2026-08-05 · view entry permalink →
ByteToBreach hits Hungary's State Treasury after Romania's land registry — the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle
Hungarian outlet Telex.hu reports that the Magyar Államkincstár — Hungary's State Treasury — was breached in late July 2026, with the intrusion confirmed by Treasury officials to Hungarian journalists over the weekend of 2026-08-01/02, and specifically affecting its Agricultural and Rural Development Office (MVH) (Telex.hu, 2026-08-03). Risky Bulletin frames the significance plainly: the same actor who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system (Risky Bulletin, 2026-08-05). That is the part which matters beyond Hungary — this is one financially-motivated operator, assessed by KELA as likely an individual, reaching two national government bodies of two EU member states inside roughly a month (KELA, 2026-07-17).
The reported entry point is the transferable part, and it is not a novel technique. Per cybersecurity experts Telex.hu consulted, who reviewed screenshots the attacker leaked, access came through an unpatched Oracle WebLogic Server, with the outlet linking to Oracle's October 2017 Critical Patch Update (Telex.hu, 2026-08-03). No source names a specific CVE, so none is recorded in this entry's metadata and none should be inferred from the patch-cycle reference. What the reporting does support is the shape: a public application server carrying fixes that shipped roughly nine years ago, still reachable, still in service at a national treasury.
From that foothold the attacker escalated to domain-administrator rights — Telex.hu's sources state the attackers obtained the highest-level administrative privileges in practically every critical system — and the same reporting puts the reach at 116 virtual machines and 229 TB of data, with ransomware encrypting files on employee workstations (Telex.hu, 2026-08-03). Those scope figures derive from the experts' reading of attacker-supplied screenshots rather than from an official statement, and should be held as a claim under review. Treasury officials state that customer and citizen data was not affected. On origin the two accounts diverge: Telex.hu reports the Treasury's own experts attributing the attack to Russian servers, while ByteToBreach disputes that characterisation, denies making a ransom demand and describes the motive as financial. Neither account is independently confirmed. Hungary's National Cybersecurity Institute is investigating and the affected servers were disconnected on discovery.
Triage: exploitation of a legacy application server looks in telemetry like the application server's own service account doing something new — a Java process spawning a command interpreter, outbound connections from a host that should only receive them, or an authentication from the server's account to a system it has never touched. On a host that has run unchanged for years, a first-of-its-kind child process or destination is a stronger signal than it would be anywhere else, precisely because the baseline is so static.
The same hacker who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system.
A támadók gyakorlatilag minden kritikus rendszerben megszerezték a legmagasabb szintű rendszergazdai jogosultságokat
Builds on: 2026-07-26/weekly-w30-ch-eu-public-sector-third-party-incidents · 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated