceOpen finding ↗

2026-07-26 · view entry permalink →

HIGHNATOB1

Swiss and European public-sector bodies carried the week's home-region incident load — and nearly every one was reached through a third party, a shared platform or a fiduciary, then followed by a disclosure that had to be walked back

The week's confirmed incidents with a direct Swiss or European home-region nexus landed almost entirely on public-sector and critical-infrastructure bodies, and two structural patterns are more useful to defenders than any single victim.

The first is the access path: the breach rarely started inside the named victim. Swiss rolling-stock manufacturer Stadler Rail disclosed that the Everest group compromised a data-exchange platform it shares with a supplier and demanded CHF 10 million, which the company did not pay — "Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht", while its own production ran normally (swissinfo.ch, 2026-07-21). A Vaud fiduciary breach claimed by BravoX published more than 100,000 client files — some 220 GB — exposing tax and administrative records of roughly fifteen Nord-Vaudois municipalities and the personal tax file of a sitting cantonal State Councillor (Le Temps, 2026-07-22). A Bern autism-support foundation, Stiftung Autismuslink, confirmed that "grössere Datenmengen" were exfiltrated and its server temporarily encrypted (Stiftung Autismuslink, 2026-07); the INC Ransom RaaS group claimed the attack via a matching leak-site listing (Ransomware.live, 2026-07-24), and the foundation's constituency-relevance is that it serves Swiss cantonal education-directorate and disability-insurance-linked clients. In each case the sensitive public-sector data sat with a supplier, a fiduciary or a small third-party service organisation, not on a government perimeter.

The second pattern is a disclosure that had to be walked back. Geneva's IFAGE adult-education foundation had earlier framed its incident as affecting employee data; the attackers — the DragonForce group (ICTjournal, 2026-07-17) — published the stolen set, which included identity-document photographs, addresses and multi-year student exam results, and 20 minutes reported the disclosure "concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etc.)" (20 minutes, 2026-07-24). The starkest reversal is Romania's national land registry ANCPI, which stated on 2026-07-20 that its databases "have not been affected"; the national cybersecurity directorate DNSC's interim report describes attackers compromising the authentication servers, entering VMware vCenter, enumerating all 1,083 virtual machines, deleting roughly 100 and encrypting ESXi hosts, and exfiltrating about two million ePayment-platform user records — "nume; e-mailuri; identificatori; hash-uri ale parolelor" (PS News relaying DNSC, 2026-07-24), with the report also noting the affected servers ran no antivirus.

Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht

swissinfo.ch 2026-07-21

atacatorii au extras aproximativ două milioane de înregistrări privind utilizatori ai platformei de plăți, care conțineau: nume; e-mailuri; identificatori; hash-uri ale parolelor

PS News (relaying the DNSC report) 2026-07-24

Leur divulgation par les cybercriminels concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etc.).

20 minutes

Builds on: 2026-07-22/everest-ransomware-stadler-rail-supplier-platform-breach · 2026-07-24/bravox-vaud-fiduciary-municipalities-breach · 2026-07-25/stiftung-autismuslink-bern-inc-ransom-breach · 2026-07-26/ifage-geneva-dragonforce-data-published-student-records · 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated · 2026-07-21/ancpi-romania-cadastre-databases-not-affected-update

synthesis26 Jul 23:44Zmulti-sourceOpen finding ↗

2026-07-26 · view entry permalink →

NOTABLEupdateNATOB1

ANCPI Romania — DNSC interim report confirms vCenter-to-ESXi ransomware and exfiltration of ~2 million ePayment user records

UPDATE · originally covered ANCPI (Romania cadastre): agency says core databases were NOT compromised, contradicting ByteToBreach's destruction claim; Gov Cloud migration to complete 22 July (2026-07-21)

the picture of the attack on ANCPI, Romania's national cadastre and land-registration agency, has changed substantially. Earlier coverage recorded the agency's own position that its databases were not affected. Romania's national cybersecurity directorate DNSC has since published an interim technical report, relayed with direct quotation by Romanian technology press, that supersedes that framing on the point that matters most: the attackers extracted approximately two million records concerning users of the payment platform, containing names, e-mail addresses, identifiers and password hashes — in the report's Romanian, "atacatorii au extras aproximativ două milioane de înregistrări privind utilizatori ai platformei de plăți, care conțineau: nume; e-mailuri; identificatori; hash-uri ale parolelor" (PS News, 2026-07-24). The "databases not affected" assurance survives only in a much narrower form — DNSC states there is no indication the main Oracle Exadata database was compromised (go4it.ro, 2026-07-24) — which is a different claim from "no data was taken", since a separate payment-platform datastore demonstrably was.

The intrusion path DNSC describes is the one that makes a virtualized government estate fail all at once. Per the report the attackers compromised the authentication servers, penetrated VMware vCenter — the system administering the entire virtual infrastructure — enumerated all 1,083 virtual machines, executed lateral movement, deleted approximately 100 virtual machines and encrypted ESXi servers with ransomware (PS News, 2026-07-24). Identity compromise first, then the virtualization control plane, then destruction at the hypervisor layer beneath every guest operating system — the per-VM security stack never gets a vote. Source code for the eTerra, GIS, ePayment and security modules was taken from the agency's GitLab as well. DNSC's account of why it worked is unusually blunt for a national authority — the ANCPI infrastructure had no antivirus installed on the servers running its main applications (go4it.ro, 2026-07-24), alongside known unpatched vulnerabilities and a web-application firewall retaining connection logs for only seven minutes — which is also why the forensic picture is partial. DNSC's director had already assessed on 2026-07-18 that the attack exploited already-known vulnerabilities and could have been prevented (go4it.ro, 2026-07-18).

Triage: in vCenter and ESXi audit telemetry, the discriminating sequence is not any single administrative action but the ordering — an authentication from an unusual source or service account, followed by a full inventory enumeration of virtual machines, followed by power-off or delete operations across guests that share no application grouping. Routine administration enumerates inventory constantly and backup tooling touches many VMs, so volume alone is noise; the signal is enumeration by a principal that does not normally perform it, immediately followed by destructive operations spanning unrelated workloads.

atacatorii au extras aproximativ două milioane de înregistrări privind utilizatori ai platformei de plăți, care conțineau: nume; e-mailuri; identificatori; hash-uri ale parolelor

au compromis serverele de autentificare; au pătruns în VMware vCenter, adică sistemul care administrează întreaga infrastructură virtuală; au enumerat toate cele 1.083 de mașini virtuale; au executat mișcare laterală în rețea; au șters aproximativ 100 de mașini virtuale; au criptat servere ESXi cu ransomware

PS News (relaying the same DNSC report) 2026-07-24

infrastructura ANCPI nu beneficia de un antivirus instalat pe serverele care rulau aplicațiile principale

nu există indicii că baza de date principală Oracle Exadata ar fi fost compromisă

go4it.ro (relaying the DNSC interim technical report) 2026-07-24
incident26 Jul 13:55Zmulti-sourceOpen finding ↗

Earlier coverage (3)

2026-07-21NOTABLEupdateNATOB3ANCPI (Romania cadastre): agency says core databases were NOT compromised, contradicting ByteToBreach's destruction claim; Gov Cloud migration to complete 22 JulyUpdate on the ANCPI (Romanian National Agency for Cadastre) cyberattack: on 2026-07-20 the agency stated, after security verification, that its technical and legal databases "have not been affected" — directly contradicting data-leak operator ByteToBreach's claim of deleting backups after a failed extortion. ANCPI is migrating its applications to the Romanian Government Cloud, expected to finish 22 July, before any phased service restoration. KELA separately profiled the ByteToBreach operator; the contradiction between the wipe claim and the "databases intact" statement is itself the notable fact — both are held, neither is resolved.2026-07-19HIGHNATOB2Swiss and European public-sector, utility and transport organisations carried the week's home-region incident load — a land registry offline for days, two Swiss utilities/foundations hit through third parties, an EU transit ransomware and a EUR 1.7M telco enforcementThe incidents with a direct Swiss/European home-region or coverage-focus nexus this week clustered squarely on public-sector and critical-infrastructure organisations. Romania's national cadastre authority ANCPI had all IT systems down since 14 July after a confirmed cyberattack, with data-leak operator ByteToBreach claiming data theft, source-code exfiltration and ransomware. Two Swiss organisations were hit through third parties — the Basel canton utility IWB (electricity/gas/water/telecom) lost ~40,000 customer meter records via a compromised service provider, and Geneva adult-education foundation IFAGE was listed by DragonForce (850 GB claimed, unconfirmed). Portugal's Metro Mondego confirmed a 6 July ransomware attack (TheGentlemen claim) that its IT/OT segmentation kept off the transit service. Italy's Garante fined Wind Tre EUR 1.7M for a retail-staff-vishing-to-API-enumeration breach of 365,048 customers, and Ernst & Young disclosed a third-party ITSM-platform breach exposing client tax data. Underneath the incidents, NCSC-CH flagged an unauthenticated RCE (CVSS 9.8) in Abacus ERP — ubiquitous across Swiss SMEs, associations and public-sector-adjacent bodies — as the week's largest latent home-region exposure.2026-07-19NOTABLENATOB2Romania's national cadastre agency ANCPI hit by a multi-day cyberattack; ByteToBreach claims citizen-data and e-Terra source-code theft plus ransomwareRomania's National Agency for Cadastre and Real Estate Publicity (ANCPI) — the government authority running the national land-registry and cadastre systems (e-Terra, RENNS) used by citizens, notaries, banks and other authorities — has had all IT systems down since 14 July 2026 after what it confirmed is a cyberattack. A data-leak operator using the alias ByteToBreach, tracked by KELA and with a cross-country victimology spanning government, banking and other sectors, claims to have stolen Romanian-citizen data and the e-Terra/RENNS source code from a copied GitLab server, deployed ransomware, and begun deleting backups; ANCPI disputes that its data was compromised. A live, unresolved EU public-sector incident.